xlibre-video-intel-bin

maintainer xlibre · 1 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged This PKGBUILD downloads a prebuilt binary package (.pkg.tar.zst) from x11libre.net, which is a third-party/unofficial host, and directly extracts and installs its contents (X.org video driver files under /usr) onto the user's system. XLibre is a real fork of X.Org that exists, so this is not obviously malicious, but the binary is not sourced from an official distribution mirror or the upstream project's own verified release infrastructure (e.g., GitHub releases with reproducible builds). The sha256sum provides integrity checking against tampering in transit, but does not protect against a compromised or malicious build at the source. A prebuilt X server video driver binary installed system-wide is high-impact if the source is compromised. This is a genuine medium-severity supply-chain concern: executed binary from a non-standard personal/project host with no way to verify the build process.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:13 source=("https://x11libre.net/repo/arch_based/x86_64/${_pkgname}-${pkgver}-${pkgrel}-x86_64.pkg.tar.zst")
MEDIUM AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 80%): This PKGBUILD downloads a prebuilt binary package (.pkg.tar.zst) from x11libre.net, which is a third-party/unofficial host, and directly extracts and installs its contents (X.org video driver files under /usr) onto the user's system. XLibre is a real fork of X.Org that exists, so this is not obviously malicious, but the binary is not sourced from an official distribution mirror or the upstream project's own verified release infrastructure (e.g., GitHub releases with reproducible builds). The sha256sum provides integrity checking against tampering in transit, but does not protect against a compromised or malicious build at the source. A prebuilt X server video driver binary installed system-wide is high-impact if the source is compromised. This is a genuine medium-severity supply-chain concern: executed binary from a non-standard personal/project host with no way to verify the build process.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: artist for Xlibre <artist4xlibre@proton.me>
2
3pkgname=xlibre-video-intel-bin
4_pkgname=xlibre-video-intel
5pkgver=3.0.0.6
6pkgrel=1
7pkgdesc="XLibre Official Easy Install Drop in Replacement fork of X.Org Intel i810/i830/i915/945G/G965+ video drivers (binary release)"
8arch=(x86_64)
9url="https://x11libre.net"
10license=('MIT')
11groups=('xlibre-drivers')
12options=(!strip)
13source=("https://x11libre.net/repo/arch_based/x86_64/${_pkgname}-${pkgver}-${pkgrel}-x86_64.pkg.tar.zst")
14noextract=("${_pkgname}-${pkgver}-${pkgrel}-x86_64.pkg.tar.zst")
15depends=('mesa' 'libxvmc' 'pixman' 'xcb-util>=0.3.9'
16 'libxcb' 'libxfixes' 'libxshmfence' 'libdrm' 'libxrender'
17 'libx11' 'libxdamage' 'libxext' 'libpciaccess' 'glibc')
18optdepends=('libxrandr: for intel-virtual-output'
19 'libxinerama: for intel-virtual-output'
20 'libxcursor: for intel-virtual-output'
21 'libxtst: for intel-virtual-output'
22 'libxss: for intel-virtual-output')
23replaces=('xf86-video-intel-uxa' 'xf86-video-intel-sna')
24provides=('xf86-video-intel' 'xlibre-video-intel' 'xf86-video-intel-uxa' 'xf86-video-intel-sna')
25conflicts=('xf86-video-intel' 'xlibre-video-intel' 'xorg-server<21.1.1' 'X-ABI-VIDEODRV_VERSION<28' 'X-ABI-VIDEODRV_VERSION>=29'
26 'xf86-video-intel-sna' 'xf86-video-intel-uxa' 'xf86-video-i810' 'xf86-video-intel-legacy')
27
28sha256sums=('da4f9d7ed5f0aea3e992e93135c91f83d9792485d07c3411a13f813a646ac25b')
29
30package() {
31 tar -xf "${_pkgname}-${pkgver}-${pkgrel}-x86_64.pkg.tar.zst" -C "${pkgdir}" usr
32}
33
34

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion