xlibre-video-nouveau-bin

maintainer xlibre · 0 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged This PKGBUILD downloads a prebuilt binary package (.pkg.tar.zst) from x11libre.net, an unofficial/personal host, and installs its contents directly into the package directory. There is no source build process — the binary is extracted and installed as-is. XLibre is a real X.Org fork project, but x11libre.net is not an established, widely-trusted distribution channel (unlike, say, official distro repos or well-known CDNs). The sha256sum provides some integrity protection, but only against accidental corruption or a one-time swap — it does not protect against the host owner replacing the file and updating the checksum in the PKGBUILD, nor does it provide any cryptographic signing verification (no .sig source). Installing an unverified prebuilt X server video driver binary grants it full access to the X server ABI and runs with elevated privileges. This is a genuine supply-chain concern: a prebuilt binary from a non-mainstream host with no GPG signature verification, even if the project itself is legitimate.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:13 source=(https://x11libre.net/repo/arch_based/x86_64/xlibre-video-nouveau-1.0.18.4-1-x86_64.pkg.tar.zst)
MEDIUM AI review llm_review

An AI model (anthropic/claude-4.6-sonnet-20260217) reviewed this and agrees it is MEDIUM (confidence 82%): This PKGBUILD downloads a prebuilt binary package (.pkg.tar.zst) from x11libre.net, an unofficial/personal host, and installs its contents directly into the package directory. There is no source build process — the binary is extracted and installed as-is. XLibre is a real X.Org fork project, but x11libre.net is not an established, widely-trusted distribution channel (unlike, say, official distro repos or well-known CDNs). The sha256sum provides some integrity protection, but only against accidental corruption or a one-time swap — it does not protect against the host owner replacing the file and updating the checksum in the PKGBUILD, nor does it provide any cryptographic signing verification (no .sig source). Installing an unverified prebuilt X server video driver binary grants it full access to the X server ABI and runs with elevated privileges. This is a genuine supply-chain concern: a prebuilt binary from a non-mainstream host with no GPG signature verification, even if the project itself is legitimate.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: artist for Xlibre
2
3pkgname=xlibre-video-nouveau-bin
4_pkgname=xlibre-xf86-video-nouveau
5pkgver=1.0.18.4
6pkgrel=1
7pkgdesc="XLibre Official Easy Install Drop in Replacement fork of X.Org nouveau video driver (binary release)"
8arch=(x86_64)
9url=https://x11libre.net/repo/arch_based/x86_64
10license=('MIT')
11groups=('xlibre-drivers')
12options=(!strip)
13source=(https://x11libre.net/repo/arch_based/x86_64/xlibre-video-nouveau-1.0.18.4-1-x86_64.pkg.tar.zst)
14noextract=("${_pkgname}-${pkgver}-${pkgrel}-x86_64.pkg.tar.zst")
15depends=('mesa' 'libdrm' 'glibc')
16provides=('xf86-video-nouveau' 'xlibre-video-nouveau')
17conflicts=('xf86-video-nouveau' 'xlibre-video-nouveau' 'xorg-server<21.1.1' 'X-ABI-VIDEODRV_VERSION<28' 'X-ABI-VIDEODRV_VERSION>=29')
18
19sha256sums=('f01d7cb736dbfa58979d4a1b9ac83b8f369a1411db14cc650304bdd85584d3f2')
20
21package() {
22 tar -xf "${_pkgname}-${pkgver}-${pkgrel}-x86_64.pkg.tar.zst" -C "${pkgdir}" usr
23}
24
25

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion