xrt-bin

maintainer luciddream · 0 votes · scanned 2026-08-03 00:08:14.047287
LOW
broken
View on AUR ↗
Why flagged The source URL is on xilinx.com, the official Xilinx/AMD vendor domain, so this is not an unofficial or personal host. The query-parameter style URL (openDownload?filename=...) is Xilinx's standard download redirect mechanism used across their product line — the actual filename is embedded in the parameter and is specific and versioned (xrt_202110.2.11.634_20.04-amd64-xrt.deb). An md5sum is provided, which pins the content at package-build time (though MD5 is weak, it still provides basic integrity verification). The package installs a prebuilt Debian binary from the official vendor, which is a legitimate but non-ideal packaging pattern (prebuilt binary vs. building from source). The main concerns are: (1) MD5 is cryptographically weak; (2) the dynamic URL could theoretically serve different content if Xilinx changes the backend, but the md5sum mitigates this; (3) no GPG signature verification. These are sloppy/non-standard practices but not a genuine supply-chain attack vector given the official vendor origin and checksum presence. The 'broken' flag is borderline since the package() function references data.tar.gz without extracting it from the .deb first (missing ar extraction step), but this is a packaging bug rather than a security issue. Overall: low severity, sloppy packaging.

Triggered rules

LOW AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (anthropic/claude-4.6-sonnet-20260217) reviewed the full PKGBUILD and judged it LOW (confidence 82%): The source URL is on xilinx.com, the official Xilinx/AMD vendor domain, so this is not an unofficial or personal host. The query-parameter style URL (openDownload?filename=...) is Xilinx's standard download redirect mechanism used across their product line — the actual filename is embedded in the parameter and is specific and versioned (xrt_202110.2.11.634_20.04-amd64-xrt.deb). An md5sum is provided, which pins the content at package-build time (though MD5 is weak, it still provides basic integrity verification). The package installs a prebuilt Debian binary from the official vendor, which is a legitimate but non-ideal packaging pattern (prebuilt binary vs. building from source). The main concerns are: (1) MD5 is cryptographically weak; (2) the dynamic URL could theoretically serve different content if Xilinx changes the backend, but the md5sum mitigates this; (3) no GPG signature verification. These are sloppy/non-standard practices but not a genuine supply-chain attack vector given the official vendor origin and checksum presence. The 'broken' flag is borderline since the package() function references data.tar.gz without extracting it from the .deb first (missing ar extraction step), but this is a packaging bug rather than a security issue. Overall: low severity, sloppy packaging.

1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:11 source=(https://www.xilinx.com/bin/public/openDownload?filename=xrt_202110.2.11.634_20.04-amd64-xrt.deb)

PKGBUILD

1 offending line(s) highlighted
1pkgname=xrt-bin
2pkgver=2021.2
3pkgrel=1
4pkgdesc="Xilinx Run Time for FPGA"
5arch=('x86_64')
6url="https://github.com/Xilinx/XRT"
7license=('EULA')
8groups=('base-devel')
9depends=(ocl-icd)
10optdepends=(vivado)
11source=(https://www.xilinx.com/bin/public/openDownload?filename=xrt_202110.2.11.634_20.04-amd64-xrt.deb)
12md5sums=(a40f8a4386e8f92f9af43d1bfae54b62)
13
14package() {
15 tar -zxf data.tar.gz -C "${pkgdir}"
16 mv "${pkgdir}/lib" "${pkgdir}/usr/lib"
17 mv "${pkgdir}/opt/xilinx" "${pkgdir}/opt/Xilinx"
18}
19

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 LOW 2
2026-08-02 00:16:08 LOW 2
2026-08-01 00:11:18 LOW 2
2026-07-31 00:14:10 LOW 2
2026-07-30 00:17:23 LOW 2
2026-07-29 00:25:53 LOW 2
2026-07-28 00:07:28 LOW 2
2026-07-27 00:24:32 LOW 2
2026-07-26 00:07:32 LOW 2
2026-07-25 00:13:44 LOW 2
2026-07-24 00:02:28 LOW 2
2026-07-23 00:14:47 LOW 2
2026-07-22 00:29:32 LOW 2
2026-07-21 00:24:15 LOW 2
2026-07-20 00:19:49 LOW 2
2026-07-19 00:17:08 LOW 2
2026-07-18 00:14:48 LOW 2
2026-07-17 00:06:16 LOW 2
2026-07-16 00:05:41 LOW 2
2026-07-15 00:09:25 LOW 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion