youtube-downloader-bin

maintainer schinfo · 1 votes · scanned 2026-08-03 00:08:14.047287
MEDIUM
View on AUR ↗
Why flagged The package downloads a prebuilt .deb binary from a non-official, non-whitelisted host (schinfo.de), which is not the project's official domain, creating a supply-chain risk if the host is compromised or malicious.

Triggered rules

MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:23 source_x86_64=("${pkgname}-${pkgver}-${_build}-${pkgrel}.amd64.deb::https://schinfo.de/MediaHuman/YouTubeDownloader.amd64.deb")
MEDIUM AI review llm_review

An AI model (qwen/qwen3-235b-a22b-07-25) reviewed this and agrees it is MEDIUM (confidence 95%): The package downloads a prebuilt .deb binary from a non-official, non-whitelisted host (schinfo.de), which is not the project's official domain, creating a supply-chain risk if the host is compromised or malicious.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Helmut Stult <hst[at]e-mail[dot]de>
2
3
4pkgname=youtube-downloader-bin
5_pkgname=youtube-downloader
6pkgver=3.9.22
7pkgrel=1
8_build=2600710
9pkgdesc='YouTube Downloader by MediaHuman'
10arch=('x86_64')
11url="https://www.mediahuman.com/download.html"
12license=('LicenseRef-custom')
13depends=('ffmpeg'
14 'hicolor-icon-theme'
15 'qt5-declarative'
16 'qt5-multimedia'
17 'qt5-networkauth'
18 'qt5-quickcontrols'
19 'qt5-webengine'
20 'taglib')
21provides=('youtube-downloader')
22conflicts=('youtube-downloader')
23source_x86_64=("${pkgname}-${pkgver}-${_build}-${pkgrel}.amd64.deb::https://schinfo.de/MediaHuman/YouTubeDownloader.amd64.deb")
24sha256sums_x86_64=('b99da97cf963cf585dd08a5249a46c8912f40751d2fbca2176d4b67ae38d78c1')
25
26pkgver() {
27 bsdtar -xf control.tar.xz -C .
28 actpkgverlong="$(cat "control" | grep "Version: ")"
29 actpkgver=${actpkgverlong##*: }
30 echo "$actpkgver"
31}
32
33package() {
34 bsdtar -xf data.tar.xz -C ${pkgdir}/
35 install -D "${pkgdir}/usr/share/doc/${_pkgname}/copyright" -t "${pkgdir}/usr/share/licenses/${pkgname}/"
36 install -dm755 $pkgdir/usr/bin
37 ln -s /opt/$_pkgname/YouTubeDownloader "${pkgdir}/usr/bin/YouTubeDownloader"
38}
39

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 MEDIUM 2
2026-08-02 00:16:08 MEDIUM 2
2026-08-01 00:11:18 MEDIUM 2
2026-07-31 00:14:10 MEDIUM 2
2026-07-30 00:17:23 MEDIUM 2
2026-07-29 00:25:53 MEDIUM 2
2026-07-28 00:07:28 MEDIUM 2
2026-07-27 00:24:32 MEDIUM 2
2026-07-26 00:07:32 MEDIUM 2
2026-07-25 00:13:44 MEDIUM 2
2026-07-24 00:02:28 MEDIUM 2
2026-07-23 00:14:47 MEDIUM 2
2026-07-22 00:29:32 MEDIUM 2
2026-07-21 00:24:15 MEDIUM 2
2026-07-20 00:19:49 MEDIUM 2
2026-07-19 00:17:08 MEDIUM 2
2026-07-18 00:14:48 MEDIUM 2
2026-07-17 00:06:16 MEDIUM 2
2026-07-16 00:05:41 MEDIUM 2
2026-07-15 00:09:25 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion