AUR AI Reviewer

Review Results

Version #1719 of plex-media-server-plexpass · commit 98072685cc4b · status Reviewed

Risk 0/5 · Safe .SRCINFO
Result #276

Comment

The only change in this .SRCINFO hunk is a version bump from 1.43.3.10793 to 1.43.3.10828. No source URLs, checksums, build steps, install scripts, or packaging metadata were altered in the provided diff, so there is no new security concern visible from this change alone. Risk is minimal.

@@ -1,6 +1,6 @@
 pkgbase = plex-media-server-plexpass
 	pkgdesc = The back-end media server component of Plex.
-	pkgver = 1.43.3.10793
+	pkgver = 1.43.3.10828
 	pkgrel = 1
 	url = https://plex.tv/
 	install = plex-media-server.install
Risk 0/5 · Safe .SRCINFO
Result #277

Comment

The change is a straightforward version bump in .SRCINFO for Plex Media Server PlexPass, updating the per-architecture download URLs and checksums to a newer upstream release on the official downloads.plex.tv domain over HTTPS. There are no new sources, scripts, build steps, or packaging logic introduced here, and nothing in this diff suggests privilege escalation, persistence, or integrity bypass. Risk is low because the only security-relevant aspect is trusting the upstream binary release and its updated checksums, which is expected for this package type.

@@ -27,13 +27,13 @@ pkgbase = plex-media-server-plexpass
 	sha256sums = c597bee0bcbb59ed791651555a904e5f7e9d2e82f6c6986b6352e5fc38e5b557
 	sha256sums = b7ff6525a3c7a8be885edc85bb523095f8e25ddb38873127e2a4e97b28f2c7ad
 	sha256sums = 7bb97271eb2dc5d1dcb95f9763f505970d234df17f1b8d79b467b9020257915a
-	source_x86_64 = https://downloads.plex.tv/plex-media-server-new/1.43.3.10793-cd55560bb/redhat/plexmediaserver-1.43.3.10793-cd55560bb.x86_64.rpm
-	sha256sums_x86_64 = a7b26b9e4965ee34fe5bfd93c9d7d010067a5060b3473c65125cb52ee2757e34
-	source_i686 = https://downloads.plex.tv/plex-media-server-new/1.43.3.10793-cd55560bb/redhat/plexmediaserver-1.43.3.10793-cd55560bb.i686.rpm
-	sha256sums_i686 = 0e8e56daea4728b56bd6e60318038ce364c0104904b113d50a882c2f8aa4b4a6
-	source_armv7h = https://downloads.plex.tv/plex-media-server-new/1.43.3.10793-cd55560bb/debian/plexmediaserver_1.43.3.10793-cd55560bb_armhf.deb
-	sha256sums_armv7h = 5dfa918ffa4eaab60e44723f413afc14e7b11161393656b919e8e5a4ec957584
-	source_aarch64 = https://downloads.plex.tv/plex-media-server-new/1.43.3.10793-cd55560bb/debian/plexmediaserver_1.43.3.10793-cd55560bb_arm64.deb
-	sha256sums_aarch64 = fe60cd8c91dc3f8cfcb0bd121c150f8e58bd229394ac973c128e80b0cfd99652
+	source_x86_64 = https://downloads.plex.tv/plex-media-server-new/1.43.3.10828-00f62d37d/redhat/plexmediaserver-1.43.3.10828-00f62d37d.x86_64.rpm
+	sha256sums_x86_64 = 2ff1d3e1ac1052cfadfcaa932c17f6fa775e625859aa93224c85983f00052183
+	source_i686 = https://downloads.plex.tv/plex-media-server-new/1.43.3.10828-00f62d37d/redhat/plexmediaserver-1.43.3.10828-00f62d37d.i686.rpm
+	sha256sums_i686 = 6ec375fe8d4de3bd5f3734865b6aa4245a791d7029a1216362f0625c5354cf1f
+	source_armv7h = https://downloads.plex.tv/plex-media-server-new/1.43.3.10828-00f62d37d/debian/plexmediaserver_1.43.3.10828-00f62d37d_armhf.deb
+	sha256sums_armv7h = a24a65361bb28ebeecadf82d4c02d023ee9b3a34ee2baa0635bfc51e1d01b1be
+	source_aarch64 = https://downloads.plex.tv/plex-media-server-new/1.43.3.10828-00f62d37d/debian/plexmediaserver_1.43.3.10828-00f62d37d_arm64.deb
+	sha256sums_aarch64 = f08c0ae850e331fa8204e9aa88226598d8da9181ae91f97fe01f76964ba962a0
 
 pkgname = plex-media-server-plexpass
Risk 0/5 · Safe PKGBUILD
Result #278

Comment

The change only bumps the Plex Pass version and corresponding upstream checksum fragment in PKGBUILD. No new sources, scripts, build steps, permissions, or install-time behavior are introduced by this diff hunk. Based on the provided change alone, there are no obvious security red flags beyond the usual trust in upstream binary distribution.

@@ -13,8 +13,8 @@
 # Based on the plex-media-server package by Maxime Gauduin.
 
 pkgname=plex-media-server-plexpass
-pkgver=1.43.3.10793
-_pkgsum=cd55560bb
+pkgver=1.43.3.10828
+_pkgsum=00f62d37d
 pkgrel=1
 pkgdesc='The back-end media server component of Plex.'
 arch=('x86_64' 'i686' 'armv7h' 'aarch64')
Risk 0/5 · Safe PKGBUILD
Result #279

Comment

The change only updates architecture-specific SHA-256 checksums in PKGBUILD for the existing upstream binary sources. I do not see any new sources, build-time downloads, privilege changes, install-script logic, or packaging behavior changes. This is a routine integrity hash refresh, with no obvious security impact beyond trusting the new upstream artifacts themselves, which is expected for a versioned package update.

@@ -43,10 +43,10 @@ sha256sums=('b7f2fb1cbedde54a79a1794ec9f35f8bdeb033a4c5453ec77944ca7fe77cd9b7'
             'c597bee0bcbb59ed791651555a904e5f7e9d2e82f6c6986b6352e5fc38e5b557'
             'b7ff6525a3c7a8be885edc85bb523095f8e25ddb38873127e2a4e97b28f2c7ad'
             '7bb97271eb2dc5d1dcb95f9763f505970d234df17f1b8d79b467b9020257915a')
-sha256sums_x86_64=('a7b26b9e4965ee34fe5bfd93c9d7d010067a5060b3473c65125cb52ee2757e34')
-sha256sums_i686=('0e8e56daea4728b56bd6e60318038ce364c0104904b113d50a882c2f8aa4b4a6')
-sha256sums_armv7h=('5dfa918ffa4eaab60e44723f413afc14e7b11161393656b919e8e5a4ec957584')
-sha256sums_aarch64=('fe60cd8c91dc3f8cfcb0bd121c150f8e58bd229394ac973c128e80b0cfd99652')
+sha256sums_x86_64=('2ff1d3e1ac1052cfadfcaa932c17f6fa775e625859aa93224c85983f00052183')
+sha256sums_i686=('6ec375fe8d4de3bd5f3734865b6aa4245a791d7029a1216362f0625c5354cf1f')
+sha256sums_armv7h=('a24a65361bb28ebeecadf82d4c02d023ee9b3a34ee2baa0635bfc51e1d01b1be')
+sha256sums_aarch64=('f08c0ae850e331fa8204e9aa88226598d8da9181ae91f97fe01f76964ba962a0')
 
 prepare() {
   if [[ $CARCH = armv7h ]] || [[ $CARCH = aarch64 ]]; then