AUR AI Reviewer

Review Results

Version #2101 of plex-media-server-plexpass · commit 34f784bca10f · status Reviewed

Risk 0/5 · Safe .SRCINFO
Result #1967

Comment

The change only bumps pkgver in .SRCINFO from 1.43.3.10861 to 1.43.3.10896. No source URLs, checksums, build logic, install scripts, or permissions are altered in this diff. By itself this is a metadata-only version update with no evident security impact.

@@ -1,6 +1,6 @@
 pkgbase = plex-media-server-plexpass
 	pkgdesc = The back-end media server component of Plex.
-	pkgver = 1.43.3.10861
+	pkgver = 1.43.3.10896
 	pkgrel = 1
 	url = https://plex.tv/
 	install = plex-media-server.install
Risk 0/5 · Safe .SRCINFO
Result #1968

Comment

The change is a straightforward version bump in .SRCINFO from Plex 1.43.3.10861 to 1.43.3.10896, with corresponding checksum updates for the official downloads. The source URLs remain HTTPS and point to Plex's official download host, and there are no new sources, scripts, build steps, or privilege-related artifacts introduced by this diff. No security red flags are evident in the reviewed hunk.

@@ -27,13 +27,13 @@ pkgbase = plex-media-server-plexpass
 	sha256sums = c597bee0bcbb59ed791651555a904e5f7e9d2e82f6c6986b6352e5fc38e5b557
 	sha256sums = b7ff6525a3c7a8be885edc85bb523095f8e25ddb38873127e2a4e97b28f2c7ad
 	sha256sums = 7bb97271eb2dc5d1dcb95f9763f505970d234df17f1b8d79b467b9020257915a
-	source_x86_64 = https://downloads.plex.tv/plex-media-server-new/1.43.3.10861-07dfddaeb/redhat/plexmediaserver-1.43.3.10861-07dfddaeb.x86_64.rpm
-	sha256sums_x86_64 = 2c1ff73ffd2ab8c8523fb5d37394c3cccffe0e8bd662b8a78749a7385874fb6b
-	source_i686 = https://downloads.plex.tv/plex-media-server-new/1.43.3.10861-07dfddaeb/redhat/plexmediaserver-1.43.3.10861-07dfddaeb.i686.rpm
-	sha256sums_i686 = 2d22d0061aefa7c9662fb86f6fcc19f02e6e2478f5b0fadc2dad24c4bd9d371c
-	source_armv7h = https://downloads.plex.tv/plex-media-server-new/1.43.3.10861-07dfddaeb/debian/plexmediaserver_1.43.3.10861-07dfddaeb_armhf.deb
-	sha256sums_armv7h = f22851c1611d03df736fd0cd9af0bc15f53c8767fd1ff69a85febbaeb22feab9
-	source_aarch64 = https://downloads.plex.tv/plex-media-server-new/1.43.3.10861-07dfddaeb/debian/plexmediaserver_1.43.3.10861-07dfddaeb_arm64.deb
-	sha256sums_aarch64 = 2d4006110e55cd3920c82d8aec83db21b943d57430a94db486ffbd01902f15ae
+	source_x86_64 = https://downloads.plex.tv/plex-media-server-new/1.43.3.10896-cb3ebc72d/redhat/plexmediaserver-1.43.3.10896-cb3ebc72d.x86_64.rpm
+	sha256sums_x86_64 = ea678ff32fc7d42f9105d28ada1495f00ef5139c05550f37a68bacfefe1f4c31
+	source_i686 = https://downloads.plex.tv/plex-media-server-new/1.43.3.10896-cb3ebc72d/redhat/plexmediaserver-1.43.3.10896-cb3ebc72d.i686.rpm
+	sha256sums_i686 = 565394c842ca75c171e89ed753d1fb15db5855e60d6bd467afd5ae6561e0e361
+	source_armv7h = https://downloads.plex.tv/plex-media-server-new/1.43.3.10896-cb3ebc72d/debian/plexmediaserver_1.43.3.10896-cb3ebc72d_armhf.deb
+	sha256sums_armv7h = 59a8f5ee5bcb64b8827e1d759855d5eca35b2f76eb8055df75cbbc3d01f09567
+	source_aarch64 = https://downloads.plex.tv/plex-media-server-new/1.43.3.10896-cb3ebc72d/debian/plexmediaserver_1.43.3.10896-cb3ebc72d_arm64.deb
+	sha256sums_aarch64 = 2a7ad1306795d391551d778eec21e6426fcfefd95f0bb288771611f62d8e7d2d
 
 pkgname = plex-media-server-plexpass
Risk 0/5 · Safe PKGBUILD
Result #1969

Comment

The change only bumps Plex Pass version identifiers and updates the corresponding upstream package checksums for each architecture. No new sources, scripts, install hooks, or build logic were introduced, and the package still downloads from Plex's official HTTPS endpoints with pinned versioned URLs. The diff does not add any persistence, privilege escalation, or build-time network behavior beyond the existing package fetches. Risk is low.

@@ -13,8 +13,8 @@
 # Based on the plex-media-server package by Maxime Gauduin.
 
 pkgname=plex-media-server-plexpass
-pkgver=1.43.3.10861
-_pkgsum=07dfddaeb
+pkgver=1.43.3.10896
+_pkgsum=cb3ebc72d
 pkgrel=1
 pkgdesc='The back-end media server component of Plex.'
 arch=('x86_64' 'i686' 'armv7h' 'aarch64')
Risk 0/5 · Safe PKGBUILD
Result #1970

Comment

The change is a routine version bump in PKGBUILD: pkgver/_pkgsum and the per-architecture sha256sums were updated to match new upstream artifacts. There are no new sources, scripts, network fetches, privilege changes, or packaging logic changes in the diff. I see no security red flags in this hunk by itself.

@@ -43,10 +43,10 @@ sha256sums=('b7f2fb1cbedde54a79a1794ec9f35f8bdeb033a4c5453ec77944ca7fe77cd9b7'
             'c597bee0bcbb59ed791651555a904e5f7e9d2e82f6c6986b6352e5fc38e5b557'
             'b7ff6525a3c7a8be885edc85bb523095f8e25ddb38873127e2a4e97b28f2c7ad'
             '7bb97271eb2dc5d1dcb95f9763f505970d234df17f1b8d79b467b9020257915a')
-sha256sums_x86_64=('2c1ff73ffd2ab8c8523fb5d37394c3cccffe0e8bd662b8a78749a7385874fb6b')
-sha256sums_i686=('2d22d0061aefa7c9662fb86f6fcc19f02e6e2478f5b0fadc2dad24c4bd9d371c')
-sha256sums_armv7h=('f22851c1611d03df736fd0cd9af0bc15f53c8767fd1ff69a85febbaeb22feab9')
-sha256sums_aarch64=('2d4006110e55cd3920c82d8aec83db21b943d57430a94db486ffbd01902f15ae')
+sha256sums_x86_64=('ea678ff32fc7d42f9105d28ada1495f00ef5139c05550f37a68bacfefe1f4c31')
+sha256sums_i686=('565394c842ca75c171e89ed753d1fb15db5855e60d6bd467afd5ae6561e0e361')
+sha256sums_armv7h=('59a8f5ee5bcb64b8827e1d759855d5eca35b2f76eb8055df75cbbc3d01f09567')
+sha256sums_aarch64=('2a7ad1306795d391551d778eec21e6426fcfefd95f0bb288771611f62d8e7d2d')
 
 prepare() {
   if [[ $CARCH = armv7h ]] || [[ $CARCH = aarch64 ]]; then