AUR AI Reviewer

Review Results

Version #2686 of plex-media-server-plexpass · commit 2fcbac5f9fe3 · status Reviewed

Risk 0/5 · Safe .SRCINFO
Result #4477

Comment

The change only bumps pkgver in .SRCINFO from 1.43.4.10903 to 1.43.5.11029. No source URLs, checksums, build steps, install scripts, or packaging logic are modified in the reviewed diff, so there is no new security concern visible here. This is a routine version update in metadata only.

@@ -1,6 +1,6 @@
 pkgbase = plex-media-server-plexpass
 	pkgdesc = The back-end media server component of Plex.
-	pkgver = 1.43.4.10903
+	pkgver = 1.43.5.11029
 	pkgrel = 1
 	url = https://plex.tv/
 	install = plex-media-server.install
Risk 0/5 · Safe .SRCINFO
Result #4478

Comment

The change only updates the Plex binary package version and corresponding SHA256 checksums in .SRCINFO. The source URLs remain HTTPS and point to the official Plex download host, with no new sources, scripts, or build-time execution introduced. This is a routine version bump with no obvious supply-chain or persistence red flags in the diff provided.

@@ -27,13 +27,13 @@ pkgbase = plex-media-server-plexpass
 	sha256sums = c597bee0bcbb59ed791651555a904e5f7e9d2e82f6c6986b6352e5fc38e5b557
 	sha256sums = b7ff6525a3c7a8be885edc85bb523095f8e25ddb38873127e2a4e97b28f2c7ad
 	sha256sums = 7bb97271eb2dc5d1dcb95f9763f505970d234df17f1b8d79b467b9020257915a
-	source_x86_64 = https://downloads.plex.tv/plex-media-server-new/1.43.4.10903-e5521bd8c/redhat/plexmediaserver-1.43.4.10903-e5521bd8c.x86_64.rpm
-	sha256sums_x86_64 = 391598ee0e495794ad60a596eb7386435d4ce4bf5ff8e922cf1f686bee91467b
-	source_i686 = https://downloads.plex.tv/plex-media-server-new/1.43.4.10903-e5521bd8c/redhat/plexmediaserver-1.43.4.10903-e5521bd8c.i686.rpm
-	sha256sums_i686 = 51bb10dfedd829f6fd067e5ba62dd94e49f138f2b22dcff962b2c5eeac3fb726
-	source_armv7h = https://downloads.plex.tv/plex-media-server-new/1.43.4.10903-e5521bd8c/debian/plexmediaserver_1.43.4.10903-e5521bd8c_armhf.deb
-	sha256sums_armv7h = 908f716cebaf053500427ff132e56b59f4a69bfda5da927e8439bbf009cb1212
-	source_aarch64 = https://downloads.plex.tv/plex-media-server-new/1.43.4.10903-e5521bd8c/debian/plexmediaserver_1.43.4.10903-e5521bd8c_arm64.deb
-	sha256sums_aarch64 = 945e86d0514f61492b5169bbeac6e91892b336f6895d78632bec017b5908e5ab
+	source_x86_64 = https://downloads.plex.tv/plex-media-server-new/1.43.5.11029-6bf8af3f0/redhat/plexmediaserver-1.43.5.11029-6bf8af3f0.x86_64.rpm
+	sha256sums_x86_64 = 10bcea4e21088c018a11c018bb017255ba32629803314270d280b96361b283f0
+	source_i686 = https://downloads.plex.tv/plex-media-server-new/1.43.5.11029-6bf8af3f0/redhat/plexmediaserver-1.43.5.11029-6bf8af3f0.i686.rpm
+	sha256sums_i686 = befc40d9979cd002528f6970d658653ca80da10572934636ff1b2aa1bf3ac7b3
+	source_armv7h = https://downloads.plex.tv/plex-media-server-new/1.43.5.11029-6bf8af3f0/debian/plexmediaserver_1.43.5.11029-6bf8af3f0_armhf.deb
+	sha256sums_armv7h = 02fdcf29f378de74905140df0e7671014e764fd09358f9b3e264e4c699a5cb9c
+	source_aarch64 = https://downloads.plex.tv/plex-media-server-new/1.43.5.11029-6bf8af3f0/debian/plexmediaserver_1.43.5.11029-6bf8af3f0_arm64.deb
+	sha256sums_aarch64 = b289c218db9c4efa81effab8efb82ca9aba5576f58e95aeb7c485b07db41ec1b
 
 pkgname = plex-media-server-plexpass
Risk 0/5 · Safe PKGBUILD
Result #4479

Comment

The change is a straightforward version bump in PKGBUILD: pkgver and the corresponding upstream checksum fragment were updated. No new sources, scripts, install hooks, permissions changes, or build-time network behavior were introduced in the provided diff hunk. Based on this hunk alone, there are no evident security concerns.

@@ -13,8 +13,8 @@
 # Based on the plex-media-server package by Maxime Gauduin.
 
 pkgname=plex-media-server-plexpass
-pkgver=1.43.4.10903
-_pkgsum=e5521bd8c
+pkgver=1.43.5.11029
+_pkgsum=6bf8af3f0
 pkgrel=1
 pkgdesc='The back-end media server component of Plex.'
 arch=('x86_64' 'i686' 'armv7h' 'aarch64')
Risk 0/5 · Safe PKGBUILD
Result #4480

Comment

The change only updates architecture-specific SHA-256 checksums in PKGBUILD. This is a normal integrity update for new upstream artifacts and does not introduce new sources, commands, network access, privilege changes, or packaging behavior changes. No security red flags are evident from the diff hunk provided.

@@ -43,10 +43,10 @@ sha256sums=('b7f2fb1cbedde54a79a1794ec9f35f8bdeb033a4c5453ec77944ca7fe77cd9b7'
             'c597bee0bcbb59ed791651555a904e5f7e9d2e82f6c6986b6352e5fc38e5b557'
             'b7ff6525a3c7a8be885edc85bb523095f8e25ddb38873127e2a4e97b28f2c7ad'
             '7bb97271eb2dc5d1dcb95f9763f505970d234df17f1b8d79b467b9020257915a')
-sha256sums_x86_64=('391598ee0e495794ad60a596eb7386435d4ce4bf5ff8e922cf1f686bee91467b')
-sha256sums_i686=('51bb10dfedd829f6fd067e5ba62dd94e49f138f2b22dcff962b2c5eeac3fb726')
-sha256sums_armv7h=('908f716cebaf053500427ff132e56b59f4a69bfda5da927e8439bbf009cb1212')
-sha256sums_aarch64=('945e86d0514f61492b5169bbeac6e91892b336f6895d78632bec017b5908e5ab')
+sha256sums_x86_64=('10bcea4e21088c018a11c018bb017255ba32629803314270d280b96361b283f0')
+sha256sums_i686=('befc40d9979cd002528f6970d658653ca80da10572934636ff1b2aa1bf3ac7b3')
+sha256sums_armv7h=('02fdcf29f378de74905140df0e7671014e764fd09358f9b3e264e4c699a5cb9c')
+sha256sums_aarch64=('b289c218db9c4efa81effab8efb82ca9aba5576f58e95aeb7c485b07db41ec1b')
 
 prepare() {
   if [[ $CARCH = armv7h ]] || [[ $CARCH = aarch64 ]]; then