amazon-corretto-11
maintainer eagletmt
· 9 votes
· scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged
The package downloads Amazon Corretto binaries from the official AWS domain, which is the legitimate source; the non-whitelisted host is a false concern as corretto.aws is the project's official distribution infrastructure.
Triggered rules
LOW
AI review downgraded a static finding
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads Amazon Corretto binaries from the official AWS domain, which is the legitimate source; the non-whitelisted host is a false concern as corretto.aws is the project's official distribution infrastructure.
1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM
source=() URL on a non-standard host
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:14
source_x86_64=("https://corretto.aws/downloads/resources/${pkgver}/amazon-corretto-${pkgver}-linux-x64.tar.gz"{,.sig})
PKGBUILD
1 offending line(s) highlighted
1
# Maintainer: Kohei Suzuki <eagletmt@gmail.com>
2
pkgname=amazon-corretto-11
3
pkgver=11.0.32.9.1
4
pkgrel=3
5
pkgdesc='No-cost, multiplatform, production-ready distribution of OpenJDK'
6
arch=('x86_64' 'aarch64')
7
url='https://aws.amazon.com/corretto/'
8
license=('GPL2')
9
depends=('java-runtime-common' 'java-environment-common')
10
provides=('java-runtime-headless=11' 'java-runtime=11' 'java-environment=11')
11
backup=()
12
options=()
13
# https://docs.aws.amazon.com/corretto/latest/corretto-11-ug/downloads-list.html
14
source_x86_64=("https://corretto.aws/downloads/resources/${pkgver}/amazon-corretto-${pkgver}-linux-x64.tar.gz"{,.sig})
15
source_aarch64=("https://corretto.aws/downloads/resources/${pkgver}/amazon-corretto-${pkgver}-linux-aarch64.tar.gz"{,.sig})
16
validpgpkeys=('6DC3636DAE534049C8B94623A122542AB04F24E3') # Amazon Services LLC (Amazon Corretto release) <corretto-team@amazon.com>
17
18
package() {
19
mkdir -p "$pkgdir/usr/lib/jvm"
20
case "$CARCH" in
21
"x86_64")
22
cp -a "amazon-corretto-$pkgver-linux-x64" "$pkgdir/usr/lib/jvm/java-11-amazon-corretto"
23
;;
24
"aarch64")
25
cp -a "amazon-corretto-$pkgver-linux-aarch64" "$pkgdir/usr/lib/jvm/java-11-amazon-corretto"
26
;;
27
esac
28
}
29
30
sha256sums_x86_64=('b09aac76316cef26dca770c89ca23ce55708bd0463e2640e86915ee528cb5bd0'
31
'SKIP')
32
sha256sums_aarch64=('c922bdb3b9ee3eb2e5c6c15f39147d79f4698cd17e181423fea46319b3891504'
33
'SKIP')
34
Changes since previous scan
--- PKGBUILD @ 2026-06-19 19:07+++ PKGBUILD @ 2026-08-03 00:08@@ -1,7 +1,7 @@ # Maintainer: Kohei Suzuki <eagletmt@gmail.com> pkgname=amazon-corretto-11-pkgver=11.0.31.11.1-pkgrel=1+pkgver=11.0.32.9.1+pkgrel=3 pkgdesc='No-cost, multiplatform, production-ready distribution of OpenJDK' arch=('x86_64' 'aarch64') url='https://aws.amazon.com/corretto/'@@ -27,8 +27,8 @@ esac } -sha256sums_x86_64=('70f6ff3668f27d1052f9e26c7a00d601774a556a49e6e9e7faa9d510ae1d0dbe'+sha256sums_x86_64=('b09aac76316cef26dca770c89ca23ce55708bd0463e2640e86915ee528cb5bd0' 'SKIP')-sha256sums_aarch64=('8ee5fba821463363dc76a18049e338d12c74752430a743aa405af126a62218da'+sha256sums_aarch64=('c922bdb3b9ee3eb2e5c6c15f39147d79f4698cd17e181423fea46319b3891504' 'SKIP') Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-08-03 00:08:14 | LOW | 2 |
| 2026-08-02 00:16:08 | LOW | 2 |
| 2026-08-01 00:11:18 | LOW | 2 |
| 2026-07-31 00:14:10 | LOW | 2 |
| 2026-07-30 00:17:23 | LOW | 2 |
| 2026-07-29 00:25:53 | LOW | 2 |
| 2026-07-28 00:07:28 | LOW | 2 |
| 2026-07-27 00:24:32 | LOW | 2 |
| 2026-07-26 00:07:32 | LOW | 2 |
| 2026-07-25 00:13:44 | LOW | 2 |
| 2026-07-24 00:02:28 | LOW | 2 |
| 2026-07-23 00:14:47 | LOW | 2 |
| 2026-07-22 17:21:24 | MEDIUM | 1 |
| 2026-06-19 19:07:35 | CLEAN | 2 |
| 2026-06-18 16:11:54 | MEDIUM | 1 |