amazon-corretto-8

maintainer eagletmt · 7 votes · scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged The package downloads Amazon Corretto OpenJDK tarballs from the official corretto.aws domain, which is the project's legitimate distribution host; despite the static analyzer flag for a non-standard host, this is a normal and trusted source for the software, and the PGP signature is verified, making the risk low.

Triggered rules

LOW AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads Amazon Corretto OpenJDK tarballs from the official corretto.aws domain, which is the project's legitimate distribution host; despite the static analyzer flag for a non-standard host, this is a normal and trusted source for the software, and the PGP signature is verified, making the risk low.

1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:14 source_x86_64=("https://corretto.aws/downloads/resources/${pkgver}/amazon-corretto-${pkgver}-linux-x64.tar.gz"{,.sig})

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Kohei Suzuki <eagletmt@gmail.com>
2pkgname=amazon-corretto-8
3pkgver=8.502.07.1
4pkgrel=2
5pkgdesc='No-cost, multiplatform, production-ready distribution of OpenJDK'
6arch=('x86_64' 'aarch64')
7url='https://aws.amazon.com/corretto/'
8license=('GPL2')
9depends=('java-runtime-common' 'java-environment-common')
10provides=('java-runtime-headless=8' 'java-runtime=8' 'java-environment=8')
11backup=()
12options=()
13# https://docs.aws.amazon.com/corretto/latest/corretto-8-ug/downloads-list.html
14source_x86_64=("https://corretto.aws/downloads/resources/${pkgver}/amazon-corretto-${pkgver}-linux-x64.tar.gz"{,.sig})
15source_aarch64=("https://corretto.aws/downloads/resources/${pkgver}/amazon-corretto-${pkgver}-linux-aarch64.tar.gz"{,.sig})
16validpgpkeys=('6DC3636DAE534049C8B94623A122542AB04F24E3') # Amazon Services LLC (Amazon Corretto release) <corretto-team@amazon.com>
17
18package() {
19 mkdir -p "$pkgdir/usr/lib/jvm"
20 case "$CARCH" in
21 "x86_64")
22 cp -a "amazon-corretto-$pkgver-linux-x64" "$pkgdir/usr/lib/jvm/java-8-amazon-corretto"
23 ;;
24 "aarch64")
25 cp -a "amazon-corretto-$pkgver-linux-aarch64" "$pkgdir/usr/lib/jvm/java-8-amazon-corretto"
26 ;;
27 esac
28}
29
30sha256sums_x86_64=('ff9b634a2a70b81b75e855be1db50ff712e4ea5f92dc224cb1c069122710b111'
31 'SKIP')
32sha256sums_aarch64=('7aafc6a9e4c284cbe9753ffe1af5495ca12370f6ac9f02e7ab1d81ef2f1d4c50'
33 'SKIP')
34

Changes since previous scan

--- PKGBUILD @ 2026-06-20 00:18
+++ PKGBUILD @ 2026-08-03 00:08
@@ -1,7 +1,7 @@
# Maintainer: Kohei Suzuki <eagletmt@gmail.com>
pkgname=amazon-corretto-8
-pkgver=8.492.09.2
-pkgrel=1
+pkgver=8.502.07.1
+pkgrel=2
pkgdesc='No-cost, multiplatform, production-ready distribution of OpenJDK'
arch=('x86_64' 'aarch64')
url='https://aws.amazon.com/corretto/'
@@ -27,8 +27,8 @@
esac
}
-sha256sums_x86_64=('b9a74845d1171eabd1482b43a759164efd529cf8317d7edc4484688b459c3a88'
+sha256sums_x86_64=('ff9b634a2a70b81b75e855be1db50ff712e4ea5f92dc224cb1c069122710b111'
'SKIP')
-sha256sums_aarch64=('1409bc282d3bdb0826a9cc1fec9704f924264dbde282e2aa1e09027aed5d6df2'
+sha256sums_aarch64=('7aafc6a9e4c284cbe9753ffe1af5495ca12370f6ac9f02e7ab1d81ef2f1d4c50'
'SKIP')

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 LOW 2
2026-08-02 00:16:08 LOW 2
2026-08-01 00:11:18 LOW 2
2026-07-31 00:14:10 LOW 2
2026-07-30 00:17:23 LOW 2
2026-07-29 00:25:53 LOW 2
2026-07-28 00:07:28 LOW 2
2026-07-27 00:24:32 LOW 2
2026-07-26 00:07:32 LOW 2
2026-07-25 00:13:44 LOW 2
2026-07-24 00:02:28 LOW 2
2026-07-23 00:14:47 LOW 2
2026-07-22 17:21:24 MEDIUM 1
2026-06-20 00:18:46 MEDIUM 1
2026-06-19 23:51:18 CLEAN 2
2026-06-19 19:07:35 LOW 2
2026-06-18 16:11:54 MEDIUM 1

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion