java-openjfx-bin

maintainer lapsus · 13 votes · scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged The package downloads official OpenJFX builds from Gluon's domain, which is the legitimate vendor; despite the static analyzer flagging the host as non-standard, the sources are verifiable and the content is non-executable libraries and docs, posing minimal risk.

Triggered rules

LOW AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads official OpenJFX builds from Gluon's domain, which is the legitimate vendor; despite the static analyzer flagging the host as non-standard, the sources are verifiable and the content is non-executable libraries and docs, posing minimal risk.

2 higher static findings superseded - not the current verdict (shown for transparency)
MEDIUM External download from an untrusted host, not in source=() external_download_not_in_source

curl/wget fetches a URL on a non-allowlisted host that is not part of source=(), so it is not checksum-verified by makepkg.

  • PKGBUILD:43 curl -fsSL https://repo1.maven.org/maven2/org/openjfx/javafx/maven-metadata.xml |
MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:33 source=("https://download2.gluonhq.com/openjfx/${pkgver}/openjfx-${pkgver}_linux-x64_bin-sdk.zip"

PKGBUILD

2 offending line(s) highlighted
1# Maintainer: Yakov Till <yakov.till@gmail.com>
2# Contributor: L B <leobaldin dot 2000 at gmail dot com>
3
4pkgname=java-openjfx-bin
5pkgver=26.0.2
6pkgrel=1
7pkgdesc="Java OpenJFX ${pkgver} client application platform (Gluon build)."
8arch=('x86_64')
9url='https://openjfx.io/'
10license=('GPL-2.0-only WITH Classpath-exception-2.0')
11depends=('java-environment>=24'
12 'alsa-lib'
13 'at-spi2-core'
14 'cairo'
15 'ffmpeg'
16 'ffmpeg4.4'
17 'fontconfig'
18 'freetype2'
19 'gdk-pixbuf2'
20 'glib2'
21 'gstreamer'
22 'gtk3'
23 'libglvnd'
24 'libx11'
25 'libxtst'
26 'libxxf86vm'
27 'pango'
28 'qt5-base'
29 'webkit2gtk-4.1')
30provides=("java-openjfx=${pkgver}")
31conflicts=('java-openjfx')
32options=('!strip' '!debug')
33source=("https://download2.gluonhq.com/openjfx/${pkgver}/openjfx-${pkgver}_linux-x64_bin-sdk.zip"
34 "https://download2.gluonhq.com/openjfx/${pkgver}/openjfx-${pkgver}_linux-x64_bin-jmods.zip"
35 "https://download2.gluonhq.com/openjfx/${pkgver}/openjfx-${pkgver}-javadoc.zip")
36sha256sums=('8ea7652becace5bf09dab4b855e30381f21fcd3a65a3dac74b69f63c6d175b66'
37 '7c32eee96c4f992cea43cecee77420a660478ee2776f0b7475e03fb40cbfae84'
38 'c2d3a32303b6b248fe1a2531f33f4edb2d583be9f1e4ac59ff88e1d875d2cb51')
39
40_jvmdir=usr/lib/jvm/java-${pkgver}-openjfx
41
42latestver() {
43 curl -fsSL https://repo1.maven.org/maven2/org/openjfx/javafx/maven-metadata.xml |
44 sed -nE 's:.*<version>([0-9]+(\.[0-9]+)*)</version>.*:\1:p' |
45 sort -V |
46 tail -1
47}
48
49package() {
50 # Install
51 install -d "${pkgdir}/${_jvmdir}"
52 cp -a "javafx-sdk-${pkgver}/lib" "${pkgdir}/${_jvmdir}/"
53 # Copy source archive
54 cp -a "javafx-sdk-${pkgver}/src.zip" "${pkgdir}/${_jvmdir}/"
55 mv "${pkgdir}/${_jvmdir}/src.zip" "${pkgdir}/${_jvmdir}/lib/javafx-src.zip"
56 # Legal
57 install -d "${pkgdir}/usr/share/licenses/${pkgname}"
58 cp -a "javafx-sdk-${pkgver}/legal" "${pkgdir}/usr/share/licenses/${pkgname}/"
59 # Jmods
60 install -d "${pkgdir}/${_jvmdir}/jmods"
61 cp -a "javafx-jmods-${pkgver}/"* "${pkgdir}/${_jvmdir}/jmods/"
62 # Docs
63 install -d "${pkgdir}/usr/share/doc/${pkgname}"
64 cp -a "javafx-${pkgver}-javadoc/"* "${pkgdir}/usr/share/doc/${pkgname}/"
65}
66

Changes since previous scan

--- PKGBUILD @ 2026-07-21 00:24
+++ PKGBUILD @ 2026-08-03 00:08
@@ -2,8 +2,8 @@
# Contributor: L B <leobaldin dot 2000 at gmail dot com>
pkgname=java-openjfx-bin
-pkgver=26.0.1
-pkgrel=2
+pkgver=26.0.2
+pkgrel=1
pkgdesc="Java OpenJFX ${pkgver} client application platform (Gluon build)."
arch=('x86_64')
url='https://openjfx.io/'
@@ -33,9 +33,9 @@
source=("https://download2.gluonhq.com/openjfx/${pkgver}/openjfx-${pkgver}_linux-x64_bin-sdk.zip"
"https://download2.gluonhq.com/openjfx/${pkgver}/openjfx-${pkgver}_linux-x64_bin-jmods.zip"
"https://download2.gluonhq.com/openjfx/${pkgver}/openjfx-${pkgver}-javadoc.zip")
-sha256sums=('af7bd9585d14fe6341b0bb6fec1c9c3a93d987c8b8aea4bf97c594714e3d1e31'
- '27f476c4628e14084af79bfef693f534351113bd793043412637dabd32ee35c7'
- '7f84f4d7cf21e5144ed8283b77b3fa6e2ee2df2b4cd0951080e3e2b2464c7c88')
+sha256sums=('8ea7652becace5bf09dab4b855e30381f21fcd3a65a3dac74b69f63c6d175b66'
+ '7c32eee96c4f992cea43cecee77420a660478ee2776f0b7475e03fb40cbfae84'
+ 'c2d3a32303b6b248fe1a2531f33f4edb2d583be9f1e4ac59ff88e1d875d2cb51')
_jvmdir=usr/lib/jvm/java-${pkgver}-openjfx

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 LOW 3
2026-08-02 00:16:08 LOW 3
2026-08-01 00:11:18 LOW 3
2026-07-31 00:14:10 LOW 3
2026-07-30 00:17:23 LOW 3
2026-07-29 00:25:53 LOW 3
2026-07-28 00:07:28 LOW 3
2026-07-27 00:24:32 LOW 3
2026-07-26 00:07:32 LOW 3
2026-07-25 00:13:44 LOW 3
2026-07-24 00:02:28 LOW 3
2026-07-23 00:14:47 LOW 3
2026-07-22 00:29:32 LOW 3
2026-07-21 19:17:41 MEDIUM 2
2026-07-21 00:24:15 LOW 3
2026-07-20 15:14:11 MEDIUM 2
2026-06-19 23:51:18 CLEAN 3
2026-06-19 22:34:54 MEDIUM 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion