java-openjfx-bin

LOW
maintainer lapsus 12 votes scanned 2026-09-17 00:27:14.276658
View on AUR
Why flagged

The package downloads official OpenJFX builds from Gluon's domain, which is the legitimate vendor; despite the static analyzer flagging the host as non-standard, the sources are verifiable and the content is non-executable libraries and docs, posing minimal risk.

Triggered rules

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads official OpenJFX builds from Gluon's domain, which is the legitimate vendor; despite the static analyzer flagging the host as non-standard, the sources are verifiable and the content is non-executable libraries and docs, posing minimal risk.

2 higher static findings superseded - not the current verdict (shown for transparency)
Medium External download from an untrusted host, not in source=() external_download_not_in_source

curl/wget fetches a URL on a non-allowlisted host that is not part of source=(), so it is not checksum-verified by makepkg.

  • PKGBUILD:43 curl -fsSL https://repo1.maven.org/maven2/org/openjfx/javafx/maven-metadata.xml |
Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:33 source=("https://download2.gluonhq.com/openjfx/${pkgver}/openjfx-${pkgver}_linux-x64_bin-sdk.zip"

PKGBUILD

2 offending line(s) highlighted
1# Maintainer: Yakov Till <yakov.till@gmail.com>
2# Contributor: L B <leobaldin dot 2000 at gmail dot com>
3
4pkgname=java-openjfx-bin
5pkgver=26.0.2
6pkgrel=1
7pkgdesc="Java OpenJFX ${pkgver} client application platform (Gluon build)."
8arch=('x86_64')
9url='https://openjfx.io/'
10license=('GPL-2.0-only WITH Classpath-exception-2.0')
11depends=('java-environment>=24'
12 'alsa-lib'
13 'at-spi2-core'
14 'cairo'
15 'ffmpeg'
16 'ffmpeg4.4'
17 'fontconfig'
18 'freetype2'
19 'gdk-pixbuf2'
20 'glib2'
21 'gstreamer'
22 'gtk3'
23 'libglvnd'
24 'libx11'
25 'libxtst'
26 'libxxf86vm'
27 'pango'
28 'qt5-base'
29 'webkit2gtk-4.1')
30provides=("java-openjfx=${pkgver}")
31conflicts=('java-openjfx')
32options=('!strip' '!debug')
33source=("https://download2.gluonhq.com/openjfx/${pkgver}/openjfx-${pkgver}_linux-x64_bin-sdk.zip"
34 "https://download2.gluonhq.com/openjfx/${pkgver}/openjfx-${pkgver}_linux-x64_bin-jmods.zip"
35 "https://download2.gluonhq.com/openjfx/${pkgver}/openjfx-${pkgver}-javadoc.zip")
36sha256sums=('8ea7652becace5bf09dab4b855e30381f21fcd3a65a3dac74b69f63c6d175b66'
37 '7c32eee96c4f992cea43cecee77420a660478ee2776f0b7475e03fb40cbfae84'
38 'c2d3a32303b6b248fe1a2531f33f4edb2d583be9f1e4ac59ff88e1d875d2cb51')
39
40_jvmdir=usr/lib/jvm/java-${pkgver}-openjfx
41
42latestver() {
43 curl -fsSL https://repo1.maven.org/maven2/org/openjfx/javafx/maven-metadata.xml |
44 sed -nE 's:.*<version>([0-9]+(\.[0-9]+)*)</version>.*:\1:p' |
45 sort -V |
46 tail -1
47}
48
49package() {
50 # Install
51 install -d "${pkgdir}/${_jvmdir}"
52 cp -a "javafx-sdk-${pkgver}/lib" "${pkgdir}/${_jvmdir}/"
53 # Copy source archive
54 cp -a "javafx-sdk-${pkgver}/src.zip" "${pkgdir}/${_jvmdir}/"
55 mv "${pkgdir}/${_jvmdir}/src.zip" "${pkgdir}/${_jvmdir}/lib/javafx-src.zip"
56 # Legal
57 install -d "${pkgdir}/usr/share/licenses/${pkgname}"
58 cp -a "javafx-sdk-${pkgver}/legal" "${pkgdir}/usr/share/licenses/${pkgname}/"
59 # Jmods
60 install -d "${pkgdir}/${_jvmdir}/jmods"
61 cp -a "javafx-jmods-${pkgver}/"* "${pkgdir}/${_jvmdir}/jmods/"
62 # Docs
63 install -d "${pkgdir}/usr/share/doc/${pkgname}"
64 cp -a "javafx-${pkgver}-javadoc/"* "${pkgdir}/usr/share/doc/${pkgname}/"
65}
66

Scan history

Scanned at (UTC)SeverityRules
2026-09-17 00:27:14 Low 3
2026-09-16 00:03:17 Low 3
2026-09-15 00:25:31 Low 3
2026-09-14 00:27:57 Low 3
2026-09-13 00:19:54 Low 3
2026-09-12 00:25:17 Low 3
2026-09-11 00:19:22 Low 3
2026-09-10 00:22:44 Low 3
2026-09-09 00:04:09 Low 3
2026-09-08 00:18:08 Low 3
2026-09-07 00:30:15 Low 3
2026-09-06 00:17:06 Low 3
2026-09-05 00:16:27 Low 3
2026-09-04 00:03:13 Low 3
2026-09-03 00:15:47 Low 3
2026-09-02 00:02:31 Low 3
2026-09-01 00:11:19 Low 3
2026-08-31 00:19:57 Low 3
2026-08-30 00:04:14 Low 3
2026-08-29 00:29:17 Low 3

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion