zulu-8-bin

LOW
maintainer yigitsalar 3 votes scanned 2026-10-06 00:13:36.889724
View on AUR
Why flagged

The package downloads prebuilt Zulu JDK binaries from Azul's official CDN (cdn.azul.com), which is the legitimate and expected source for these binaries; despite the static analyzer flag for a non-standard host, this is a trusted vendor domain, and the downloads are verified via sha256sums, making the risk low.

Triggered rules

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads prebuilt Zulu JDK binaries from Azul's official CDN (cdn.azul.com), which is the legitimate and expected source for these binaries; despite the static analyzer flag for a non-standard host, this is a trusted vendor domain, and the downloads are verified via sha256sums, making the risk low.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:32 source_aarch64=("https://cdn.azul.com/zulu/bin/zulu${_zulu_build}-ca-jdk${pkgver}-linux_aarch64.tar.gz")

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Yiğit Salar <yigit dot salar7 at gmail dot com>
2# Contributor: Sam Guymer <sam at guymer dot me>
3
4_jdkname=zulu-8
5pkgname="${_jdkname}-bin"
6_java_ver=8
7_zulu_build=8.96.0.205
8pkgver=8.0.504
9pkgrel=1
10pkgdesc='Zulu Community builds of OpenJDK are fully certified and 100% open source Java Development Kits (JDKs) for all Java development and production workloads.'
11arch=('aarch64' 'x86_64')
12url='https://azul.com/products/zulu-community'
13license=('custom')
14options=('!strip' '!debug')
15depends=(
16 'java-environment-common' 'java-runtime-common' 'ca-certificates-utils'
17 # not 100% sure if all of these dependencies are needed
18 # dependencies from jre8-openjdk-headless
19 'nss'
20 # dependencies from jre8-openjdk
21 'xdg-utils' 'hicolor-icon-theme'
22)
23provides=(
24 "java-environment=$_java_ver"
25 "java-environment-openjdk=$_java_ver"
26 "java-runtime-headless=$_java_ver"
27 "java-runtime-headless-openjdk=$_java_ver"
28 "java-runtime=$_java_ver"
29 "java-runtime-openjdk=$_java_ver"
30)
31install="$pkgname.install"
32source_aarch64=("https://cdn.azul.com/zulu/bin/zulu${_zulu_build}-ca-jdk${pkgver}-linux_aarch64.tar.gz")
33source_x86_64=("https://cdn.azul.com/zulu/bin/zulu${_zulu_build}-ca-jdk${pkgver}-linux_x64.tar.gz")
34sha256sums_aarch64=('c79f5fd740702a1336a9e6da2262be03e1a6e4255a94d198b66c49896be6b478')
35sha256sums_x86_64=('fdb93d3789f740c62b85c57a1c55db9960eb8bf6d7966ca8becd2a6be89bfcbf')
36
37_jvmdir="/usr/lib/jvm/${_jdkname}"
38
39# Upstream config files that should go to etc and get backup
40_conf_files=(
41 calendars.properties
42 content-types.properties
43 flavormap.properties
44 images/cursors/cursors.properties
45 logging.properties
46 management/jmxremote.access
47 management/jmxremote.password
48 management/management.properties
49 management/snmp.acl
50 net.properties
51 psfont.properties.ja
52 psfontj2d.properties
53 security/java.policy
54 security/java.security
55 sound.properties
56)
57
58package() {
59 if [ "${CARCH}" = "aarch64" ]; then
60 _conf_files+=('aarch64/jvm.cfg')
61 cd "$srcdir/zulu${_zulu_build}-ca-jdk${pkgver}-linux_aarch64"
62 else
63 _conf_files+=('amd64/jvm.cfg')
64 cd "$srcdir/zulu${_zulu_build}-ca-jdk${pkgver}-linux_x64"
65 fi
66
67 install -dm 755 "${pkgdir}/${_jvmdir}"
68 cp -a . "${pkgdir}/${_jvmdir}/"
69
70 # copied from java8-openjdk
71
72 # Set config files
73 mv "${pkgdir}${_jvmdir}"/jre/lib/management/jmxremote.password{.template,}
74 mv "${pkgdir}${_jvmdir}"/jre/lib/management/snmp.acl{.template,}
75
76 # Conf
77 install -dm 755 "${pkgdir}/etc/${_jdkname}"
78 for f in "${_conf_files[@]}"; do
79 _file="${_jvmdir}/jre/lib/$f"
80 install -D -m 644 "${pkgdir}${_file}" "${pkgdir}/etc/${_jdkname}/$f"
81 ln -sf "/etc/${_jdkname}/$f" "${pkgdir}${_file}"
82 done
83
84 # Install license
85 install -d -m 755 "${pkgdir}/usr/share/licenses/${pkgbase}/"
86 install -m 644 ASSEMBLY_EXCEPTION LICENSE THIRD_PARTY_README "${pkgdir}/usr/share/licenses/${pkgbase}"
87
88 # Man pages
89 for f in man/man1/* man/ja/man1/*; do
90 install -Dm 644 "${f}" "${pkgdir}/usr/share/${f/\.1/-zulu-8.1}"
91 done
92 rm -rf "${pkgdir}/${_jvmdir}/man"
93 ln -s /usr/share/man "${pkgdir}/${_jvmdir}/man"
94
95 # Link JKS keystore from ca-certificates-utils
96 rm -f "${pkgdir}${_jvmdir}/jre/lib/security/cacerts"
97 ln -sf /etc/ssl/certs/java/cacerts "${pkgdir}${_jvmdir}/jre/lib/security/cacerts"
98}
99

Scan history

Scanned at (UTC)SeverityRules
2026-10-06 00:13:36 Low 2
2026-10-05 00:08:03 Low 2
2026-10-04 00:18:08 Low 2
2026-10-03 00:23:04 Low 2
2026-10-02 00:00:32 Low 2
2026-10-01 00:02:06 Low 2
2026-09-30 00:20:07 Low 2
2026-09-29 00:07:46 Low 2
2026-09-28 00:28:32 Low 2
2026-09-27 00:07:07 Low 2
2026-09-26 00:12:15 Low 2
2026-09-25 00:03:36 Low 2
2026-09-24 00:24:14 Low 2
2026-09-23 00:28:13 Low 2
2026-09-22 00:15:14 Low 2
2026-09-21 00:26:32 Low 2
2026-09-20 00:25:31 Low 2
2026-09-19 00:25:36 Low 2
2026-09-18 00:17:11 Low 2
2026-09-17 00:27:14 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion