zulu-8-bin
The package downloads prebuilt Zulu JDK binaries from Azul's official CDN (cdn.azul.com), which is the legitimate and expected source for these binaries; despite the static analyzer flag for a non-standard host, this is a trusted vendor domain, and the downloads are verified via sha256sums, making the risk low.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads prebuilt Zulu JDK binaries from Azul's official CDN (cdn.azul.com), which is the legitimate and expected source for these binaries; despite the static analyzer flag for a non-standard host, this is a trusted vendor domain, and the downloads are verified via sha256sums, making the risk low.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:32
source_aarch64=("https://cdn.azul.com/zulu/bin/zulu${_zulu_build}-ca-jdk${pkgver}-linux_aarch64.tar.gz")
PKGBUILD
1 offending line(s) highlighted# Maintainer: Yiğit Salar <yigit dot salar7 at gmail dot com>
# Contributor: Sam Guymer <sam at guymer dot me>
_jdkname=zulu-8
pkgname="${_jdkname}-bin"
_java_ver=8
_zulu_build=8.96.0.205
pkgver=8.0.504
pkgrel=1
pkgdesc='Zulu Community builds of OpenJDK are fully certified and 100% open source Java Development Kits (JDKs) for all Java development and production workloads.'
arch=('aarch64' 'x86_64')
url='https://azul.com/products/zulu-community'
license=('custom')
options=('!strip' '!debug')
depends=(
'java-environment-common' 'java-runtime-common' 'ca-certificates-utils'
# not 100% sure if all of these dependencies are needed
# dependencies from jre8-openjdk-headless
'nss'
# dependencies from jre8-openjdk
'xdg-utils' 'hicolor-icon-theme'
)
provides=(
"java-environment=$_java_ver"
"java-environment-openjdk=$_java_ver"
"java-runtime-headless=$_java_ver"
"java-runtime-headless-openjdk=$_java_ver"
"java-runtime=$_java_ver"
"java-runtime-openjdk=$_java_ver"
)
install="$pkgname.install"
source_aarch64=("https://cdn.azul.com/zulu/bin/zulu${_zulu_build}-ca-jdk${pkgver}-linux_aarch64.tar.gz")
source_x86_64=("https://cdn.azul.com/zulu/bin/zulu${_zulu_build}-ca-jdk${pkgver}-linux_x64.tar.gz")
sha256sums_aarch64=('c79f5fd740702a1336a9e6da2262be03e1a6e4255a94d198b66c49896be6b478')
sha256sums_x86_64=('fdb93d3789f740c62b85c57a1c55db9960eb8bf6d7966ca8becd2a6be89bfcbf')
_jvmdir="/usr/lib/jvm/${_jdkname}"
# Upstream config files that should go to etc and get backup
_conf_files=(
calendars.properties
content-types.properties
flavormap.properties
images/cursors/cursors.properties
logging.properties
management/jmxremote.access
management/jmxremote.password
management/management.properties
management/snmp.acl
net.properties
psfont.properties.ja
psfontj2d.properties
security/java.policy
security/java.security
sound.properties
)
package() {
if [ "${CARCH}" = "aarch64" ]; then
_conf_files+=('aarch64/jvm.cfg')
cd "$srcdir/zulu${_zulu_build}-ca-jdk${pkgver}-linux_aarch64"
else
_conf_files+=('amd64/jvm.cfg')
cd "$srcdir/zulu${_zulu_build}-ca-jdk${pkgver}-linux_x64"
fi
install -dm 755 "${pkgdir}/${_jvmdir}"
cp -a . "${pkgdir}/${_jvmdir}/"
# copied from java8-openjdk
# Set config files
mv "${pkgdir}${_jvmdir}"/jre/lib/management/jmxremote.password{.template,}
mv "${pkgdir}${_jvmdir}"/jre/lib/management/snmp.acl{.template,}
# Conf
install -dm 755 "${pkgdir}/etc/${_jdkname}"
for f in "${_conf_files[@]}"; do
_file="${_jvmdir}/jre/lib/$f"
install -D -m 644 "${pkgdir}${_file}" "${pkgdir}/etc/${_jdkname}/$f"
ln -sf "/etc/${_jdkname}/$f" "${pkgdir}${_file}"
done
# Install license
install -d -m 755 "${pkgdir}/usr/share/licenses/${pkgbase}/"
install -m 644 ASSEMBLY_EXCEPTION LICENSE THIRD_PARTY_README "${pkgdir}/usr/share/licenses/${pkgbase}"
# Man pages
for f in man/man1/* man/ja/man1/*; do
install -Dm 644 "${f}" "${pkgdir}/usr/share/${f/\.1/-zulu-8.1}"
done
rm -rf "${pkgdir}/${_jvmdir}/man"
ln -s /usr/share/man "${pkgdir}/${_jvmdir}/man"
# Link JKS keystore from ca-certificates-utils
rm -f "${pkgdir}${_jvmdir}/jre/lib/security/cacerts"
ln -sf /etc/ssl/certs/java/cacerts "${pkgdir}${_jvmdir}/jre/lib/security/cacerts"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-10-06 00:13:36 | Low | 2 |
| 2026-10-05 00:08:03 | Low | 2 |
| 2026-10-04 00:18:08 | Low | 2 |
| 2026-10-03 00:23:04 | Low | 2 |
| 2026-10-02 00:00:32 | Low | 2 |
| 2026-10-01 00:02:06 | Low | 2 |
| 2026-09-30 00:20:07 | Low | 2 |
| 2026-09-29 00:07:46 | Low | 2 |
| 2026-09-28 00:28:32 | Low | 2 |
| 2026-09-27 00:07:07 | Low | 2 |
| 2026-09-26 00:12:15 | Low | 2 |
| 2026-09-25 00:03:36 | Low | 2 |
| 2026-09-24 00:24:14 | Low | 2 |
| 2026-09-23 00:28:13 | Low | 2 |
| 2026-09-22 00:15:14 | Low | 2 |
| 2026-09-21 00:26:32 | Low | 2 |
| 2026-09-20 00:25:31 | Low | 2 |
| 2026-09-19 00:25:36 | Low | 2 |
| 2026-09-18 00:17:11 | Low | 2 |
| 2026-09-17 00:27:14 | Low | 2 |