Comment
The change is a straightforward version bump in .SRCINFO for an upstream Burp Suite JAR, with the source URL still using HTTPS on the official PortSwigger CDN and the checksum updated accordingly. No new sources, scripts, install logic, or packaging behavior are introduced by this diff. Based on the provided hunk alone, there are no obvious supply-chain or privilege-escalation concerns.
@@ -1,18 +1,18 @@
pkgbase = burpsuite
pkgdesc = An integrated platform for performing security testing of web applications (free edition)
- pkgver = 2026.7.1
+ pkgver = 2026.7.2
pkgrel = 1
url = https://portswigger.net/burp/
install = burpsuite.install
arch = any
license = custom
depends = java-runtime>=21
- noextract = burpsuite-2026.7.1.jar
- source = burpsuite-2026.7.1.jar::https://portswigger-cdn.net/burp/releases/download?product=desktop&version=2026.7.1&type=Jar
+ noextract = burpsuite-2026.7.2.jar
+ source = burpsuite-2026.7.2.jar::https://portswigger-cdn.net/burp/releases/download?product=desktop&version=2026.7.2&type=Jar
source = LICENSE
source = burpsuite.desktop
source = icon64.png
- sha256sums = 21aaf2b965e0932ca2a4d94c189c472a519c7f5bc71e01fb9b700db359bafb27
+ sha256sums = 58b9aebf4f512aae01e3f2f58961443dc938e458b1ff90d316cfcc3d82660bc3
sha256sums = a1146672de7084a1cddc5b7dab4d18b3530c194bd6e45a2b0ac04b579751ca30
sha256sums = 950c61d7ce1257c21a4152abebb8da320d0206ceb59247d6c912903d1ed39fc8
sha256sums = d31232a7dbdab9d5723f12aa25c52d13fd46ef2e8837a85fb9a08c3a7f151541