Comment
The change only switches JetBrains download URLs from download-cf.jetbrains.com to download.jetbrains.com for the same CLion tarballs, with unchanged HTTPS and checksums. No build logic, install scripts, or package metadata beyond the source host changes are affected. This does not introduce a new trust boundary or execution path, so I see no security issue in the reviewed hunk.
@@ -13,9 +13,9 @@ pkgbase = clion
options = !strip
source = jetbrains-clion.desktop
sha256sums = a7a3f9891f5d8e7e5650afe00819909413fa2ed911393dd0648fba91233974a2
- source_x86_64 = https://download-cf.jetbrains.com/cpp/CLion-2026.2.3.1.tar.gz
+ source_x86_64 = https://download.jetbrains.com/cpp/CLion-2026.2.3.1.tar.gz
sha256sums_x86_64 = 8db6133c8ac63b8e492e5401f0f32026a9cdf698787f8578d20339c05e73c7c3
- source_aarch64 = https://download-cf.jetbrains.com/cpp/CLion-2026.2.3.1-aarch64.tar.gz
+ source_aarch64 = https://download.jetbrains.com/cpp/CLion-2026.2.3.1-aarch64.tar.gz
sha256sums_aarch64 = d511854dd3879ea6206cfb12ac1a46d0a5db03c6c11a726eb8ea52a6d94f3f23
pkgname = clion