-
corretto-17
Amazon Corretto 17 is a no-cost, multi-platform, production-ready distribution of OpenJDK 17
Amazon Coretto updated their changelog, mentioning CVE-2022-21449 on the 12th of April.
-
SaaSHub
SaaSHub - Software Alternatives and Reviews. SaaSHub helps you find the best software and product alternatives
-
My impression is that Adoptium / Temurin usually takes an extra week or two just because of their release process: https://github.com/adoptium/adoptium/issues/139
-
Arch as well but the point about responsible disclosure is for the majority of users to have the patch before the vulnerability and POC are published. And I'd bet most Java web things are running on one of the unpatched builds (like Ubuntu with its 10 year LTS).
-
The move to the MS Build was purely because MS had apt repos out about 2 months before Adoptium got their sorted when they moved from Adopt to Adoptium. https://github.com/adoptium/installer/issues/330