fcitx5-mozkey-ibg-ut

LOW
maintainer Masterisk-F 0 votes scanned 2026-08-28 15:38:44.104675
View on AUR
Why flagged

All sources are git checkouts from GitHub (the project's own repo and well-known utuhiro78 UT dictionary repos) plus a Wikipedia dump from dumps.wikimedia.org; the non-standard host flagged is dumps.wikimedia.org which is an official Wikimedia source for data files, not executable code; the package builds from source using bazelisk and installs the compiled binaries, which is normal AUR packaging practice.

Triggered rules

Low Few votes, recently uploaded zero_votes_recent

Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (anthropic/claude-sonnet-4.6) reviewed the full PKGBUILD and judged it LOW (confidence 75%): All sources are git checkouts from GitHub (the project's own repo and well-known utuhiro78 UT dictionary repos) plus a Wikipedia dump from dumps.wikimedia.org; the non-standard host flagged is dumps.wikimedia.org which is an official Wikimedia source for data files, not executable code; the package builds from source using bazelisk and installs the compiled binaries, which is normal AUR packaging practice.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:44 'https://dumps.wikimedia.org/jawiki/20260601/jawiki-20260601-pages-articles-multistream-index.txt.bz2')

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Masterisk-F <masterisk-f [at] proton DOT me>
2# Contributor: Nocifer <apmichalopoulos at gmail dot com>
3# Contributor: UTUMI Hirosi <utuhiro78 at yahoo dot co dot jp>
4# Contributor: Felix Yan <felixonmars@gmail.com>
5# Contributor: ponsfoot <cabezon dot hashimoto at gmail dot com>
6
7# UT 辞書のプロジェクトページ: https://utuhiro78.github.io/linuxplayers/mozc-ut.html
8
9ENABLED_DICTIONARIES=(
10 'alt-cannadic'
11 'edict2'
12 'jawiki'
13 'neologd'
14 'personal-names'
15 'place-names'
16 'skk-jisyo'
17 'sudachidict'
18)
19
20pkgname=fcitx5-mozkey-ibg-ut
21pkgver=0.10.4
22pkgrel=1
23pkgdesc='Mozkey IbG Japanese input method for Fcitx 5 with UT dictionaries'
24arch=('x86_64')
25url='https://github.com/kazormia296/mozkey-ibg'
26license=('Apache-2.0 AND BSD-2-Clause AND BSD-3-Clause AND CC0-1.0 AND CC-BY-2.5 AND CC-BY-SA-3.0 AND CC-BY-SA-4.0 AND GFDL-1.3-only AND GPL-2.0-only AND GPL-2.0-or-later AND LGPL-2.1-or-later AND MIT AND NAIST-2003 AND Unicode-3.0 AND LicenseRef-Okinawa-Dictionary')
27depends=('fcitx5' 'hicolor-icon-theme' 'llama-cpp' 'qt6-base')
28makedepends=('git' 'bazelisk' 'python' 'gettext' 'bzip2' 'pkg-config')
29provides=('mozkey-ibg=0.10.4' 'fcitx5-mozkey-ibg=0.10.4')
30conflicts=('mozkey-ibg' 'mozkey-ibg-bin' 'fcitx5-mozkey-ibg')
31options=('!debug' '!strip')
32source=(
33 "mozkey-ibg::git+https://github.com/kazormia296/mozkey-ibg.git#tag=v${pkgver}"
34 # UT dictionary
35 'git+https://github.com/utuhiro78/merge-ut-dictionaries.git#commit=15c1c64502b43e31d328012860376c03c3eaf633'
36 'git+https://github.com/utuhiro78/mozcdic-ut-alt-cannadic.git#commit=08e033f4558b7a0b03d8ad6920216d9473f15627'
37 'git+https://github.com/utuhiro78/mozcdic-ut-edict2.git#commit=d7279ba285fd5ddfe158b0bfd0c4fcda1f7b08c3'
38 'git+https://github.com/utuhiro78/mozcdic-ut-jawiki.git#commit=b50cabaecaf32c03d102db55fc5d0b98e334ec9e'
39 'git+https://github.com/utuhiro78/mozcdic-ut-neologd.git#commit=d8307abf02b830b185c9320822cffa0d0787c54e'
40 'git+https://github.com/utuhiro78/mozcdic-ut-personal-names.git#commit=5896ebef5f39d5772f4575fa05eb24436ce5a5f1'
41 'git+https://github.com/utuhiro78/mozcdic-ut-place-names.git#commit=6f9d9bda14f0bd2c10c1563d2aed9150ea95095c'
42 'git+https://github.com/utuhiro78/mozcdic-ut-skk-jisyo.git#commit=7c02e535bd6d999a715a53b58c3366f2401bfb7f'
43 'git+https://github.com/utuhiro78/mozcdic-ut-sudachidict.git#commit=7def3da408b1854801bd5b559273f9fb8001ef5b'
44 'https://dumps.wikimedia.org/jawiki/20260601/jawiki-20260601-pages-articles-multistream-index.txt.bz2')
45noextract=('jawiki-20260601-pages-articles-multistream-index.txt.bz2')
46b2sums=('33d7df80a31ed7bb126949fd0f995ff08c41753d15062ecb7a2bf058c5855685d60963270d4a77ffe351e7a9ee8e9acb83a5a2a4ab6f98401d493ebc7440e978'
47 '84150b8d743335d4b2801d15b74640380da0cfb95815bfc32a98f48f0fc7ac25b98ab417afee715c87a70dd8127568bd999e8e6a2c17da09d2a560fcdba030d3'
48 'f320adaf559ad3b51cb323c19f1ac0155f33f1b59939bfc34577f429cfc64d589271c5b6a9fe481fa7be6b97e7043832b0b7bf339e0559a836fa5a1b62101f5d'
49 'e9555a886657f237a55552f8f8aec769f0522cb54b4765f805ec1cd06dc80d8e8f735c35099132471bb46bda8219cf2991f6357b2cca5df24ff38f63c5d8f331'
50 '55a45669af70fa125127f27298f161180e7e6c4869611f6dc7a89416f0e82ed99453bdf87f674f5cd860acd174ab0ee14d3551d02fc1c2aa6ee8c38abb993a92'
51 '2eca0fd11c44091b2cf0a59de232a8d9b30e6c0a16cb4ece11d8a9f54457fe14b7ec9dd58aa1e67828df113d83a46b077a80b683333dc23a28617fbb3fe13fd0'
52 '83746b7d3b3cfe66e5f3b931abaf907fd37071a003d22e4d0cb065f91f554f33533104ed3b4dbe58840cdcb438dfa69882ea099fcfbfd0e8df0cf28417ae60a7'
53 'a93db79ae5e75ede45217f6a3feaf2982f2c948dfe4a0695854339f6baceda1358bf98f6118c4b7291fe2a11670e4e0e4c4164328fa03e9bad6aa7fd20bf54a5'
54 '1add7e57200df1899f48e0a0ba03351523c121eee95068aa7e332c3a3967089d78c4146ffd4528f0513b2228fbd2cfb72661b41427a6e3330b275edb83e23bbd'
55 '602388543678e45d4703e6165d718265a2a9e1a6f4c5359aa090ccd6eaa901d2f329da72814fc0064e9b08b936f70a0291d29da09b5d1ef68aa272058f589d44'
56 'cd4c02ee67d98084b6e4909eea77ca464d3cca838595538c5219710927aa42630fa67110f45297252c11f8e8c84d5a3c346a378b848d86ca14b4eb84505c1f74')
57
58prepare() {
59 cd "${srcdir}/merge-ut-dictionaries/src/merge/"
60
61 # 固定したローカルスナップショット(mozkey-ibg ソースと jawiki dump)を使う。
62 # merge_dictionaries.py は本来 Google の mozc-master.zip を取得するため、
63 # mozc-ut と同じ要領でローカルファイルを参照するよう書き換える。
64 sed -i -e "s|mozc-master/src/data/dictionary_oss|${srcdir}/mozkey-ibg/src/data/dictionary_oss|g ;
65 84s|ZipFile(f'mozc-{date_str}\.zip') as zip_ref|open('merge_dictionaries\.py') as dummy_ref| ;
66 86s|zip_ref\.|| ;
67 96s|zip_ref\.namelist()|os\.listdir(path='${srcdir}/mozkey-ibg/src/data/dictionary_oss')| ;
68 104s|zip_ref\.|| ;
69 169s|jawiki_index_file = .*|jawiki_index_file = '${srcdir}/jawiki-20260601-pages-articles-multistream-index.txt.bz2'| ;
70 152,168d;89,90d;80,83d;67,79d ;
71 7i import os" merge_dictionaries.py
72
73 # UT 辞書をコンパイルする
74 printf '\nCompiling the UT dictionary...\n\n'
75
76 [[ -e mozcdic-ut.txt ]] && rm mozcdic-ut.txt
77
78 for dict in "${ENABLED_DICTIONARIES[@]}"
79 do
80 bzip2 -dfk "${srcdir}"/mozcdic-ut-${dict}/mozcdic-ut-${dict}.txt.bz2
81 cat "${srcdir}"/mozcdic-ut-${dict}/mozcdic-ut-${dict}.txt >> mozcdic-ut.txt
82 done
83
84 python merge_dictionaries.py mozcdic-ut.txt
85
86 # UT 辞書を mozkey-ibg のベース辞書へ追記する
87 cat mozcdic-ut.txt >> "${srcdir}"/mozkey-ibg/src/data/dictionary_oss/dictionary00.txt
88}
89
90build() {
91 cd "${srcdir}/mozkey-ibg"
92
93 # コミット済みの Zenz GGUF はそのままでは llama.cpp が拒否するため、
94 # 上流の正規化ツールで llama.cpp 互換のメタデータへ変換して dist/ に生成する。
95 python3 tools/release/normalize_zenz_gguf.py create --root .
96
97 cd src
98 bazelisk build \
99 //unix/fcitx5:fcitx5-mozkey-ibg.so \
100 //unix/fcitx5:grimodex_consumer_tool \
101 //server:mozc_server \
102 //gui/tool:mozc_tool \
103 //zenz_scorer:mozc_zenz_scorer \
104 --config=oss_linux \
105 --config=release_build \
106 --config=no_sframe \
107 --//unix/fcitx5:use_server=true
108}
109
110package() {
111 cd "${srcdir}/mozkey-ibg"
112
113 addon_dir="$(pkg-config --variable=libdir Fcitx5Core)/fcitx5"
114
115 # サーバ本体・ツール・zenz scorer(製品固有の private libexec path)
116 install -Dm755 src/bazel-bin/server/mozc_server \
117 "${pkgdir}/usr/lib/mozkey-ibg/mozc_server"
118 install -Dm755 src/bazel-bin/gui/tool/mozc_tool \
119 "${pkgdir}/usr/lib/mozkey-ibg/mozc_tool"
120 install -Dm755 src/bazel-bin/zenz_scorer/mozc_zenz_scorer \
121 "${pkgdir}/usr/lib/mozkey-ibg/mozc_zenz_scorer"
122 install -Dm755 src/bazel-bin/unix/fcitx5/grimodex_consumer_tool \
123 "${pkgdir}/usr/lib/mozkey-ibg/unregister-grimodex-consumer"
124
125 # fcitx5 アドオン本体
126 install -Dm755 src/bazel-bin/unix/fcitx5/fcitx5-mozkey-ibg.so \
127 "${pkgdir}${addon_dir}/fcitx5-mozkey-ibg.so"
128
129 # fcitx5 メタデータ
130 install -Dm644 src/unix/fcitx5/mozkey-ibg-addon.conf \
131 "${pkgdir}/usr/share/fcitx5/addon/mozkey-ibg.conf"
132 install -Dm644 src/unix/fcitx5/mozkey-ibg.conf \
133 "${pkgdir}/usr/share/fcitx5/inputmethod/mozkey-ibg.conf"
134 msgfmt --xml -d src/unix/fcitx5/po/ \
135 --template src/unix/fcitx5/io.github.kazormia296.MozkeyIbG.metainfo.xml.in \
136 -o src/unix/fcitx5/io.github.kazormia296.MozkeyIbG.metainfo.xml
137 install -Dm644 src/unix/fcitx5/io.github.kazormia296.MozkeyIbG.metainfo.xml \
138 "${pkgdir}/usr/share/metainfo/io.github.kazormia296.MozkeyIbG.metainfo.xml"
139
140 # アドオン設置ディレクトリの記録(上流の fcitx5-addon-dir 相当)
141 install -d "${pkgdir}/usr/share/mozkey-ibg"
142 printf '%s\n' "${addon_dir}" > "${pkgdir}/usr/share/mozkey-ibg/fcitx5-addon-dir"
143
144 # 翻訳
145 for pofile in src/unix/fcitx5/po/*.po
146 do
147 lang="$(basename "${pofile}" .po)"
148 install -d "${pkgdir}/usr/share/locale/${lang}/LC_MESSAGES"
149 msgfmt "${pofile}" -o \
150 "${pkgdir}/usr/share/locale/${lang}/LC_MESSAGES/fcitx5-mozkey-ibg.mo"
151 done
152
153 # アイコン(hicolor)
154 local icon_dir="${pkgdir}/usr/share/icons/hicolor"
155 install -Dm644 src/data/images/product_icon_32bpp-128.png \
156 "${icon_dir}/128x128/apps/org.fcitx.Fcitx5.fcitx_mozkey_ibg.png"
157 install -Dm644 src/data/images/unix/ime_product_icon_opensource-32.png \
158 "${icon_dir}/32x32/apps/org.fcitx.Fcitx5.fcitx_mozkey_ibg.png"
159
160 local ui_name ui_dest
161 for pair in 'alpha_full:alpha_full' 'alpha_half:alpha_half' 'direct:direct' \
162 'hiragana:hiragana' 'katakana_full:katakana_full' \
163 'katakana_half:katakana_half' 'dictionary:dictionary' \
164 'properties:properties' 'tool:tool'
165 do
166 ui_name="${pair%%:*}"
167 ui_dest="${pair##*:}"
168 install -Dm644 "scripts/icons/ui-${ui_name}.png" \
169 "${icon_dir}/48x48/apps/org.fcitx.Fcitx5.fcitx_mozkey_ibg_${ui_dest}.png"
170 done
171
172 ln -sf org.fcitx.Fcitx5.fcitx_mozkey_ibg.png \
173 "${icon_dir}/128x128/apps/fcitx_mozkey_ibg.png"
174 ln -sf org.fcitx.Fcitx5.fcitx_mozkey_ibg.png \
175 "${icon_dir}/32x32/apps/fcitx_mozkey_ibg.png"
176 for pair in 'alpha_full:alpha_full' 'alpha_half:alpha_half' 'direct:direct' \
177 'hiragana:hiragana' 'katakana_full:katakana_full' \
178 'katakana_half:katakana_half' 'dictionary:dictionary' \
179 'properties:properties' 'tool:tool'
180 do
181 ui_dest="${pair##*:}"
182 ln -sf "org.fcitx.Fcitx5.fcitx_mozkey_ibg_${ui_dest}.png" \
183 "${icon_dir}/48x48/apps/fcitx_mozkey_ibg_${ui_dest}.png"
184 done
185
186 # Zenz(ローカル AI 補正)モデルと llama-server シンボリックリンク
187 install -Dm644 dist/zenz/linux/zenz-v3.2-small-Q5_K_M.gguf \
188 "${pkgdir}/usr/lib/mozkey-ibg/models/zenz-v3.2-small-Q5_K_M.gguf"
189 ln -sf /usr/bin/llama-server \
190 "${pkgdir}/usr/lib/mozkey-ibg/llama-server"
191
192 # ライセンス・通知(上流が持っているファイルのみをそのまま同梱する)
193 local licdir="${pkgdir}/usr/share/licenses/${pkgname}"
194
195 # Mozc (BSD-3-Clause) と Fcitx5 アダプタ(BSD-3-Clause / LGPL)
196 install -Dm644 LICENSE "${licdir}/Mozc-LICENSE.txt"
197 install -Dm644 LICENSES/Fcitx5-Mozc-BSD-3-Clause.txt \
198 "${licdir}/Fcitx5-Mozc-BSD-3-Clause.txt"
199 install -Dm644 LICENSES/LGPL-2.1-or-later.txt \
200 "${licdir}/LGPL-2.1-or-later.txt"
201 install -Dm644 THIRD_PARTY_NOTICES.md \
202 "${licdir}/THIRD_PARTY_NOTICES.md"
203
204 # UT 辞書ごとのライセンス(ソースリポジトリ付属の LICENSE をそのまま同梱)
205 for dict in "${ENABLED_DICTIONARIES[@]}"
206 do
207 install -Dm644 "${srcdir}/mozcdic-ut-${dict}/LICENSE" \
208 "${licdir}/ut/${dict}-LICENSE.txt"
209 done
210
211 # Zenz ランタイム / 辞書パイプラインの通知・ライセンス
212 install -Dm644 src/win32/installer/zenz_runtime/licenses/Apache-2.0.txt \
213 "${licdir}/dictionary/Apache-2.0.txt"
214 install -Dm644 tools/dictionary/RELEASE_THIRD_PARTY_NOTICES.md \
215 "${licdir}/dictionary/THIRD_PARTY_NOTICES.md"
216 install -Dm644 tools/dictionary/daily_sources.lock.json \
217 "${licdir}/dictionary/daily_sources.lock.json"
218 for zenz_license in \
219 zenz-v3.2-small-gguf.txt \
220 llama.cpp-MIT.txt \
221 cpp-httplib-MIT.txt \
222 nlohmann-json-MIT.txt \
223 Apache-2.0.txt \
224 THIRD_PARTY_NOTICES.md
225 do
226 install -Dm644 "src/win32/installer/zenz_runtime/licenses/${zenz_license}" \
227 "${licdir}/zenz-runtime/${zenz_license}"
228 done
229
230 # ドキュメント
231 for documentation_file in src/data/installer/*.html
232 do
233 install -Dm644 "${documentation_file}" \
234 "${pkgdir}/usr/share/doc/mozkey-ibg/$(basename -- "${documentation_file}")"
235 done
236}
237

Scan history

Scanned at (UTC)SeverityRules
2026-08-28 15:38:44 Low 3
2026-08-28 15:35:42 Medium 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion