latin-words
The source is a static data archive from a reputable web archive (archive.org) of an official academic project's content; it is not executable code, and the worst case of a swapped source is data tampering, not code execution.
Triggered rules
llm_review
The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The source is a static data archive from a reputable web archive (archive.org) of an official academic project's content; it is not executable code, and the worst case of a swapped source is data tampering, not code execution.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:16
source=("$pkgname-$pkgver.zip::http://web.archive.org/web/20230328161642/http://archives.nd.edu/whitaker/old/wordsall.zip")
PKGBUILD
1 offending line(s) highlighted# Former maintainers:
# * Orivej Desh <smpuj@bk.ru>
# * Stefan Husmann <stefan-husmann@t-online.de>
# Maintainer: Vitrum <wqdxosty1yhj@bk.ru>
pkgname=latin-words
pkgver=1.97FC
pkgrel=7
pkgdesc="William Whitaker's Latin-English-Latin intelligent dictionary and Latin text analyser."
arch=("i686" "x86_64")
url="http://archives.nd.edu/whitaker/words.htm"
license=('custom')
depends=('bash')
makedepends=('gcc-ada')
source=("$pkgname-$pkgver.zip::http://web.archive.org/web/20230328161642/http://archives.nd.edu/whitaker/old/wordsall.zip")
sha256sums=('592134d7602879e0937b6f977a6f63aa1d14b813edaf6de04a1d8596a9a2c18e')
# Alternative source:
#source=("$pkgname-$pkgver::git://github.com/dsanson/Words.git")
#sha256sums=('SKIP')
prepare() {
cd "$srcdir"
sed -i 's/PAUSE_IN_SCREEN_OUTPUT => TRUE/PAUSE_IN_SCREEN_OUTPUT => FALSE/g' developer_parameters.adb
}
build() {
cd "$srcdir"
gnatmake -O3 words
gnatmake makedict && echo "g" | ./makedict
gnatmake makestem && echo "g" | ./makestem
gnatmake makeefil && ./makeefil
gnatmake makeinfl && ./makeinfl
}
package() {
cd "$srcdir"
# main application
install -D words "$pkgdir/usr/share/words-$pkgver/words"
install -m644 ADDONS.LAT DICTFILE.GEN EWDSFILE.GEN INDXFILE.GEN \
INFLECTS.SEC STEMFILE.GEN UNIQUES.LAT \
"$pkgdir/usr/share/words-$pkgver/"
# documentation
install -Dm644 wordsdoc.htm "$pkgdir/usr/share/doc/words-$pkgver/wordsdoc.htm"
# starting script
cat > words.sh <<-EOF
#!/bin/bash
pushd /usr/share/words-$pkgver >/dev/null
./words "\$@"
popd >/dev/null
EOF
install -Dm755 words.sh "$pkgdir/usr/bin/words"
# license
cat > LICENSE <<-EOF
Quoting from wordsdoc.htm:
This is a free program, which means it is proper to copy it and pass it on to
your friends. Consider it a developmental item for which there is no charge.
However, just for form, it is Copyrighted (c). Permission is hereby freely
given for any and all use of program and data. You can sell it as your own,
but at least tell me.
and later in the same document:
Licence
All parts of the WORDS system, source code and data files, are made freely
available to anyone who wishes to use them, for whatever purpose.
EOF
install -Dm644 LICENSE "$pkgdir/usr/share/licenses/latin-words/LICENSE"
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-09-17 00:27:14 | Low | 2 |
| 2026-09-16 00:03:17 | Low | 2 |
| 2026-09-15 00:25:31 | Low | 2 |
| 2026-09-14 00:27:57 | Low | 2 |
| 2026-09-13 00:19:54 | Low | 2 |
| 2026-09-12 00:25:17 | Low | 2 |
| 2026-09-11 00:19:22 | Low | 2 |
| 2026-09-10 00:22:44 | Low | 2 |
| 2026-09-09 00:04:09 | Low | 2 |
| 2026-09-08 00:18:08 | Low | 2 |
| 2026-09-07 00:30:15 | Low | 2 |
| 2026-09-06 00:17:06 | Low | 2 |
| 2026-09-05 00:16:27 | Low | 2 |
| 2026-09-04 00:03:13 | Low | 2 |
| 2026-09-03 00:15:47 | Low | 2 |
| 2026-09-02 00:02:31 | Low | 2 |
| 2026-09-01 00:11:19 | Low | 2 |
| 2026-08-31 00:19:57 | Low | 2 |
| 2026-08-30 00:04:14 | Low | 2 |
| 2026-08-29 00:29:17 | Low | 2 |