Loading the package list…
Verify the keys yourself
The bundle holds two public keys. The package key signs every
.rpm at build time. The metadata key signs the APT release
files and each RPM repository index. Both RPM checks are on by default
(gpgcheck=1 and repo_gpgcheck=1). On the APT side the signed
InRelease covers every package hash transitively.
curl -fsSL https://repo.kathara.org/RPM-GPG-KEY-kathara | gpg --show-keys
What is served here
| Path | Contents |
|---|---|
deb/dists/<suite>/, deb/pool/<suite>/ | APT indices and packages |
rpm/fedora/<releasever>/<basearch>/ | RPM packages and repodata/ |
kathara-archive-keyring.gpg / .asc | APT bootstrap keyring (metadata key) |
RPM-GPG-KEY-kathara | RPM public key bundle (package + metadata keys) |
kathara.repo | DNF bootstrap configuration |
packages.tsv | Everything published, one line per package |
