Admin message

Due to an influx of spam, we have had to temporarily disable account registrations. Please write an email to accountsupport@archlinux.org, with your desired username, if you want to get access. Sorry for the inconvenience.

Closed
Milestone Jan 1, 2025–Dec 31, 2025

Distribution-agnostic OpenPGP stack for the verification of distribution artifacts

With this milestone we will provide a set of foundational libraries, based on a UAPI specification for the generic verification of distribution artifacts. These libraries will extend the use of a generic directory structure for OpenPGP certificates used for the verification of distribution artifacts and the use of PGPKI (aka the “Web of Trust”)

The libraries mentioned above will be integrated into the ALPM context to allow for example the full verification of packages and repository metadata. We will entirely replace the use of the legacy GnuPG software with a modern Rust-based approach in the package consumption and package source verification subsystems of the Arch Linux packaging stack.

  • Work items 11
  • Merge requests 4
  • Participants 3
  • Labels 7
Loading
Loading
Loading
Loading
100% complete
100%
Start date
Jan 1, 2025
Jan 1
-
Dec 31 2025
Due date
Dec 31, 2025 (Past due)
11
Work items 11 New issue
Open: 0 Closed: 11
None
Total weight
None
4
Merge requests 4
Open: 0 Closed: 2 Merged: 2
0
Releases
None
Reference: archlinux/alpm/alpm%"Distribution-agnostic OpenPGP stack for the verification of distribution artifacts"