OM omarpkg
Omarchy Package Repository

Packages you can inspect.

omarpkg turns a package request into a generated, reviewed, and traceable Arch build. The source stays visible. The signing key stays away from workers.

  1. 01
    Package request

    Name and upstream URL.

  2. 02
    Maintainer approval

    Area queue and security sign-off.

  3. 03
    Factory

    An agent generates the PKGBUILD.

  4. 04
    Human review

    A maintainer approves the generated diff.

  5. 05
    Build and signing

    Verified sources, an offline build, separate signing.

  6. 06
    Dev channel

    Quarantine, smoke tests, and feedback.

  7. 07
    Stable channel

    A maintainer promotes a compatible batch.

  8. 08
    Distribution

    Signed packages, recipes, and evidence.

0stable releases
0in dev
0open requests
Public catalogue

Latest releases

View all packages

No packages published yet.

The catalogue will show releases after a reviewed build reaches dev or stable. You can still request a package.

Request a package
Two distribution surfaces

Build records.

Redistributable software becomes a signed binary. Software we cannot redistribute remains a recipe that fetches vendor bytes with a pinned checksum.

Surface A · binaries

signed

omarpkg hosts packages whose license permits redistribution. Each release points to its source digest, build inputs, attestation, signature, and test evidence.

R2 artifact · pacman repository · immutable history

Surface B · recipes

vendor fetch

Chrome, NVIDIA, Zoom, Spotify, and similar packages keep their bytes at the vendor. omarpkg publishes the reviewed recipe and pinned checksum.

No proprietary bytes stored by omarpkg

Stable channel.

We cannot promise every package works perfectly. Package inputs, review decisions, build evidence, and signatures are visible. The pipeline is designed to prevent packages from attacking users.