Surface A · binaries
signedomarpkg hosts packages whose license permits redistribution. Each release points to its source digest, build inputs, attestation, signature, and test evidence.
omarpkg turns a package request into a generated, reviewed, and traceable Arch build. The source stays visible. The signing key stays away from workers.
Name and upstream URL.
Area queue and security sign-off.
An agent generates the PKGBUILD.
A maintainer approves the generated diff.
Verified sources, an offline build, separate signing.
Quarantine, smoke tests, and feedback.
A maintainer promotes a compatible batch.
Signed packages, recipes, and evidence.
The catalogue will show releases after a reviewed build reaches dev or stable. You can still request a package.
Request a packageRedistributable software becomes a signed binary. Software we cannot redistribute remains a recipe that fetches vendor bytes with a pinned checksum.
omarpkg hosts packages whose license permits redistribution. Each release points to its source digest, build inputs, attestation, signature, and test evidence.
Chrome, NVIDIA, Zoom, Spotify, and similar packages keep their bytes at the vendor. omarpkg publishes the reviewed recipe and pinned checksum.
We cannot promise every package works perfectly. Package inputs, review decisions, build evidence, and signatures are visible. The pipeline is designed to prevent packages from attacking users.