Security

Signing trust chain, security updates and vulnerability reporting. The rolling-release security model: upstream patches land and are picked up immediately.

Signing & Trust

All Linxira packages and repository databases are signed with our own key and verified by pacman at install time. Keys are Ed25519, with a master Certify key kept offline and a separate Signing subkey used for day-to-day package and repo signing.

The signing public key ships with the system keyring package: installing Linxira or adding the [linxira] repository makes pacman import and trust the signing key automatically — no manual steps. Key material is only distributed through official release announcements and repository metadata; fingerprints are not published on this site.

Security Updates

Key Management Model

Private keys are protected with two independent layers:

The two passphrases are kept separately; leaking either alone does not expose usable private keys. Key files are archived offline as .asc.enc; plaintext private keys never enter any repository. Rotation or new-key issuance happens offline by the holder, then is re-encrypted into the vault.

Report a Vulnerability

For security issues in Linxira, please report privately via GitHub Security Advisory first: