Signing trust chain, security updates and vulnerability reporting. The rolling-release security model: upstream patches land and are picked up immediately.
All Linxira packages and repository databases are signed with our own key and verified by pacman at install time. Keys are Ed25519, with a master Certify key kept offline and a separate Signing subkey used for day-to-day package and repo signing.
The signing public key ships with the system keyring package: installing Linxira or adding the [linxira] repository makes pacman import and trust the signing key automatically — no manual steps. Key material is only distributed through official release announcements and repository metadata; fingerprints are not published on this site.
Private keys are protected with two independent layers:
The two passphrases are kept separately; leaking either alone does not expose usable private keys. Key files are archived offline as .asc.enc; plaintext private keys never enter any repository. Rotation or new-key issuance happens offline by the holder, then is re-encrypted into the vault.
For security issues in Linxira, please report privately via GitHub Security Advisory first: