Images and publishing
APT mirrors
Mirror Debian and Ubuntu archives for apt. Every package is checked and scanned.
- Settings, Registries: switch on APT mirror.
- Add an APT registry for each archive. Its address is the archive root, like
https://deb.debian.org/debian. Security updates are their own archive, likehttps://security.debian.org/debian-security. - Pick the advisory feed of its distro, like Debian:12, so its packages are checked against the right advisories.
- In whitelist mode, add an APT allow rule of
*, then deny or kill what you do not want. - Developers use the address the mirror shows, like
/apt/debian/. See Set up apt.
- By default each suite's InRelease goes out exactly as the distro signed it, and every download is checked: the rules, the kill switch, holds, advisories and cooling off.
- With Filtered index on, ForgeRepo™ first checks the distro's signature itself, then hands out Packages files of only what the rules and the kill switch allow, for amd64 and arm64, signed with its own key. Clients trust that key with signed-by. This works for the official Debian and Ubuntu archives.
- Every index file is checked against the SHA256 in InRelease, and every .deb against the SHA256 in its Packages file, before it is kept.
- Advisories come from OSV, in the feed you picked, by source package: libssl3 gets the advisories of openssl.
- The signing key is made on first use and kept in the cache folder. If it is ever lost, every client has to fetch the new one.