3 ms·
More precisely, an expiration timestamp is embedded in the repository metadata. Packages in debian and derivatives are not signed. Instead, the manifest that l
by na412 8y ago
More precisely, an expiration timestamp is embedded in the repository metadata.
Packages in debian and derivatives are not signed. Instead, the manifest that lists all the available packages and their checksums is signed. That's also where the expiration data is stored.
- JdeBP 8y agoEven more precisely still, not even the lists of packages are signed. Only InRelease and Release are signed, and they only contain the list of Package files. It's FreeBSD that has the approach of just one signed file containing everything. APT has moved closer to it over the years, but it is not there yet. * https://unix.stackexchange.com/a/332441/5132 https://unix.stackexchange.com/a/332441/5132