InterGenOS — Security is not first. It is only.

InterGenOS Package Repository

This is the binary package repository for InterGenOS. The package index is PGP-signed by the InterGenOS release key, and every package archive is hash-verified against that signed index by pkm before anything is installed.

The repository is live. The current release's full package set — 1,000+ packages — is published under /x86_64/current/: the signed InterGenOS.db index, per-package .igos.tar.gz archives, and the matching source archives under sources/. For the current release itself, see the repository README.

Installation images

Installation images are published under /iso/, each beside its SHA-256 checksum file, a detached signature over that checksum from the release key, a software bill of materials, and the release notes. Verify the checksum signature and then the image before writing it to a USB stick — the install guide walks the commands in order.

Using it

On an InterGenOS system, pkm fetches and verifies from here:

pkm sync             # fetch + verify the signed InterGenOS.db index
pkm install <name>   # download, hash-check, and install a package
pkm upgrade          # bring every installed package up to the index

pkm verifies the index signature against the release-key fingerprint pinned into the tool, then hash-checks every archive against the index before installing. None of these checks depends on trusting this page.

Trust chain

See the repository trust model and the signing key publication. The release public key is served beside the packages at intergenos-release-key.asc.