
Curated repository of Qubes OS security bulletins, canaries, PGP keys, and ISO digests, with authenticated verification via git tags and detached signatures.
The Qubes security pack (qubes-secpack) is a git repository containing security-related information about the Qubes OS Project. It includes the following:
keys/)QSBs/)canaries/)fund/)digests/)The files contained in this repository can be authenticated in two ways:
git tag -v)All the keys used by the Qubes OS Project itself, including the keys used to sign files and commits in this repository (but excluding some keys owned by individual people), are ultimately signed by the Qubes Master Signing Key (QMSK). Even though the QMSK is included in this repo, you should make sure to obtain the QMSK fingerprint from multiple independent sources in several different ways as a fake Qubes security pack would contain a fake QMSK.
For more information about the Qubes security pack, including its history and rationale, and for detailed instructions for verifying its contents, please see the Qubes security pack (qubes-secpack) documentation page.