Linux workstation

Debian 12 (Bookworm) native package

libcairo2

Cairo 2D vector graphics library

Packages / Debian 12 (Bookworm) / libs / libcairo2

[Source: cairo]

Package: libcairo2 (1.16.0-7)

Maintainers:

Debian GNOME Maintainers

External Resources:

Homepage: [cairographics.org]

Similar packages:

Cairo 2D vector graphics library

Other Packages Related to libcairo2:

  • dep: [libc6] (>= 2.35)

    GNU C Library: Shared libraries

  • dep: [libfontconfig1] (>= 2.12.6)

    generic font configuration library - runtime

  • dep: [libfreetype6] (>= 2.9.1)

    FreeType 2 font engine, shared library files

  • dep: [libpixman-1-0] (>= 0.30.0)

    pixel-manipulation library for X and cairo

  • dep: [libpng16-16] (>= 1.6.2-1)

    PNG library - runtime (version 1.6)

  • dep: [libx11-6]

    X11 client-side library

  • dep: [libxcb-render0]

    X C Binding, render extension

  • dep: [libxcb-shm0]

    X C Binding, shm extension

  • dep: [libxcb1] (>= 1.6)

    X C Binding

  • dep: [libxext6]

    X11 miscellaneous extension library

  • dep: [libxrender1]

    X Rendering Extension client library

  • dep: [zlib1g] (>= 1:1.1.4)

    compression library - runtime

Download libcairo2

ArchitecturePackage SizeInstalled SizeFiles
amd64561 KiB1.3 MiB[list of files]
arm64514 KiB1.3 MiB[list of files]

Package file paths (7)

Paths come from the repository package-file index for the observed builds. They describe archive/package associations, not every file that will exist on a running system after maintainer scripts, alternatives, generated state, diversions, or installation choices.

  • /usr/lib/aarch64-linux-gnu/libcairo.so.2
  • /usr/lib/aarch64-linux-gnu/libcairo.so.2.11600.0
  • /usr/lib/x86_64-linux-gnu/libcairo.so.2
  • /usr/lib/x86_64-linux-gnu/libcairo.so.2.11600.0
  • /usr/share/doc/libcairo2/changelog.Debian.gz
  • /usr/share/doc/libcairo2/changelog.gz
  • /usr/share/doc/libcairo2/copyright

Field source: Debian 12 (Bookworm) main amd64 revision bookworm-main-amd64:9e0b5aabb2465b3d2e7a7fe27f9913846277833f7a2826e7767acccff5b588c5

Use this package

OpenFactory can boot this operating system in a browser VM, or start a build that includes the native package name from this record.

Versions, suites, and repositories

Each row is recorded package-index metadata for one version, architecture, suite, and repository. Names, URLs, and sizes are source-reported; a link is a potentially mutable retrieval location, not an OpenFactory redistribution claim or proof that OpenFactory retained the artifact bytes.

VersionReleaseArchitectureRepositoryPackage sizeInstalled sizePublisher repository artifact
1.16.0-7bookworm / mainamd64Debian 12 · main · amd64561 KiB1.3 MiBpool/main/c/cairo/libcairo2_1.16.0-7_amd64.deb
1.16.0-7bookworm / mainarm64Debian 12 · main · arm64514 KiB1.3 MiBpool/main/c/cairo/libcairo2_1.16.0-7_arm64.deb

Field source: Debian 12 (Bookworm) main amd64 revision bookworm-main-amd64:9e0b5aabb2465b3d2e7a7fe27f9913846277833f7a2826e7767acccff5b588c5

Checksums and observation dates

For an APT source, signature verification authenticates the repository metadata chain and the Packages index containing this source-reported artifact digest. It does not certify package safety.

1.16.0-7 / amd64Observed Sep 1, 2026 to Sep 1, 2026

Verification status: Metadata observed; artifact bytes were not independently fetched or hashed by this catalog import. The digest below is source-reported.

Source-reported sha256: 927fa059f8b5791d0cd744d4e3a8c57fa872ef849ce14434dc2222ac8a076a69

After downloading that exact artifact, compare its bytes with the source-reported expected digest:

printf '%s %s\n' '927fa059f8b5791d0cd744d4e3a8c57fa872ef849ce14434dc2222ac8a076a69' 'libcairo2_1.16.0-7_amd64.deb' | sha256sum --check --strict -

A match establishes equality with the repository metadata value. It does not establish safety or catalog-side artifact retrieval.

Field source: Debian 12 (Bookworm) main amd64 revision bookworm-main-amd64:9e0b5aabb2465b3d2e7a7fe27f9913846277833f7a2826e7767acccff5b588c5

1.16.0-7 / arm64Observed Sep 1, 2026 to Sep 1, 2026

Verification status: Metadata observed; artifact bytes were not independently fetched or hashed by this catalog import. The digest below is source-reported.

Source-reported sha256: 48b5c5ae1972ea0757c6285463d611d0ca32c9c808957961e5c7924126f30289

After downloading that exact artifact, compare its bytes with the source-reported expected digest:

printf '%s %s\n' '48b5c5ae1972ea0757c6285463d611d0ca32c9c808957961e5c7924126f30289' 'libcairo2_1.16.0-7_arm64.deb' | sha256sum --check --strict -

A match establishes equality with the repository metadata value. It does not establish safety or catalog-side artifact retrieval.

Field source: Debian 12 (Bookworm) main arm64 revision bookworm-main-arm64:2ddb1737692e8c45c53e8d57c0ce4cd21c78c5703b830c3226b1423566a06c00

Catalog record completeness

The completeness score measures metadata coverage, not software quality, security, compatibility, or suitability.

Summary and description
25/25
Artifact path and source digest
25/25
Dependency metadata
15/15
Package-file index
15/15
Homepage
5/5
License text
0/5
Source package or maintainer
10/10

Recorded total: 95/100

Field source: Debian 12 (Bookworm) main amd64 revision bookworm-main-amd64:9e0b5aabb2465b3d2e7a7fe27f9913846277833f7a2826e7767acccff5b588c5, Debian 12 (Bookworm) main arm64 revision bookworm-main-arm64:2ddb1737692e8c45c53e8d57c0ce4cd21c78c5703b830c3226b1423566a06c00. The cross-OS mapping is catalog-derived from the source-reported homepage; it does not establish authorship or publisher identity

Sources and provenance

Field-source links above resolve here. Each source entry names the metadata publisher, trust tier, exact snapshot revision, signature result, and observation time; catalog-derived mappings are labeled separately.

  • Authoritative source; repository metadata signature verified, revision bookworm-main-amd64:9e0b5aabb2465b3d2e7a7fe27f9913846277833f7a2826e7767acccff5b588c5

    Signature verification covers the configured repository metadata chain. It does not certify that the package is safe or suitable.

    Repository-signature verification record
    Signed-object SHA-256
    77737fa4b34f2693e982cc9ee35736816c35a7778fc2d326cc1bbf5b301fe1aa
    Signer fingerprint
    4CB50190207B4758A3F73A796ED0E7B82643E131
    Keyring revision
    debian-archive-keyring.gpg
    SHA-256 506b815cbb32d9b6066b4a2aa524071e071761e7e7f68c3ac74f3061ba852017
    Tool and policy
    gpgv (GnuPG) 2.4.9
    openfactory-software-catalog-signature-v1
    Verification time
    Sep 1, 2026
    Signed Release → package-index hash linkage

    Path: main/binary-amd64/Packages.xz
    Expected SHA-256: 9e0b5aabb2465b3d2e7a7fe27f9913846277833f7a2826e7767acccff5b588c5
    Observed SHA-256: 9e0b5aabb2465b3d2e7a7fe27f9913846277833f7a2826e7767acccff5b588c5
    Result: match verified

  • Authoritative source; repository metadata signature verified, revision bookworm-main-arm64:2ddb1737692e8c45c53e8d57c0ce4cd21c78c5703b830c3226b1423566a06c00

    Signature verification covers the configured repository metadata chain. It does not certify that the package is safe or suitable.

    Repository-signature verification record
    Signed-object SHA-256
    77737fa4b34f2693e982cc9ee35736816c35a7778fc2d326cc1bbf5b301fe1aa
    Signer fingerprint
    4CB50190207B4758A3F73A796ED0E7B82643E131
    Keyring revision
    debian-archive-keyring.gpg
    SHA-256 506b815cbb32d9b6066b4a2aa524071e071761e7e7f68c3ac74f3061ba852017
    Tool and policy
    gpgv (GnuPG) 2.4.9
    openfactory-software-catalog-signature-v1
    Verification time
    Sep 1, 2026
    Signed Release → package-index hash linkage

    Path: main/binary-arm64/Packages.xz
    Expected SHA-256: 2ddb1737692e8c45c53e8d57c0ce4cd21c78c5703b830c3226b1423566a06c00
    Observed SHA-256: 2ddb1737692e8c45c53e8d57c0ce4cd21c78c5703b830c3226b1423566a06c00
    Result: match verified