Linux workstation

Debian 13 (Trixie) native package

picom

lightweight compositor for X11

Packages / Debian 13 (Trixie) / x11 / picom

Package: picom (12.5-1)

Maintainers:

Nikos Tsipinakis

External Resources:

Homepage: [github.com]

lightweight compositor for X11

Other Packages Related to picom:

  • dep: [python3]

    interactive high-level object-oriented language (default python3 version)

  • dep: [libc6] (>= 2.38)

    GNU C Library: Shared libraries

  • dep: [libconfig11] (>= 1.7.3)

    parsing/manipulation of structured configuration files

  • dep: [libdbus-1-3] (>= 1.10)

    simple interprocess messaging system (library)

  • dep: [libepoxy0] (>= 1.5.4)

    OpenGL function pointer management library

  • dep: [libev4t64] (>= 1:4.04)

    high-performance event loop library modelled after libevent

  • dep: [libpcre2-8-0] (>= 10.22)

    New Perl Compatible Regular Expression Library- 8 bit runtime files

  • dep: [libpixman-1-0] (>= 0.25.2)

    pixel-manipulation library for X and cairo

  • dep: [libx11-6]

    X11 client-side library

  • dep: [libx11-xcb1]

    Xlib/XCB interface library

  • dep: [libxcb-composite0]

    X C Binding, composite extension

  • dep: [libxcb-damage0]

    X C Binding, damage extension

  • dep: [libxcb-glx0]

    X C Binding, glx extension

  • dep: [libxcb-image0] (>= 0.2.1)

    utility libraries for X C Binding -- image

  • dep: [libxcb-present0]

    X C Binding, present extension

  • dep: [libxcb-randr0] (>= 1.12)

    X C Binding, randr extension

  • dep: [libxcb-render-util0]

    utility libraries for X C Binding -- render-util

  • dep: [libxcb-render0] (>= 1.12)

    X C Binding, render extension

  • dep: [libxcb-shape0]

    X C Binding, shape extension

  • dep: [libxcb-sync1]

    X C Binding, sync extension

  • dep: [libxcb-util1] (>= 0.4.0)

    utility libraries for X C Binding -- atom, aux and event

  • dep: [libxcb-xfixes0]

    X C Binding, xfixes extension

  • dep: [libxcb1] (>= 1.9.2)

    X C Binding

Download picom

ArchitecturePackage SizeInstalled SizeFiles
amd64279 KiB900 KiB[list of files]

Package file paths (15)

Paths come from the repository package-file index for the observed builds. They describe archive/package associations, not every file that will exist on a running system after maintainer scripts, alternatives, generated state, diversions, or installation choices.

  • /etc/xdg/autostart/picom.desktop
  • /usr/bin/picom
  • /usr/bin/picom-inspect
  • /usr/bin/picom-trans
  • /usr/lib/aarch64-linux-gnu/pkgconfig/picom-api.pc
  • /usr/lib/x86_64-linux-gnu/pkgconfig/picom-api.pc
  • /usr/share/applications/picom.desktop
  • /usr/share/doc/picom/changelog.Debian.gz
  • /usr/share/doc/picom/changelog.gz
  • /usr/share/doc/picom/copyright
  • /usr/share/doc/picom/examples/picom.sample.conf
  • /usr/share/doc/picom/README.md.gz
  • /usr/share/man/man1/picom.1.gz
  • /usr/share/man/man1/picom-inspect.1.gz
  • /usr/share/man/man1/picom-trans.1.gz

Field source: Debian 13 (Trixie) main amd64 revision trixie-main-amd64:3ab4e811cf4f3e5a335d382c58cc19d85f1abe7a4ef4689160ca1f637fa0e9b3

Use this package

OpenFactory can boot this operating system in a browser VM, or start a build that includes the native package name from this record.

Versions, suites, and repositories

Each row is recorded package-index metadata for one version, architecture, suite, and repository. Names, URLs, and sizes are source-reported; a link is a potentially mutable retrieval location, not an OpenFactory redistribution claim or proof that OpenFactory retained the artifact bytes.

VersionReleaseArchitectureRepositoryPackage sizeInstalled sizePublisher repository artifact
12.5-1trixie / mainamd64Debian 13 · main · amd64279 KiB900 KiBpool/main/p/picom/picom_12.5-1_amd64.deb

Field source: Debian 13 (Trixie) main amd64 revision trixie-main-amd64:3ab4e811cf4f3e5a335d382c58cc19d85f1abe7a4ef4689160ca1f637fa0e9b3

Checksums and observation dates

For an APT source, signature verification authenticates the repository metadata chain and the Packages index containing this source-reported artifact digest. It does not certify package safety.

12.5-1 / amd64Observed Sep 1, 2026 to Sep 1, 2026

Verification status: Metadata observed; artifact bytes were not independently fetched or hashed by this catalog import. The digest below is source-reported.

Source-reported sha256: 4d5054faf9ef9af5e16b0720433a30968f17bfb6cae7bc64212492f8cbbc7b52

After downloading that exact artifact, compare its bytes with the source-reported expected digest:

printf '%s %s\n' '4d5054faf9ef9af5e16b0720433a30968f17bfb6cae7bc64212492f8cbbc7b52' 'picom_12.5-1_amd64.deb' | sha256sum --check --strict -

A match establishes equality with the repository metadata value. It does not establish safety or catalog-side artifact retrieval.

Field source: Debian 13 (Trixie) main amd64 revision trixie-main-amd64:3ab4e811cf4f3e5a335d382c58cc19d85f1abe7a4ef4689160ca1f637fa0e9b3

Catalog record completeness

The completeness score measures metadata coverage, not software quality, security, compatibility, or suitability.

Summary and description
25/25
Artifact path and source digest
25/25
Dependency metadata
15/15
Package-file index
15/15
Homepage
5/5
License text
0/5
Source package or maintainer
10/10

Recorded total: 95/100

Field source: Debian 13 (Trixie) main amd64 revision trixie-main-amd64:3ab4e811cf4f3e5a335d382c58cc19d85f1abe7a4ef4689160ca1f637fa0e9b3, Debian 13 (Trixie) main arm64 revision trixie-main-arm64:753da751bbc7a679f48bd1b623ffd4479cb6861c426118284c76eb82909e4908. The cross-OS mapping is catalog-derived from the source-reported homepage; it does not establish authorship or publisher identity

Sources and provenance

Field-source links above resolve here. Each source entry names the metadata publisher, trust tier, exact snapshot revision, signature result, and observation time; catalog-derived mappings are labeled separately.

  • Authoritative source; repository metadata signature verified, revision trixie-main-amd64:3ab4e811cf4f3e5a335d382c58cc19d85f1abe7a4ef4689160ca1f637fa0e9b3

    Signature verification covers the configured repository metadata chain. It does not certify that the package is safe or suitable.

    Repository-signature verification record
    Signed-object SHA-256
    98b25b5cd185c59d34aa6e4c3e9b5b8f01bbe9d104fe2dcfbcd30dc0a14a59ed
    Signer fingerprint
    4CB50190207B4758A3F73A796ED0E7B82643E131
    Keyring revision
    debian-archive-keyring.gpg
    SHA-256 506b815cbb32d9b6066b4a2aa524071e071761e7e7f68c3ac74f3061ba852017
    Tool and policy
    gpgv (GnuPG) 2.4.9
    openfactory-software-catalog-signature-v1
    Verification time
    Sep 1, 2026
    Signed Release → package-index hash linkage

    Path: main/binary-amd64/Packages.xz
    Expected SHA-256: 3ab4e811cf4f3e5a335d382c58cc19d85f1abe7a4ef4689160ca1f637fa0e9b3
    Observed SHA-256: 3ab4e811cf4f3e5a335d382c58cc19d85f1abe7a4ef4689160ca1f637fa0e9b3
    Result: match verified

  • Authoritative source; repository metadata signature verified, revision trixie-main-arm64:753da751bbc7a679f48bd1b623ffd4479cb6861c426118284c76eb82909e4908

    Signature verification covers the configured repository metadata chain. It does not certify that the package is safe or suitable.

    Repository-signature verification record
    Signed-object SHA-256
    98b25b5cd185c59d34aa6e4c3e9b5b8f01bbe9d104fe2dcfbcd30dc0a14a59ed
    Signer fingerprint
    4CB50190207B4758A3F73A796ED0E7B82643E131
    Keyring revision
    debian-archive-keyring.gpg
    SHA-256 506b815cbb32d9b6066b4a2aa524071e071761e7e7f68c3ac74f3061ba852017
    Tool and policy
    gpgv (GnuPG) 2.4.9
    openfactory-software-catalog-signature-v1
    Verification time
    Sep 1, 2026
    Signed Release → package-index hash linkage

    Path: main/binary-arm64/Packages.xz
    Expected SHA-256: 753da751bbc7a679f48bd1b623ffd4479cb6861c426118284c76eb82909e4908
    Observed SHA-256: 753da751bbc7a679f48bd1b623ffd4479cb6861c426118284c76eb82909e4908
    Result: match verified