Linux workstation

Debian 13 (Trixie) native package

signapk

Command line tool for signing Android ZIP/JAR/APK

Packages / Debian 13 (Trixie) / devel / signapk

[Source: android-platform-build]

Package: signapk (1:10.0.0+r36-1.1)

Maintainers:

Android Tools Maintainers

External Resources:

Homepage: [android.googlesource.com]

Similar packages:

  • [android-logtags-tools]

    Tools from AOSP that process event-log-tags files

  • [makeparallel]

    Command line tool for communication with the GNU make jobserver

  • [signtos]

    Android signing tool for signing Trusty images

  • [zipalign]

    Zip archive alignment tool

  • [ziptime]

    Zip archive timestamp remover

Command line tool for signing Android ZIP/JAR/APK

Other Packages Related to signapk:

  • dep: [default-jre]

    Standard Java or Java compatible Runtime

  • dep: java9-runtime

    Package not available

  • dep: java10-runtime

    Package not available

  • dep: java11-runtime

    Package not available

  • dep: [jarwrapper] (>= 0.5)

    Run executable Java .jar files

  • dep: [libapksig-java]

    library to sign and verify Android APKs

  • dep: [libbcpkix-java]

    Bouncy Castle Java API for PKIX, CMS, EAC, TSP, PKCS, OCSP, CMP, and CRMF

  • dep: [libbcprov-java]

    Bouncy Castle Java Cryptographic Service Provider

Download signapk

ArchitecturePackage SizeInstalled SizeFiles
all33 KiB46 KiB[list of files]

Caminhos de arquivo do pacote (0)

Paths come from the repository package-file index for the observed builds. They describe archive/package associations, not every file that will exist on a running system after maintainer scripts, alternatives, generated state, diversions, or installation choices.

No package-associated file paths were observed for the displayed build metadata.

Field source: Debian 13 (Trixie) main amd64 revision trixie-main-amd64:3ab4e811cf4f3e5a335d382c58cc19d85f1abe7a4ef4689160ca1f637fa0e9b3

Usar este pacote

O OpenFactory pode iniciar este sistema operacional em uma máquina virtual do navegador, ou começar uma construção que inclui o nome nativo do pacote deste registro.

Versões, suites e repositórios

Cada linha é metadado do índice de pacotes para uma versão, arquitetura, suite e repositório. Nomes, URLs e tamanhos vêm da fonte; um link é um ponto de obtenção mutável, não uma redistribuição da OpenFactory.

VersionReleaseArchitectureRepositoryPackage sizeInstalled sizePublisher repository artifact
1:10.0.0+r36-1.1trixie / mainallDebian 13 · main · amd6433 KiB46 KiBpool/main/a/android-platform-build/signapk_10.0.0+r36-1.1_all.deb
1:10.0.0+r36-1.1trixie / mainallDebian 13 · main · arm6433 KiB46 KiBpool/main/a/android-platform-build/signapk_10.0.0+r36-1.1_all.deb

Field source: Debian 13 (Trixie) main amd64 revision trixie-main-amd64:3ab4e811cf4f3e5a335d382c58cc19d85f1abe7a4ef4689160ca1f637fa0e9b3

Checksums e datas de observação

For an APT source, signature verification authenticates the repository metadata chain and the Packages index containing this source-reported artifact digest. It does not certify package safety.

1:10.0.0+r36-1.1 / allObserved Sep 1, 2026 to Sep 1, 2026

Verification status: Metadata observed; artifact bytes were not independently fetched or hashed by this catalog import. The digest below is source-reported.

Source-reported sha256: e94fcd54de9d6ffae104eee6139af79afbe4d1ada55682c7388d72deb666396e

After downloading that exact artifact, compare its bytes with the source-reported expected digest:

printf '%s %s\n' 'e94fcd54de9d6ffae104eee6139af79afbe4d1ada55682c7388d72deb666396e' 'signapk_10.0.0+r36-1.1_all.deb' | sha256sum --check --strict -

A match establishes equality with the repository metadata value. It does not establish safety or catalog-side artifact retrieval.

Field source: Debian 13 (Trixie) main amd64 revision trixie-main-amd64:3ab4e811cf4f3e5a335d382c58cc19d85f1abe7a4ef4689160ca1f637fa0e9b3

1:10.0.0+r36-1.1 / allObserved Sep 1, 2026 to Sep 1, 2026

Verification status: Metadata observed; artifact bytes were not independently fetched or hashed by this catalog import. The digest below is source-reported.

Source-reported sha256: e94fcd54de9d6ffae104eee6139af79afbe4d1ada55682c7388d72deb666396e

After downloading that exact artifact, compare its bytes with the source-reported expected digest:

printf '%s %s\n' 'e94fcd54de9d6ffae104eee6139af79afbe4d1ada55682c7388d72deb666396e' 'signapk_10.0.0+r36-1.1_all.deb' | sha256sum --check --strict -

A match establishes equality with the repository metadata value. It does not establish safety or catalog-side artifact retrieval.

Field source: Debian 13 (Trixie) main arm64 revision trixie-main-arm64:753da751bbc7a679f48bd1b623ffd4479cb6861c426118284c76eb82909e4908

Completude do registro

The completeness score measures metadata coverage, not software quality, security, compatibility, or suitability.

Summary and description
25/25
Artifact path and source digest
25/25
Dependency metadata
15/15
Package-file index
0/15
Homepage
5/5
License text
0/5
Source package or maintainer
10/10

Recorded total: 80/100

Field source: Debian 13 (Trixie) main amd64 revision trixie-main-amd64:3ab4e811cf4f3e5a335d382c58cc19d85f1abe7a4ef4689160ca1f637fa0e9b3, Debian 13 (Trixie) main arm64 revision trixie-main-arm64:753da751bbc7a679f48bd1b623ffd4479cb6861c426118284c76eb82909e4908. The cross-OS mapping is catalog-derived from the source-reported homepage; it does not establish authorship or publisher identity

Fontes e proveniência

Field-source links above resolve here. Each source entry names the metadata publisher, trust tier, exact snapshot revision, signature result, and observation time; catalog-derived mappings are labeled separately.

  • Authoritative source; repository metadata signature verified, revision trixie-main-amd64:3ab4e811cf4f3e5a335d382c58cc19d85f1abe7a4ef4689160ca1f637fa0e9b3

    Signature verification covers the configured repository metadata chain. It does not certify that the package is safe or suitable.

    Repository-signature verification record
    Signed-object SHA-256
    98b25b5cd185c59d34aa6e4c3e9b5b8f01bbe9d104fe2dcfbcd30dc0a14a59ed
    Signer fingerprint
    4CB50190207B4758A3F73A796ED0E7B82643E131
    Keyring revision
    debian-archive-keyring.gpg
    SHA-256 506b815cbb32d9b6066b4a2aa524071e071761e7e7f68c3ac74f3061ba852017
    Tool and policy
    gpgv (GnuPG) 2.4.9
    openfactory-software-catalog-signature-v1
    Verification time
    Sep 1, 2026
    Signed Release → package-index hash linkage

    Path: main/binary-amd64/Packages.xz
    Expected SHA-256: 3ab4e811cf4f3e5a335d382c58cc19d85f1abe7a4ef4689160ca1f637fa0e9b3
    Observed SHA-256: 3ab4e811cf4f3e5a335d382c58cc19d85f1abe7a4ef4689160ca1f637fa0e9b3
    Result: match verified

  • Authoritative source; repository metadata signature verified, revision trixie-main-arm64:753da751bbc7a679f48bd1b623ffd4479cb6861c426118284c76eb82909e4908

    Signature verification covers the configured repository metadata chain. It does not certify that the package is safe or suitable.

    Repository-signature verification record
    Signed-object SHA-256
    98b25b5cd185c59d34aa6e4c3e9b5b8f01bbe9d104fe2dcfbcd30dc0a14a59ed
    Signer fingerprint
    4CB50190207B4758A3F73A796ED0E7B82643E131
    Keyring revision
    debian-archive-keyring.gpg
    SHA-256 506b815cbb32d9b6066b4a2aa524071e071761e7e7f68c3ac74f3061ba852017
    Tool and policy
    gpgv (GnuPG) 2.4.9
    openfactory-software-catalog-signature-v1
    Verification time
    Sep 1, 2026
    Signed Release → package-index hash linkage

    Path: main/binary-arm64/Packages.xz
    Expected SHA-256: 753da751bbc7a679f48bd1b623ffd4479cb6861c426118284c76eb82909e4908
    Observed SHA-256: 753da751bbc7a679f48bd1b623ffd4479cb6861c426118284c76eb82909e4908
    Result: match verified