Live data from cpac-trust-db
No active advisories
The database is clean — no known compromised packages.
No snapshots yet
CPAC clients will submit anonymized PKGBUILD hashes as they install packages.
This page shows the live contents of the CPAC Trust Database — the community-maintained trust data backend for CPAC.
Maintainer-curated records of known malicious, compromised, or suspicious packages. Only the core team can publish advisories.
Anonymized, crowdsourced PKGBUILD hashes submitted by CPAC clients. Used to detect divergence from known-good package states.
The full database is open source onGitHub. Every change is auditable via git history.