Skip to content

feat: add signed NexaWrt APK repository - #18

Merged
tifycloud merged 1 commit into
mainfrom
codex/self-hosted-apk-repository
Jul 22, 2026
Merged

tifycloud merged 1 commit into
mainfrom
codex/self-hosted-apk-repository

Conversation

@tifycloud

Copy link
Copy Markdown
Owner

Summary

  • add a signed NexaWrt APK repository pipeline for OpenWrt 25.12
  • embed the locked repository URL and public verification key into AX9000 builds
  • publish the immutable repository archive through a protected GitHub environment and expose it through GitHub Pages
  • add the native nexawrt-repository bootstrap package and status helper
  • make Pages fail closed if the locked repository release is absent or invalid
  • add repository lock, package allowlist, signing-key validation, safe archive staging, and policy tests

Repository endpoint

https://tifycloud.github.io/NexaWrt/packages/25.12/testing/aarch64_cortex-a53/packages.adb

OpenWrt 25.12 uses APK rather than OPKG, so the firmware is configured through /etc/apk/repositories.d/nexawrt.list and /etc/apk/keys/nexawrt-repository.pem.

Verification

  • full tests/test_static.sh suite passed
  • actionlint passed for package repository and Pages workflows
  • shellcheck passed for changed shell policy/build files
  • Python compile and repository unit tests passed (10/10)
  • real OpenWrt host apk signed-index integration passed
  • correct public key accepted; wrong public key rejected
  • independent security re-review closed both previous P1 findings with no new P0/P1 blockers

Rollout

The initial repository is deliberately the testing channel and contains only the reviewed nexawrt-repository bootstrap package. Additional packages should be added through the locked package manifest after source review. Publishing on main requires approval in the protected package-repository environment.

@tifycloud
tifycloud merged commit 9abc35f into main Jul 22, 2026
6 checks passed
@tifycloud
tifycloud deleted the codex/self-hosted-apk-repository branch July 22, 2026 02:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant