8–9 Aug 2026
NTUST
Asia/Taipei timezone

Beyond apt install: The Journey of an Ubuntu Package

Not scheduled
30m
AU (NTUST)

AU

NTUST

No. 43, Sec. 4, Keelung Rd., Da'an Dist., Taipei City 106335, Taiwan
Talk Other

Speaker

Shishir Subedi

Description

Every day, millions of users type apt update and apt install and software appears on their system as if by magic. Behind this simple command lies a sophisticated infrastructure of cryptographic safeguards, precise archive organization, and rigorous human review. This talk is an invitation to look under the hood and trace the full lifecycle of an Ubuntu package, from the central archive to the local machine.

The journey begins with an exploration of the repository architecture. We will break down how your system's repository configuration maps to a structured archive where metadata and installable packages are organized separately. We will discuss how Ubuntu manages change over a release's lifetime through distinct channels for security fixes, stable updates, and backported features, and how the archive groups packages by the level of support and maintenance they receive.

Trust is the backbone of this ecosystem. We will demonstrate the "Chain of Trust" that ensures package authenticity, illustrating how the system verifies that software is genuine and untampered with, even when fetched over potentially untrusted network mirrors. This section illustrates how a single signed file at the top anchors the trust for every package in the archive.

Finally, we will explore the human "gatekeepers" of the ecosystem. We will demystify the procedural checks and balances, such as the security auditing and stable release update processes that ensure software remains reliable long after a version is released.

Biography

Shishir is a security engineer at Canonical, where he works on mitigating vulnerabilities across applications in the Ubuntu archive. He holds a degree in computer engineering and has hands-on experience in open-source security, application hardening, and infrastructure security. When not at a terminal, he can be found on a football pitch, at a table tennis table, or on a hiking trail.

What audience can learn

  • How the Ubuntu archive is structured and how metadata flows to your system.
  • How Ubuntu organizes software into components and pockets.
  • How GPG verifies package integrity before installation.
  • The roles of the SRU and Security teams in auditing software.

Summary

Traces a package's journey from the Ubuntu archive to your machine, covering archive organization, the cryptographic chain of trust that secures packages even over untrusted mirrors, and the human processes like Security and Stable Release Updates that keep the ecosystem reliable.

Things to know or prepare for this session

  • Apt Basics: Running commands like apt update and apt install.

Good to have:
- Curiosity about how systems verify trusted files.
- General knowledge of LTS and interim releases.

Difficulty level Begineer
Language English

Presentation materials

There are no materials yet.