Every daily run verifies what it publishes, batch by batch, before publishing it:
texlive.tlpdb, the three installers and the twoupdate-tlmgr-latestupdaters are checked against their SHA-512 and GPG signatures, with the TeX Live primary key fingerprint pinned inTaskfile.yml. A signature from an expired or revoked key is rejected.texlive.tlpdb.xz, the copytlmgrdownloads, must decompress to the verifiedtexlive.tlpdbbyte for byte.- Every package container is checked against the
containerchecksumrecorded in the signed tlpdb. - A tree that fails any check is never published; the previous good copy stays live.
Those are the only files TeX Live signs. The rest of the tree (install-tl,
install-tl-windows.bat, texlive.tlpdb.md5 and the helper trees under tlpkg/) is
copied as-is; no TeX Live tool fetches them from a repository URL.
tlmgr repeats the signature check on the client, so a tampered mirror is rejected there
too. After each publish, texlive.tlpdb.sha512 is read back through the domain and compared
with what was uploaded.
Uploads are not atomic. Containers land first and the tlpdb that names them a minute or so
later, and containers are overwritten in place, so a tlmgr run that overlaps the publish
can see checksum errors. Rerun it.
If you find a way to serve altered or unsigned content through tlnet.katoptra.org, or a
weakness in the pipeline itself, report it privately through
GitHub's vulnerability reporting.
Please do not open a public issue for it.
Problems with the packages themselves (a malicious or broken upstream package) belong to TeX Live and CTAN; this mirror copies what they publish, byte for byte.
Only the current main branch and the live mirror. There are no releases.