Source: apt-transport-in-toto Section: utils Priority: optional Maintainer: in-toto developers Uploaders: Santiago Torres-Arias , Lukas Puehringer , Holger Levsen , Justin Cappos , Frédéric Pierret , Build-Depends: debhelper-compat (= 13), dh-python, dh-exec, python3-all, python3-requests, python3-mock, python3-coverage, in-toto (>= 1.0.0), gnupg, Standards-Version: 4.7.0 Rules-Requires-Root: no Homepage: Vcs-Git: -b debian Vcs-Browser: Package: apt-transport-in-toto Architecture: all Depends: ${misc:Depends}, python3, python3-requests, python3-securesystemslib, in-toto (>= 1.0.0), gnupg, Description: apt transport method for in-toto supply chain verification apt-transport-in-toto provides a custom transport method for apt that fetches and verifies signed build information from autonomous rebuilders upon package installation. . It uses the supply chain security framework in-toto for its verification protocol, to i.a. define trust relationships and exchange and verify build information. . apt-transport-in-toto is developed at the Secure Systems Lab of NYU.