This public repository is the anonymous, read-only update endpoint for approved
AptUtil Windows Portable releases. It is generated by protected workflows in the
private PharmUtilities/AptUtil monorepo and is not a development repository.
- published GitHub Release assets;
- immutable candidate and promoted GitHub Release assets;
- signed
update-index-v6.jsonchannel routing and its detached signature; - the historical
update-index.json, which is no longer an active channel; - retained legacy schemas, distribution policy, and security guidance.
Application source, signing keys, build inputs, GitHub credentials, pharmacy reports, medicine sales or stock reports, customer information, and local configuration do not belong here.
The signed v6 index selects a release. AptUtil then verifies the independently signed release manifest, package hash, byte count, exact ZIP entries, and every file hash before staging an update. Separate index and release keys limit the impact of either online key. Trust changes additionally require the offline root threshold. Persistent data and trust anchors are never release payload targets.
Candidates are created once from a reviewed source commit, tested by exact package SHA-256, and promoted without rebuilding. Binary packages remain in GitHub Releases so repository history stays small.
AptTil processes uploaded reports locally. This repository does not receive or store pharmacy report data.
No licence is granted for the application or proprietary compiled packages unless explicitly stated in a release. Third-party components retain their respective licence terms and notices.