Read-only package tracking for openRuyi: RPM source versions, upstream releases, OBS builds and maintenance evidence. Collectors save observations in SQLite snapshots. Page and API requests read these snapshots. They do not query providers.
| Task | Guide |
|---|---|
| Install, configure ports, back up or upgrade | Deployment |
| Add a package or correct its upstream identity | Configuration |
| Change code and run checks | Contributing |
| Add a monitor or provider backend | Monitor porting |
| Understand consistency and security boundaries | Design |
A Linux container with native RPM bindings and Landlock ABI 6+ is required for confined SPEC parsing. Keep configuration and persistent data on separate mounts.
The running site's /api page provides query examples; /openapi.json defines
parameters and responses. Failed checks retain previous evidence and its observation time.
Upstream security
matches do not evaluate local patches or the exploitability of distributed RPMs.