Skip to content

The Dangerzone repositories

Dangerzone is more than one repository. The application, the sandbox image it runs, the packages users install and the signatures that tie them together, each live in their own place. This page gives contributors the bird's-eye view: what each repository or site is for, and how they fit together.

The big picture

nightly builds(images and attestations)monthly releases(tags and signatures)nightly CVE scansbundled in installers,or downloaded and verified.deb and .rpm.dmg, .msi, sourcerepro-buildreproducible buildsdangerzone-imagesandbox imageghcr.iosigned sandbox imageghcr-signerCosign signaturescves.dangerzone.rocksdangerzoneapplication and docspackages.freedom.pressGitHub releases

Every box in the graph is a link to the repository or site it stands for.

The repositories

freedomofpress/dangerzone

The main repository: the desktop application (in Qt), the CLI tools, the packaging for every platform and this documentation site. Releases are tagged here and their installers are published on the GitHub releases page.

freedomofpress/dangerzone-image

The sandbox: the container image that performs the document-to-pixels conversion, and the Python package that runs inside it. Images built from the main branch are published nightly to ghcr.io/freedomofpress/dangerzone/v1 (but are not tagged as latest), whereas images from feature branches are published under a testing namespace, ghcr.io/freedomofpress/dangerzone-testing/v1. The CI of this repo builds the image reproducibly, attaches provenance attestations, runs the daily CVE scans, and publishes the security dashboard. Problems with a document format, a bundled tool, or a CVE inside the sandbox belong here. The interface between the application and the image is described in Sandbox protocol, and the update mechanism in Independent sandbox updates.

freedomofpress/packages

Repository for the .deb and .rpm packages, served on https://packages.freedom.press (and on https://packages-qa.freedom.press for release candidates).

freedomofpress/ghcr-signer

Utilities to publish our official container images on a monthly cadence. Candidate images from our nightly builds are signed privately with a hardware key and the signatures are submitted as a pull request. The CI verifies the signatures and once the pull request is merged, it pushes them to the GitHub Container Registry and tags the image as latest. The blog post The GHCR Signer explains why this is needed and how it works. This is the step that lets Dangerzone trust a downloaded sandbox image.

freedomofpress/repro-build

A helper script to build bit-for-bit reproducible container images, by providing a build environment that is consistent across operating systems and container engines. dangerzone-image uses it so that anyone can rebuild the sandbox image and compare digests. The blog post Reproducing the reproducible images tells the story, and Reproducible builds covers what is reproducible on the Dangerzone side.

freedomofpress/dangerzone-rs

A rewrite of dangerzone in rust, currently in the works and not to be used yet.

Websites

stats.dangerzone.rocks

Release statistics for the project aggregating data from the GitHub releases and the container registry. Generated by freedomofpress/dangerzone-stats.

cves.dangerzone.rocks

The security dashboard: the results of the nightly grype scans of the sandbox image, both for the development branch and the latest released image. This is the second line of defense described in the security model. The dashboard is published from the dangerzone-image repository.

dangerzone.rocks and this site

The official website, with download links and the blog. Built from freedomofpress/dangerzone.rocks. This documentation site is built from the docs/ directory of the main repository and published at docs.dangerzone.rocks.