Package Search Help

You can use boolean logic (e.g. AND/OR/NOT) for complex search queries. For more help and examples, see the search documentation.

Search by package name:
my-package (implicit)
name:my-package (explicit)

Search by package filename:
my-package.ext (implicit)
filename:my-package.ext (explicit)

Search by package tag:
latest (implicit)
tag:latest (explicit)

Search by package version:
1.0.0 (implicit)
version:1.0.0 (explicit)
prerelease:true (prereleases)
prerelease:false (no prereleases)

Search by package architecture:
architecture:x86_64 

Search by package distribution:
distribution:el 

Search by package license:
license:MIT 

Search by package format:
format:deb 

Search by package status:
status:in_progress 

Search by package file checksum:
checksum:5afba 

Search by package security status:
severity:critical 

Search by package vulnerabilities:
vulnerabilities:>1 
vulnerabilities:<1000 

Search by # of package downloads:
downloads:>8 
downloads:<100 

Search by package type:
type:binary 
type:source 

Search by package size (bytes):
size:>50000 
size:<10000 

Search by dependency name/version:
dependency:log4j 
dependency:log4j=1.0.0 
dependency:log4j>1.0.0 

Search by uploaded date:
uploaded:>"1 day ago" 
uploaded:<"August 14, 2022 EST" 

Search by entitlement token (identifier):
entitlement:3lKPVJPosCsY 

Search by policy violation:
policy_violated:true
deny_policy_violated:true
license_policy_violated:true
vulnerability_policy_violated:true

Search by repository:
repository:repo-name

Search queries for all Debian-specific (and related) package types

Search by component:
deb_component:unstable

Search queries for all Maven-specific (and related) package types

Search by group ID:
maven_group_id:org.apache

Search queries for all Docker-specific (and related) package types

Search by image digest:
docker_image_digest:sha256:7c5..6d4
(full hashref only)

Search by layer digest:
docker_layer_digest:sha256:4c4..ae4
(full hashref only)

Field type modifiers (depending on the type, you can influence behaviour)

For all queries, you can use:
~foo for negation

For string queries, you can use:
^foo to anchor to start of term
foo$ to anchor to end of term
foo*bar for fuzzy matching

For number/date or version queries, you can use:
>foo for values greater than
>=foo for values greater / equal
<foo for values less than
<=foo for values less / equal

Need a secure and centralised artifact repository to deliver Alpine, Cargo, CocoaPods, Composer, Conan, Conda, CRAN, Dart, Debian, Docker, Go, Helm, Hex, LuaRocks, Maven, npm, NuGet, P2, Python, RedHat, Ruby, Swift, Terraform, Vagrant, Raw & More packages?

Cloudsmith is the new standard in Package / Artifact Management and Software Distribution.

With support for all major package formats, you can trust us to manage your software supply chain.

Start My Free Trial
 Public tideways tideways (Tideways) / apt-packages-main
non-beta packages of tideways-php/-daemon/-proxy/-cli

Tool-Specific Instructions

Although we use GPG (and RSA) keys across each repository and package format, client-side tools might have specific instructions that differ (or require manual steps). To add or use the signing key for these tools, please click on the package format specific tabs above.

Public GPG Key

GPG-based keys/signatures are used by:
Debian logo

The public GPG key for the tideways/apt-packages-main is:

-----BEGIN PGP PUBLIC KEY BLOCK-----
Version: GnuPG v2
mQGNBF8sAUoBDACo4beHSZ4+RNL4RYW5/rc9eTIre7m5VAy4OOGbH4rWs/qwY/tp
lpSW3lRP8b7pJ38ydFsegbW/0q4VY+SSTUddW1P1HayKJblaeB0fre2HVNnlcGZV
YIuxfH3THs30qlgiK90c1OIBFTa/JbGem4fpXSt1sL8mXN/fon1nGBVDmL4fDBCT
k5FgzoTiH7tVQegxVU2hR58x7cudntq7DXA+l2nxbxQZ0c55xUGI5A0dY0nkDLya
xdfx0nlHtW7j1rveAHHG9+6EASUY6HHBsB+ZfKn4Fg0reGj21KlcFd0ajlFoEJ5x
G1VeQZFuD8Apb4ZOzQj6Lnl14Z32x2LIVym27fTc8wXWkF/UyPVLhnNs/2TxSpRy
+rk9SLgjhSpPzUdPHjQEleHs76jxQ0JP1kwOkIJkbx7eVSLlfgVYvoBWGW+vrltA
iSn1vJr+Kpyx0Nb5tvWmQSxv0a6iYnywt72zgWr9syqrZFk0AWBek17KyG3eMXx+
YnxOzVFzbCe7YocAEQEAAbQ3QmVuamFtaW4gRWJlcmxlaSBUaWRld2F5cyBHbWJI
IDxwYWNrYWdpbmdAdGlkZXdheXMuY29tPokBzgQTAQoAOAIbAwULCQgHAgYVCgkI
CwIEFgIDAQIeAQIXgBYhBK9XjGEUizSFtYXkAYz8eoClZyq1BQJfMpubAAoJEIz8
eoClZyq1p+8L/jQ5G2wqYEqlmtEa6mNJIOZDR1nMU3HemKisOqEydJyTF99lZa01
KEBngqko4QaplHHIcEMMRS9wp0Qz+9eSOL1h7OhD4uz0R36ngM3KZxiXg+1ixaL9
dLbupg0+x722MDMDkYodLhgHQlA54PAv7e3IFnfojwGje6F1bxMmq4PpiN+XUqhi
a0eIqybr9IAiq//IaMp+lzXr7frbY31ehrh5/MziU/JJp46rvTUPtjQDFdH7kJab
WY5l5cyXern36fUdekchCAFmurvYsZI65E4GDE4mrGD6SKvfp0ne0BtSsXHZTAZT
ou8LdZiHwo3G2ynf6JetM2I47932lx1RxBD+awWvjx8gjitD0cyFkiDDj23M+7+h
gv1o1t3HWTLOTGUj0wXwW4kscxauyMJcFl5X2uHTnxiSpE2U9a47IhDrjT9XAWon
CAtqsu3+46MonF8HCngps9UTfZvSFPXgxQEJgBMSaEkk2Ri3t8kaId1yUDBGVTmx
GQuXoYSNJURX3bkBjQRfLAFKAQwAxOeZ1hmOAGc3ksQPgawmDoVEP+r0KYhj0wPK
2tPZmbW7dIhWQ0Ov2/3qMGLU5R53JscG2+0+mVmh/4WpR9V/c/nGbbejfG62HB/x
3aoU52i1Tn2BdlfghIoUcZ1s9O0BzJ8hHShtSUMlA/r8MgyEXsXNkzc6Y1ad997/
1Y/QjB2ZWdgs+oVU9qi9qmr9gpBiKEE63w9bnbjAHeerYtu5+/EzL+nVad54N/EU
QUDSWTrVW13lhdosy/kcTw8vwN4BCMRQBq4WPPDP6UWSbJVer6ASrwdb/B7QmA2k
WQBq/H7XCSH2AxFjKOYzb/6PGk5qfX2FngMKZdHizjlcRvWnUDfJVSEoKt6IOVhF
q2sKHVTgFBYmgHaMIqDXGumAv1HQaPDpk7jwW7EsapuJwaKRst2UP9VJZwV/zvLN
nC+x9PmC2udOZbCf5XMNV8+LbC0vwHucz+J/9nso7izHDTsb5EatubrNtCUdpakA
mFFgIRPSw5wIhhXbzyQIWxXVOoRzABEBAAGJAbYEGAEKACACGwwWIQSvV4xhFIs0
hbWF5AGM/HqApWcqtQUCXzKbrQAKCRCM/HqApWcqtc6EC/98JflUbyMu9nxf4nPS
vPceYgvOD+jTFbb9B77yx8oXns8oOVbc9dRqzaz6SgtBrr7aREZ3qJpzKIeyDrJ1
jfAzzpPb7OjlqfA6cfoUzac2hehOpteeI56yQVxkRJ4DYeOBy1eJjaYQ4gQ6NU5m
S2N156pj14UIbugr7/mk8YiRG2IddYDiAfjx8+HucDaNEmSfM23EMC+wAVSylx4u
/l+4LYOY+q6KPLMb2iwuuNSiqISPcg172Txi+XFEEASjQh2JLC9BX1Mur3XU1Nz1
5FfqCx6aHPEscld2oCQp0gVHG560hQhtn+rSEcKZWeCKMeVljpAGDb1DX/WZylku
ZdIZx9gBk5Z1uLEpsqZVTbl2+csw1GJ3jmLgf1qr2cKgl4Sv1dS0v6Fxn6dy443Z
JEpz7jeY2F9DG6IwYj2vwp4MdgwJPXvybAiWZ8OEQVFxsMZ5dukHw4727KiO71rA
H0eXVwz3C9XInmQBGoyilNLd+Gp6Xmnc4y2bfFLf7hYVwzk=
=iECu
-----END PGP PUBLIC KEY BLOCK-----

It has the following long (20 bytes) and short (8 bytes) fingerprints:

AF578C61148B3485B585E4018CFC7A80A5672AB5
8CFC7A80A5672AB5

You can download the GPG key or fetch it via the command-line:

curl -1sLf 'https://dl.cloudsmith.io/public/tideways/apt-packages-main/gpg.8CFC7A80A5672AB5.key'

Please note that the GPG key for this repository has been manually specified by Tideways. It contains the following comment:

No comment provided

Public RSA Key

RSA-based keys/signatures are used by:

The public RSA key for the tideways/apt-packages-main is:

-----BEGIN PUBLIC KEY-----
MIIBojANBgkqhkiG9w0BAQEFAAOCAY8AMIIBigKCAYEA1lmF8PdUbgsZTQSwDlsx
3pAfxbJWQTBAcm4Ie3/7xe+8Pnp4j2A5g0JaTUWhGt9hbOSym2VZuAsbpKdm6+wf
oFZ4IRxMtlhGYlWb4nVqlSXYo+1vFKceGpC9TAhKysaslOJgYv3QO6BasZBLMe1Z
KqQYMift47EVrijscKaAX21vxXPqGAnARNbv/9V3GoFyUElOpJ7DCXGHAeCZEj0Z
6pVMks+UdwvRkz7v5YhsZy1eBCs5Ve6czC7oZyIT1bZltJmZx9jdZusElzYHmqQz
BovmaDBpHEkYFOov2Zc6t0c6j63qZbAjr4STloRgUM0K1QN6hyZC65imhPNK6FZa
fczxHLxZDusyyxyDhvIKE7Tc6MaftFurMDK90SdYAid7GXBAMWIzmJrcw9g3/tft
Ltl+yVUyKsQd0iQykDhp6R0t4yO9+f+ZBxk9eXcyUkM+4KBpdSf1hMUHHWlT3b4u
Hx3KL6wCohvjRhd0768PtmMJxKzbl6uXuixKkR4fYE7xAgMBAAE=
-----END PUBLIC KEY-----

It has the following long (16 bytes) and short (8 bytes) fingerprints:

4AAAB13DAA0B70A6DE88690B2CE1C536
DE88690B2CE1C536

You can download the RSA key or fetch it via the command-line:

curl -1sLf 'https://dl.cloudsmith.io/public/tideways/apt-packages-main/rsa.DE88690B2CE1C536.key'

Public ECDSA Key

ECDSA-based keys/signatures are used by:

The public ECDSA OpenSSH key for the tideways/apt-packages-main is:

-----BEGIN PUBLIC KEY-----
MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEJLOYUSZiepiB8vi5u3VYODedHzNY
RE4uKVIlQw6iZJWUBVjYTnSr9dOe4Hvqw8wedhja+a+jx7PorqsI5ywLDQ==
-----END PUBLIC KEY-----

It has the following long (16 bytes) and short (8 bytes) fingerprints:

CCE97F7C6EC8BC9E66ECD17839158F1B
66ECD17839158F1B

You can download the ECDSA key or fetch it via the command-line:

curl -1sLf 'https://dl.cloudsmith.io/public/tideways/apt-packages-main/ecdsa.66ECD17839158F1B.key'

Please note however that the NPM client does not require this key to be installed system-wide in order to allow for package verification - NPM tooling will handle keys automatically.

Need Help?

If you couldn't find what you needed in our documentation, then you can always chat to a member of our team instead. It's our mission to be your dedicated off-site team for package management, and we mean it. Come and chat with us, anytime.

What's this page? All Cloudsmith repositories and packages are signed using GPG, RSA or ECDSA keys where supported. Signatures and checksums provide reliable mechanisms to ensure that the packages that you download/install are neither corrupt nor modified. GPG is generally preferred, but RSA or ECDSA is used for some package formats (such as Alpine or NPM). Learn more in the signing keys documentation.

Top