Linux workstation

Debian 12 (Bookworm) native package

libcurl4

easy-to-use client-side URL transfer library (OpenSSL flavour)

Packages / Debian 12 (Bookworm) / libs / libcurl4

[Source: curl]

Package: libcurl4 (7.88.1-10+deb12u15)

Maintainers:

Alessandro Ghedini

External Resources:

Homepage: [curl.se]

Similar packages:

easy-to-use client-side URL transfer library (OpenSSL flavour)

Other Packages Related to libcurl4:

  • dep: [libbrotli1] (>= 0.6.0)

    library implementing brotli encoder and decoder (shared libraries)

  • dep: [libc6] (>= 2.34)

    GNU C Library: Shared libraries

  • dep: [libgssapi-krb5-2] (>= 1.17)

    MIT Kerberos runtime libraries - krb5 GSS-API Mechanism

  • dep: [libidn2-0] (>= 0.6)

    Internationalized domain names (IDNA2008/TR46) library

  • dep: [libldap-2.5-0] (>= 2.5.4)

    OpenLDAP libraries

  • dep: [libnghttp2-14] (>= 1.50.0)

    library implementing HTTP/2 protocol (shared library)

  • dep: [libpsl5] (>= 0.16.0)

    Library for Public Suffix List (shared libraries)

  • dep: [librtmp1] (>= 2.3)

    toolkit for RTMP streams (shared library)

  • dep: [libssh2-1] (>= 1.7.0)

    SSH2 client-side library

  • dep: [libssl3] (>= 3.0.0)

    Secure Sockets Layer toolkit - shared libraries

  • dep: [libzstd1] (>= 1.5.2)

    fast lossless compression algorithm

  • dep: [zlib1g] (>= 1:1.1.4)

    compression library - runtime

Download libcurl4

ArchitecturePackage SizeInstalled SizeFiles
amd64383 KiB840 KiB[list of files]

Package file paths (7)

Paths come from the repository package-file index for the observed builds. They describe archive/package associations, not every file that will exist on a running system after maintainer scripts, alternatives, generated state, diversions, or installation choices.

  • /usr/lib/aarch64-linux-gnu/libcurl.so.4
  • /usr/lib/aarch64-linux-gnu/libcurl.so.4.8.0
  • /usr/lib/x86_64-linux-gnu/libcurl.so.4
  • /usr/lib/x86_64-linux-gnu/libcurl.so.4.8.0
  • /usr/share/doc/libcurl4/changelog.Debian.gz
  • /usr/share/doc/libcurl4/changelog.gz
  • /usr/share/doc/libcurl4/copyright

Field source: Debian 12 (Bookworm) main amd64 revision bookworm-main-amd64:9e0b5aabb2465b3d2e7a7fe27f9913846277833f7a2826e7767acccff5b588c5

Use this package

OpenFactory can boot this operating system in a browser VM, or start a build that includes the native package name from this record.

Versions, suites, and repositories

Each row is recorded package-index metadata for one version, architecture, suite, and repository. Names, URLs, and sizes are source-reported; a link is a potentially mutable retrieval location, not an OpenFactory redistribution claim or proof that OpenFactory retained the artifact bytes.

VersionReleaseArchitectureRepositoryPackage sizeInstalled sizePublisher repository artifact
7.88.1-10+deb12u15bookworm / mainamd64Debian 12 · main · amd64383 KiB840 KiBpool/main/c/curl/libcurl4_7.88.1-10+deb12u15_amd64.deb

Field source: Debian 12 (Bookworm) main amd64 revision bookworm-main-amd64:9e0b5aabb2465b3d2e7a7fe27f9913846277833f7a2826e7767acccff5b588c5

Checksums and observation dates

For an APT source, signature verification authenticates the repository metadata chain and the Packages index containing this source-reported artifact digest. It does not certify package safety.

7.88.1-10+deb12u15 / amd64Observed Sep 1, 2026 to Sep 1, 2026

Verification status: Metadata observed; artifact bytes were not independently fetched or hashed by this catalog import. The digest below is source-reported.

Source-reported sha256: 3042904de01f9c4fbdcf1452b8f81abedcf2b015f9b9deba109063322b5bd68b

After downloading that exact artifact, compare its bytes with the source-reported expected digest:

printf '%s %s\n' '3042904de01f9c4fbdcf1452b8f81abedcf2b015f9b9deba109063322b5bd68b' 'libcurl4_7.88.1-10+deb12u15_amd64.deb' | sha256sum --check --strict -

A match establishes equality with the repository metadata value. It does not establish safety or catalog-side artifact retrieval.

Field source: Debian 12 (Bookworm) main amd64 revision bookworm-main-amd64:9e0b5aabb2465b3d2e7a7fe27f9913846277833f7a2826e7767acccff5b588c5

Catalog record completeness

Sources and provenance

Field-source links above resolve here. Each source entry names the metadata publisher, trust tier, exact snapshot revision, signature result, and observation time; catalog-derived mappings are labeled separately.

  • Authoritative source; repository metadata signature verified, revision bookworm-backports-main-amd64:b863aa021bef70ee6ca393bbb9267d954281b77fd02a1d485c8259303ffdc0e6

    Signature verification covers the configured repository metadata chain. It does not certify that the package is safe or suitable.

    Repository-signature verification record
    Signed-object SHA-256
    43c0dc1b38775aa77216f1aca0b9e47abde4ef3b6f223fd965a6464f45da709d
    Signer fingerprint
    4CB50190207B4758A3F73A796ED0E7B82643E131
    Keyring revision
    debian-archive-keyring.gpg
    SHA-256 506b815cbb32d9b6066b4a2aa524071e071761e7e7f68c3ac74f3061ba852017
    Tool and policy
    gpgv (GnuPG) 2.4.9
    openfactory-software-catalog-signature-v1
    Verification time
    Sep 1, 2026
    Signed Release → package-index hash linkage

    Path: main/binary-amd64/Packages.xz
    Expected SHA-256: b863aa021bef70ee6ca393bbb9267d954281b77fd02a1d485c8259303ffdc0e6
    Observed SHA-256: b863aa021bef70ee6ca393bbb9267d954281b77fd02a1d485c8259303ffdc0e6
    Result: match verified

  • Authoritative source; repository metadata signature verified, revision bookworm-backports-main-arm64:9a9a82396b83567fd3c9e3df7d9190b5685c1bf07ef2ad14e04ad353b0caf4d5

    Signature verification covers the configured repository metadata chain. It does not certify that the package is safe or suitable.

    Repository-signature verification record
    Signed-object SHA-256
    43c0dc1b38775aa77216f1aca0b9e47abde4ef3b6f223fd965a6464f45da709d
    Signer fingerprint
    4CB50190207B4758A3F73A796ED0E7B82643E131
    Keyring revision
    debian-archive-keyring.gpg
    SHA-256 506b815cbb32d9b6066b4a2aa524071e071761e7e7f68c3ac74f3061ba852017
    Tool and policy
    gpgv (GnuPG) 2.4.9
    openfactory-software-catalog-signature-v1
    Verification time
    Sep 1, 2026
    Signed Release → package-index hash linkage

    Path: main/binary-arm64/Packages.xz
    Expected SHA-256: 9a9a82396b83567fd3c9e3df7d9190b5685c1bf07ef2ad14e04ad353b0caf4d5
    Observed SHA-256: 9a9a82396b83567fd3c9e3df7d9190b5685c1bf07ef2ad14e04ad353b0caf4d5
    Result: match verified

  • Authoritative source; repository metadata signature verified, revision bookworm-main-amd64:9e0b5aabb2465b3d2e7a7fe27f9913846277833f7a2826e7767acccff5b588c5

    Signature verification covers the configured repository metadata chain. It does not certify that the package is safe or suitable.

    Repository-signature verification record
    Signed-object SHA-256
    77737fa4b34f2693e982cc9ee35736816c35a7778fc2d326cc1bbf5b301fe1aa
    Signer fingerprint
    4CB50190207B4758A3F73A796ED0E7B82643E131
    Keyring revision
    debian-archive-keyring.gpg
    SHA-256 506b815cbb32d9b6066b4a2aa524071e071761e7e7f68c3ac74f3061ba852017
    Tool and policy
    gpgv (GnuPG) 2.4.9
    openfactory-software-catalog-signature-v1
    Verification time
    Sep 1, 2026
    Signed Release → package-index hash linkage

    Path: main/binary-amd64/Packages.xz
    Expected SHA-256: 9e0b5aabb2465b3d2e7a7fe27f9913846277833f7a2826e7767acccff5b588c5
    Observed SHA-256: 9e0b5aabb2465b3d2e7a7fe27f9913846277833f7a2826e7767acccff5b588c5
    Result: match verified

  • Authoritative source; repository metadata signature verified, revision bookworm-main-arm64:2ddb1737692e8c45c53e8d57c0ce4cd21c78c5703b830c3226b1423566a06c00

    Signature verification covers the configured repository metadata chain. It does not certify that the package is safe or suitable.

    Repository-signature verification record
    Signed-object SHA-256
    77737fa4b34f2693e982cc9ee35736816c35a7778fc2d326cc1bbf5b301fe1aa
    Signer fingerprint
    4CB50190207B4758A3F73A796ED0E7B82643E131
    Keyring revision
    debian-archive-keyring.gpg
    SHA-256 506b815cbb32d9b6066b4a2aa524071e071761e7e7f68c3ac74f3061ba852017
    Tool and policy
    gpgv (GnuPG) 2.4.9
    openfactory-software-catalog-signature-v1
    Verification time
    Sep 1, 2026
    Signed Release → package-index hash linkage

    Path: main/binary-arm64/Packages.xz
    Expected SHA-256: 2ddb1737692e8c45c53e8d57c0ce4cd21c78c5703b830c3226b1423566a06c00
    Observed SHA-256: 2ddb1737692e8c45c53e8d57c0ce4cd21c78c5703b830c3226b1423566a06c00
    Result: match verified

  • Authoritative source; repository metadata signature verified, revision bookworm-security-main-amd64:f6c2fe702b8cabb044e7bb46c5eaf3962abb6cfed5fcac896ffeb271b9d15104

    Signature verification covers the configured repository metadata chain. It does not certify that the package is safe or suitable.

    Repository-signature verification record
    Signed-object SHA-256
    6d12b591dde8841119e7e66de94b2af438681faebffabe08ea364290f7aaee1c
    Signer fingerprint
    ED541312A33F1128F10B1C6C54404762BBB6E853
    Keyring revision
    debian-archive-keyring.gpg
    SHA-256 506b815cbb32d9b6066b4a2aa524071e071761e7e7f68c3ac74f3061ba852017
    Tool and policy
    gpgv (GnuPG) 2.4.9
    openfactory-software-catalog-signature-v1
    Verification time
    Sep 1, 2026
    Signed Release → package-index hash linkage

    Path: main/binary-amd64/Packages.xz
    Expected SHA-256: f6c2fe702b8cabb044e7bb46c5eaf3962abb6cfed5fcac896ffeb271b9d15104
    Observed SHA-256: f6c2fe702b8cabb044e7bb46c5eaf3962abb6cfed5fcac896ffeb271b9d15104
    Result: match verified

  • Authoritative source; repository metadata signature verified, revision bookworm-security-main-arm64:f9b8756324afddf50b1c19d6d46164158c0361909fddc40b48777ad665dfdb14

    Signature verification covers the configured repository metadata chain. It does not certify that the package is safe or suitable.

    Repository-signature verification record
    Signed-object SHA-256
    6d12b591dde8841119e7e66de94b2af438681faebffabe08ea364290f7aaee1c
    Signer fingerprint
    ED541312A33F1128F10B1C6C54404762BBB6E853
    Keyring revision
    debian-archive-keyring.gpg
    SHA-256 506b815cbb32d9b6066b4a2aa524071e071761e7e7f68c3ac74f3061ba852017
    Tool and policy
    gpgv (GnuPG) 2.4.9
    openfactory-software-catalog-signature-v1
    Verification time
    Sep 1, 2026
    Signed Release → package-index hash linkage

    Path: main/binary-arm64/Packages.xz
    Expected SHA-256: f9b8756324afddf50b1c19d6d46164158c0361909fddc40b48777ad665dfdb14
    Observed SHA-256: f9b8756324afddf50b1c19d6d46164158c0361909fddc40b48777ad665dfdb14
    Result: match verified