Linux workstation

Debian 13 (Trixie) native package

cruft-ng

programs that helps analyse volatile "cruft" files on your system

Packages / Debian 13 (Trixie) / admin / cruft-ng

Package: cruft-ng (0.9.71)

Maintainers:

Debian Security Tools

External Resources:

Homepage: [salsa.debian.org]

programs that helps analyse volatile "cruft" files on your system

Other Packages Related to cruft-ng:

  • dep: [libc6] (>= 2.38)

    GNU C Library: Shared libraries

  • dep: [libgcc-s1] (>= 3.0)

    GCC support library

  • dep: [libmd0] (>= 0.0.0)

    message digest functions from BSD systems - shared library

  • dep: [libstdc++6] (>= 13.1)

    GNU Standard C++ Library v3

  • sug: [ncdu]

    ncurses disk usage viewer

Download cruft-ng

ArchitecturePackage SizeInstalled SizeFiles
amd64200 KiB887 KiB[list of files]
arm64187 KiB911 KiB[list of files]

Package file paths (55)

Paths come from the repository package-file index for the observed builds. They describe archive/package associations, not every file that will exist on a running system after maintainer scripts, alternatives, generated state, diversions, or installation choices.

  • /usr/bin/cpigs
  • /usr/bin/cruft
  • /usr/bin/cruft-ng
  • /usr/libexec/cruft/ALTERNATIVES
  • /usr/libexec/cruft/APPARMOR
  • /usr/libexec/cruft/AUTOPKGTEST
  • /usr/libexec/cruft/binfmt-support
  • /usr/libexec/cruft/ca-certificates
  • /usr/libexec/cruft/ccache
  • /usr/libexec/cruft/cowdancer
  • /usr/libexec/cruft/dkms
  • /usr/libexec/cruft/doc-base
  • /usr/libexec/cruft/fontconfig-config
  • /usr/libexec/cruft/grub-common
  • /usr/libexec/cruft/grub-efi-amd64-bin
  • /usr/libexec/cruft/grub-legacy
  • /usr/libexec/cruft/grub-pc-bin
  • /usr/libexec/cruft/ICON-THEME
  • /usr/libexec/cruft/init-system-helpers
  • /usr/libexec/cruft/ispell
  • /usr/libexec/cruft/kali-menu
  • /usr/libexec/cruft/kali-themes-common
  • /usr/libexec/cruft/lightdm
  • /usr/libexec/cruft/LINUX-IMAGE
  • /usr/libexec/cruft/LOGROTATE
  • /usr/libexec/cruft/LOST_FOUND
  • /usr/libexec/cruft/munin
  • /usr/libexec/cruft/raspi-firmware
  • /usr/libexec/cruft/ruby
  • /usr/libexec/cruft/runit-helper
  • /usr/libexec/cruft/selinux-policy-default
  • /usr/libexec/cruft/SERVICES
  • /usr/libexec/cruft/sudo
  • /usr/libexec/cruft/systemd-sysv
  • /usr/libexec/cruft/TMPFILES
  • /usr/libexec/cruft/ucf
  • /usr/libexec/cruft/USERS
  • /usr/libexec/cruft/virtualbox-dkms
  • /usr/libexec/cruft/WSL2
  • /usr/libexec/cruft/xserver-xorg-core
  • /usr/libexec/cruft/zfs-dkms
  • /usr/libexec/cruft/zsh
  • /usr/share/cruft/bugs
  • /usr/share/cruft/ignore
  • /usr/share/cruft/ruleset
  • /usr/share/cruft/ruleset-minimal
  • /usr/share/doc/cruft-ng/changelog.gz
  • /usr/share/doc/cruft-ng/copyright
  • /usr/share/doc/cruft-ng/flow.ditaa
  • /usr/share/doc/cruft-ng/flow.png
  • /usr/share/doc/cruft-ng/README.md
  • /usr/share/doc/cruft-ng/TODO
  • /usr/share/lintian/overrides/cruft-ng
  • /usr/share/man/man8/cpigs.8.gz
  • /usr/share/man/man8/cruft.8.gz

Field source: Debian 13 (Trixie) main amd64 revision trixie-main-amd64:3ab4e811cf4f3e5a335d382c58cc19d85f1abe7a4ef4689160ca1f637fa0e9b3

Use this package

OpenFactory can boot this operating system in a browser VM, or start a build that includes the native package name from this record.

Versions, suites, and repositories

Each row is recorded package-index metadata for one version, architecture, suite, and repository. Names, URLs, and sizes are source-reported; a link is a potentially mutable retrieval location, not an OpenFactory redistribution claim or proof that OpenFactory retained the artifact bytes.

VersionReleaseArchitectureRepositoryPackage sizeInstalled sizePublisher repository artifact
0.9.71trixie / mainamd64Debian 13 · main · amd64200 KiB887 KiBpool/main/c/cruft-ng/cruft-ng_0.9.71_amd64.deb
0.9.71trixie / mainarm64Debian 13 · main · arm64187 KiB911 KiBpool/main/c/cruft-ng/cruft-ng_0.9.71_arm64.deb

Field source: Debian 13 (Trixie) main amd64 revision trixie-main-amd64:3ab4e811cf4f3e5a335d382c58cc19d85f1abe7a4ef4689160ca1f637fa0e9b3

Checksums and observation dates

For an APT source, signature verification authenticates the repository metadata chain and the Packages index containing this source-reported artifact digest. It does not certify package safety.

0.9.71 / amd64Observed Sep 1, 2026 to Sep 1, 2026

Verification status: Metadata observed; artifact bytes were not independently fetched or hashed by this catalog import. The digest below is source-reported.

Source-reported sha256: 71f2f482a76b23ae98b534cfcc43ea30307f091f380b2ca1e80df1b4d4383ac7

After downloading that exact artifact, compare its bytes with the source-reported expected digest:

printf '%s %s\n' '71f2f482a76b23ae98b534cfcc43ea30307f091f380b2ca1e80df1b4d4383ac7' 'cruft-ng_0.9.71_amd64.deb' | sha256sum --check --strict -

A match establishes equality with the repository metadata value. It does not establish safety or catalog-side artifact retrieval.

Field source: Debian 13 (Trixie) main amd64 revision trixie-main-amd64:3ab4e811cf4f3e5a335d382c58cc19d85f1abe7a4ef4689160ca1f637fa0e9b3

0.9.71 / arm64Observed Sep 1, 2026 to Sep 1, 2026

Verification status: Metadata observed; artifact bytes were not independently fetched or hashed by this catalog import. The digest below is source-reported.

Source-reported sha256: 29cd7e44f153b685d7d393302db4535eba404ba9276222d60bde581bbaaae790

After downloading that exact artifact, compare its bytes with the source-reported expected digest:

printf '%s %s\n' '29cd7e44f153b685d7d393302db4535eba404ba9276222d60bde581bbaaae790' 'cruft-ng_0.9.71_arm64.deb' | sha256sum --check --strict -

A match establishes equality with the repository metadata value. It does not establish safety or catalog-side artifact retrieval.

Field source: Debian 13 (Trixie) main arm64 revision trixie-main-arm64:753da751bbc7a679f48bd1b623ffd4479cb6861c426118284c76eb82909e4908

Catalog record completeness

The completeness score measures metadata coverage, not software quality, security, compatibility, or suitability.

Summary and description
25/25
Artifact path and source digest
25/25
Dependency metadata
15/15
Package-file index
15/15
Homepage
5/5
License text
0/5
Source package or maintainer
10/10

Recorded total: 95/100

Field source: Debian 13 (Trixie) main amd64 revision trixie-main-amd64:3ab4e811cf4f3e5a335d382c58cc19d85f1abe7a4ef4689160ca1f637fa0e9b3, Debian 13 (Trixie) main arm64 revision trixie-main-arm64:753da751bbc7a679f48bd1b623ffd4479cb6861c426118284c76eb82909e4908. The cross-OS mapping is catalog-derived from the source-reported homepage; it does not establish authorship or publisher identity

Sources and provenance

Field-source links above resolve here. Each source entry names the metadata publisher, trust tier, exact snapshot revision, signature result, and observation time; catalog-derived mappings are labeled separately.

  • Authoritative source; repository metadata signature verified, revision trixie-main-amd64:3ab4e811cf4f3e5a335d382c58cc19d85f1abe7a4ef4689160ca1f637fa0e9b3

    Signature verification covers the configured repository metadata chain. It does not certify that the package is safe or suitable.

    Repository-signature verification record
    Signed-object SHA-256
    98b25b5cd185c59d34aa6e4c3e9b5b8f01bbe9d104fe2dcfbcd30dc0a14a59ed
    Signer fingerprint
    4CB50190207B4758A3F73A796ED0E7B82643E131
    Keyring revision
    debian-archive-keyring.gpg
    SHA-256 506b815cbb32d9b6066b4a2aa524071e071761e7e7f68c3ac74f3061ba852017
    Tool and policy
    gpgv (GnuPG) 2.4.9
    openfactory-software-catalog-signature-v1
    Verification time
    Sep 1, 2026
    Signed Release → package-index hash linkage

    Path: main/binary-amd64/Packages.xz
    Expected SHA-256: 3ab4e811cf4f3e5a335d382c58cc19d85f1abe7a4ef4689160ca1f637fa0e9b3
    Observed SHA-256: 3ab4e811cf4f3e5a335d382c58cc19d85f1abe7a4ef4689160ca1f637fa0e9b3
    Result: match verified

  • Authoritative source; repository metadata signature verified, revision trixie-main-arm64:753da751bbc7a679f48bd1b623ffd4479cb6861c426118284c76eb82909e4908

    Signature verification covers the configured repository metadata chain. It does not certify that the package is safe or suitable.

    Repository-signature verification record
    Signed-object SHA-256
    98b25b5cd185c59d34aa6e4c3e9b5b8f01bbe9d104fe2dcfbcd30dc0a14a59ed
    Signer fingerprint
    4CB50190207B4758A3F73A796ED0E7B82643E131
    Keyring revision
    debian-archive-keyring.gpg
    SHA-256 506b815cbb32d9b6066b4a2aa524071e071761e7e7f68c3ac74f3061ba852017
    Tool and policy
    gpgv (GnuPG) 2.4.9
    openfactory-software-catalog-signature-v1
    Verification time
    Sep 1, 2026
    Signed Release → package-index hash linkage

    Path: main/binary-arm64/Packages.xz
    Expected SHA-256: 753da751bbc7a679f48bd1b623ffd4479cb6861c426118284c76eb82909e4908
    Observed SHA-256: 753da751bbc7a679f48bd1b623ffd4479cb6861c426118284c76eb82909e4908
    Result: match verified