Skip to main content
LAST MIRROR METADATA SYNC: 2026-08-07 14:00 UTC STATUS: OPERATIONAL CHANNEL: os.webservice.digital All curated distribution metadata channels green.

Distribution Mirror Hub

· 8 CHANNELS · AMD64 PRIMARY

Ubuntu 26.04

Resolute Raccoon · amd64

LTS lts desktop server

Latest Ubuntu LTS desktop image. Five years of free security maintenance; enterprise option via Ubuntu Pro.

ISO ubuntu-26.04-desktop-amd64.iso (~6.1G)
SHA256 487f87faaf547ea30e0aba4d5b53346292571256b25333a978db1692bcee9dd2
Verify echo "487f87faaf547ea30e0aba4d5b53346292571256b25333a978db1692bcee9dd2 *ubuntu-26.04-desktop-amd64.iso" | sha256sum -c -

Debian 13.6.0

Trixie · amd64

stable stable netinst server

Debian Stable netinst ISO — minimal network installer for production-grade deployments.

ISO debian-13.6.0-amd64-netinst.iso (~755M)
SHA256 65273beed27b2df543b68b65630ba525cfbad8df2b12035732b2dff87d6664e7
Verify echo "65273beed27b2df543b68b65630ba525cfbad8df2b12035732b2dff87d6664e7 *debian-13.6.0-amd64-netinst.iso" | sha256sum -c -

Fedora 44

x86_64 · Fedora

current desktop live current

Fedora Workstation 44 Live — cutting-edge desktop stack with a fixed-release cadence (~6 months).

ISO Fedora-Workstation-Live-44-1.7.x86_64.iso (~2.7G)
SHA256 1620295f6a00c27c3208f0c00b8ece4eab1ec69b9002152d97488bf26a426ddf
Verify echo "1620295f6a00c27c3208f0c00b8ece4eab1ec69b9002152d97488bf26a426ddf *Fedora-Workstation-Live-44-1.7.x86_64.iso" | sha256sum -c -

Arch Linux 2026.08.01

x86_64 · Arch

rolling rolling minimal

Monthly Arch Linux bootstrap ISO for the rolling-release model. Install once; keep rolling.

ISO archlinux-2026.08.01-x86_64.iso (~1.2G)
SHA256 4e82dced1c4fd3e498b22a853f8db2a4d262d32b97e7e07d97390d9e425ffe5e
Verify echo "4e82dced1c4fd3e498b22a853f8db2a4d262d32b97e7e07d97390d9e425ffe5e *archlinux-2026.08.01-x86_64.iso" | sha256sum -c -

openSUSE Leap 16.0

x86_64 · SUSE

stable stable enterprise-aligned

openSUSE Leap 16.0 online installer — stable, enterprise-aligned fixed release.

ISO Leap-16.0-online-installer-x86_64.install.iso (online)
SHA512 47241c708de25e18cf2d58fb592aa4b4ad9120e1c26b020350e3dc9c8e68efafaeaaf31ddd989825b5bbbfe3f95fbbb72afc8ee34ceb7d7de664536dd49cd441
Verify echo "47241c708de25e18cf2d58fb592aa4b4ad9120e1c26b020350e3dc9c8e68efafaeaaf31ddd989825b5bbbfe3f95fbbb72afc8ee34ceb7d7de664536dd49cd441 *Leap-16.0-online-installer-x86_64.install.iso" | sha512sum -c -

openSUSE Tumbleweed Snapshot20260805

x86_64 · SUSE

rolling rolling netinst

openSUSE Tumbleweed NET ISO — continuous rolling release with automated openQA gating.

ISO openSUSE-Tumbleweed-NET-x86_64-Current.iso (netinst)
SHA256 08eaf4d81faf43c278bb82c81807ef3957127cd900bacee7482b267fc9ac1990
Verify echo "08eaf4d81faf43c278bb82c81807ef3957127cd900bacee7482b267fc9ac1990 *openSUSE-Tumbleweed-NET-x86_64-Current.iso" | sha256sum -c -

Linux Mint 22.3

64bit · Debian/Ubuntu

LTS lts desktop

Linux Mint 22.3 Cinnamon — polished LTS desktop based on Ubuntu LTS foundations.

ISO linuxmint-22.3-cinnamon-64bit.iso (~2.8G)
SHA256 a081ab202cfda17f6924128dbd2de8b63518ac0531bcfe3f1a1b88097c459bd4
Verify echo "a081ab202cfda17f6924128dbd2de8b63518ac0531bcfe3f1a1b88097c459bd4 *linuxmint-22.3-cinnamon-64bit.iso" | sha256sum -c -

Rocky Linux 10.2

x86_64 · RHEL

enterprise enterprise rhel-compatible minimal

Rocky Linux 10.2 minimal ISO — community enterprise OS, RHEL-compatible rebuild.

ISO Rocky-10.2-x86_64-minimal.iso (~2.0G)
SHA256 aac6ac3ce781b91a91ce78463405f66c611a5dca4b3840c79e5e01d97302f6c8
Verify echo "aac6ac3ce781b91a91ce78463405f66c611a5dca4b3840c79e5e01d97302f6c8 *Rocky-10.2-x86_64-minimal.iso" | sha256sum -c -

CLI Service Bridge

COMMAND: osdl · PURE SHELL

One-liner installer

Install the auditable shell client. Fetches live metadata from /api/v1/latest.json. Never proxies ISOs — only official URLs and published hashes.

$ curl -fsSL https://os.webservice.digital/cli/ | bash
osdl list List curated distributions and current versions.
osdl info <distro> Show version, official URL, hash, and verification command.
osdl get <distro> [--verify] [--print] Download from official URL; optional SHA verify. --print shows commands only.
osdl verify <file> <distro> Verify a local ISO against gateway-published digests.

WARNING: Hash verification confirms bit-identity with the published digest. Operators should still GPG-verify the upstream checksum files themselves.

Verification Workflow

DEFENSIVE PROTOCOL
  1. Obtain the ISO only from the official URL published on this gateway (or the distribution’s own site).
  2. Run the displayed sha256sum -c / sha512sum -c command against the local file.
  3. Download the official SHA256SUMS / CHECKSUM file and its GPG signature from the distribution project.
  4. Import the project’s signing key from a trusted path; run gpg --verify on the signature.
  5. Only then write the media (USB/hybrid) or boot the image.

FAQ

FORMAL BRIEFING
Does this site host or proxy Linux ISO files?

No. This gateway publishes metadata, official download URLs, and checksums only. All binary transfers occur directly between your client and the distribution’s official infrastructure or designated mirrors.

Is this an official mirror for any distribution?

No. os.webservice.digital is an independent operational gateway. It does not claim official mirror status for Ubuntu, Debian, Fedora, Arch, openSUSE, Linux Mint, Rocky Linux, or any other project.

How are hashes kept current?

Operators update data/catalog.json after validating digests against each project’s official checksum files. The status banner’s LAST MIRROR METADATA SYNC timestamp reflects the last such refresh in UTC.

How do I install and use the CLI tool?

Run curl -fsSL https://os.webservice.digital/cli | bash to install osdl into ~/.local/bin (or a path you choose). Then use osdl list, info, get, and verify as documented above. Prefer inspecting the installer with curl -fsSL …/cli before piping to bash in sensitive environments.

Does osdl get --verify replace GPG verification?

No. Automatic SHA verification only checks that the downloaded file matches the digest published by this gateway. You remain responsible for verifying official checksum files with the distribution’s GPG keys.

What does the operational status banner mean?

OPERATIONAL — metadata is current and channels are considered healthy. DEGRADED — partial issues (stale entries or known upstream issues). MAINTENANCE — planned update window; treat hashes as possibly in flux.

Which architectures are covered?

Primary focus is x86_64 / amd64. Other architectures may be listed in official pages; this hub curates the mainstream 64-bit PC images used by most operators.

How do I consume the public API?

GET /api/v1/latest.json for the full payload (status + distributions). GET /api/v1/distros.json for distributions only. GET /api/v1/status.json for the banner fields. CORS is open for read-only GET.

Is there tracking or third-party analytics?

No. No advertising, no third-party trackers, no external fonts or scripts. CSP is locked to same-origin assets.

Codeword Glossary

TERSE LEXICON
LTS
Long-Term Support release. Extended security maintenance window; preferred for production fleets.
ISO
Optical/disk image of an installer or live system. Usually hybrid (USB-writable) on modern distros.
SHA256
256-bit cryptographic hash. Confirms file bit-identity; does not prove authenticity alone without signed checksums.
SHA512
512-bit hash variant. Used by some projects (e.g. Debian, openSUSE Leap 16) alongside or instead of SHA256.
GPG
OpenPGP tooling for cryptographic signatures. Use to authenticate official checksum files from the project.
Mirror
Replica of official package/ISO content. This gateway is not a binary mirror — metadata only.
Netinst
Network installer image. Small local payload; packages fetched from online repositories during install.
Verify
Confirm a local ISO matches a published digest (and, ideally, that the digest file is GPG-authentic).
Hybrid
ISO constructed to boot from both optical media and USB mass storage without conversion.
Rolling
Continuously updated release model (Arch, Tumbleweed). No traditional “point” freeze for the base system.
Stable
Fixed-release train with controlled updates (Debian stable, Leap). Predictable for ops baselines.
Gateway
This service: curated links, hashes, status, and CLI — not a CDN for ISO bytes.
Channel
Logical feed identity for this site: os.webservice.digital.
osdl
Operator Shell Download Link — the CLI bridge command installed from /cli.