Distribution that states what was tested.
Software built for an architecture most buyers do not yet own needs more than a description. A RISC-V listing carries the architectures it was built for, the profile it was tested against, the scan results and the date, so an install is a decision rather than a gamble.
Where this stands today
PlannedThe Aevornix Store is live and carries a real catalogue. It has no RISC-V category. The catalogue was checked on 2026-07-26 and no product in it declares RISC-V architecture support. Everything below is the schema a category would be built on, not a description of something you can browse.
Trust chain
From a developer to an install.
Each step adds something a buyer can check. A listing that skipped a step shows the gap rather than a default value. An unscanned package is not the same as a package that passed.
Developer
A verified publishing account submits the product.
Package
The artefact, its manifest and its declared targets.
Architecture scan
Which architectures a build genuinely exists for.
Security scan
Supply chain, signing and a software bill of materials.
Licence check
The declared licence, and whether the terms match the listing.
Compatibility badge
What was tested, against which profile, on what date.
Store listing
Everything above, shown to a buyer before they install.
User install
Installation on a target that matches the listed architecture.
Listing schema
12 fields on every RISC-V listing.
What a buyer sees before installing. The compatibility score and the last-tested date are the two that most often go missing elsewhere, so both are required fields rather than optional ones.
- Product name
- What the product is called, and the package identifier it installs under.
- Developer
- The publishing account, with its verification state.
- Licence
- The licence the product is distributed under, and whether the source is available.
- Architecture support
- Which architectures a build exists for: riscv64, and any others shipped alongside.
- Operating-system target
- The system the build expects, at the version it was tested against.
- Runtime target
- Any runtime the product needs present, and the version range it accepts.
- Security scan
- Supply-chain and signing findings from the most recent scan, with its date.
- Compatibility score
- A score produced by running the scanner against a named profile. A listing without a completed scan shows no score rather than a default one.
- Last tested date
- When the product was last run against the target profile. Absent where it has not been.
- Install method
- How the product is installed: package, image, archive or runtime bundle.
- Source availability
- Whether source is published, and where.
- Commercial use status
- Whether commercial use is permitted, and under what terms.
Categories
Ten categories under the RISC-V heading.
Grouped by what the software is for rather than by which toolchain produced it. A buyer looking for a media player is not searching by build system.
- Linux applications
- Desktop and command-line software built for 64-bit RISC-V Linux.
- Developer tools
- Toolchains, debuggers, profilers and build utilities.
- AI models
- Models packaged with a runtime and a scan report.
- Mobile applications
- Applications for the open mobile foundation.
- Media applications
- Playback, capture and encoding software.
- Education tools
- Teaching and lab software for open-architecture computing.
- Security tools
- Scanning, signing, auditing and hardening utilities.
- Kiosk applications
- Single-purpose deployments for fixed-function devices.
- Runtime packages
- Interpreters, virtual machines and shared runtime layers.
- System images
- Bootable images for supported RISC-V targets.
Badges
Six badges, each earned by something.
A badge is worth nothing unless it names what produced it. Every badge below states the system that awards it. None can be awarded yet, because those systems are still being built.
| Badge | What it means | Awarded by |
|---|---|---|
| riscv64-ready | A 64-bit RISC-V build exists and installs. | Build output |
| emulator-tested | The build ran in an emulated profile and its test suite passed. | RVStack Developer Cloud |
| native-build | Built and tested on physical RISC-V hardware, not only emulation. | Physical test capacity |
| ai-runtime-ready | Model, runtime and configuration are packaged together and load successfully. | RVStack AI Runtime |
| security-scanned | A supply-chain and signing scan completed, with findings published. | Security report |
| store-certified | A full certification report passed against a named profile on a stated date. | RVStack Certify |
RISC-V