Product

Overview

How it works Watch it work All 35 features Screenshots How ForgeRepo™ is secured

Keep bad packages out

Malware scanning Typosquat detection Dependency confusion protection Cooling off new releases Allow lists and block lists

When something goes wrong

Kill switch Who has it Lockdown and degraded modes Vulnerability monitoring

Developers and approvals

Requests and auto approve Check, walk and review Waivers Dry run
Formats

Languages

Private npm registry PyPI proxy and private index Private NuGet feed and proxy Maven repository proxy RubyGems mirror Composer and Packagist proxy

Apple, containers and Linux

CocoaPods CDN mirror Swift package registry Docker registry mirror RPM mirror for dnf and yum APT mirror for Debian and Ubuntu

Use it as

An npm firewall Artifacts, SBOMs and lifecycle More than one node SSO, roles and allow lists
Learn

Guides

Learn secure development Secure coding Secure pipelines Unsafe vs safe Security and development

Supply chain

Supply chain attacks, 2016 to 2026 Software supply chain security
Compare Side by side, all four ForgeRepo™ vs JFrog ForgeRepo™ vs Sonatype ForgeRepo™ vs Cloudsmith
Docs

Start

Getting started Download All documentation Questions

For developers

npm setup pip setup docker login Push a Docker image CI basics

For administrators

First setup Rules and their order Six incidents, walked through Backup and upgrade
Pricing Install it

Container images

Pull an image

Put packages.example.com/ in front of the image name.

To pull an image through ForgeRepo™, put packages.example.com/ in front of the name you would use with Docker Hub.

Instead ofUse
docker pull nginx:latestdocker pull packages.example.com/nginx:latest
docker pull node:22-alpinedocker pull packages.example.com/node:22-alpine
docker pull bitnami/redis:7.4docker pull packages.example.com/bitnami/redis:7.4
Pull an image
$ docker pull packages.example.com/nginx:latest
...
9302921ce9b3: Verifying Checksum
9302921ce9b3: Download complete
6310eb16bf42: Pull complete
9302921ce9b3: Pull complete
ab606a349520: Pull complete
0478569e858e: Pull complete
76225461b7d3: Pull complete
c06193164a25: Pull complete
3fe5ab3f8614: Pull complete
Digest: sha256:d0d674272be3be36f9a13d79194fa0db5aa630ab3ede9bec459d12f67370aaef
Status: Downloaded newer image for packages.example.com/nginx:latest
packages.example.com/nginx:latest
$ docker images packages.example.com/nginx
REPOSITORY                        TAG       IMAGE ID       CREATED        SIZE
packages.example.com/nginx   latest    878c33739a8a   40 hours ago   170MB

Captured by running these commands against a real ForgeRepo™.

Note

Pulling by digest works too, like packages.example.com/nginx@sha256:.... A digest is only served when a tag the rules allow points at it, so a blocked tag cannot be pulled by its digest.