Start here
What ForgeRepo™ does for you
One address for every package and image your code uses, checked before it reaches your laptop or your pipeline.
ForgeRepo™ sits between your tools and the public registries. When you run npm install, pip install or docker pull, your tool asks ForgeRepo™ at packages.example.com instead of the internet. ForgeRepo™ checks the package against your company rules, fetches it if it is allowed, and hands it back.
This protects you from packages that are malicious, typosquatted, known to be vulnerable, or simply not approved yet. It also means that when a bad version is found, your security team can see who has it and stop it everywhere at once.
What you need to do
- Sign in to the portal at https://packages.example.com/_admin. See Signing in.
- Make a token. See Make a token.
- Point your tools at packages.example.com: npm, pip or docker.
- Install as usual. If something is blocked, the error says why. See When something is blocked.