Product

Overview

How it works Watch it work All 35 features Screenshots How ForgeRepo™ is secured

Keep bad packages out

Malware scanning Typosquat detection Dependency confusion protection Cooling off new releases Allow lists and block lists

When something goes wrong

Kill switch Who has it Lockdown and degraded modes Vulnerability monitoring

Developers and approvals

Requests and auto approve Check, walk and review Waivers Dry run
Formats

Languages

Private npm registry PyPI proxy and private index Private NuGet feed and proxy Maven repository proxy RubyGems mirror Composer and Packagist proxy

Apple, containers and Linux

CocoaPods CDN mirror Swift package registry Docker registry mirror RPM mirror for dnf and yum APT mirror for Debian and Ubuntu

Use it as

An npm firewall Artifacts, SBOMs and lifecycle More than one node SSO, roles and allow lists
Learn

Guides

Learn secure development Secure coding Secure pipelines Unsafe vs safe Security and development

Supply chain

Supply chain attacks, 2016 to 2026 Software supply chain security
Compare Side by side, all four ForgeRepo™ vs JFrog ForgeRepo™ vs Sonatype ForgeRepo™ vs Cloudsmith
Docs

Start

Getting started Download All documentation Questions

For developers

npm setup pip setup docker login Push a Docker image CI basics

For administrators

First setup Rules and their order Six incidents, walked through Backup and upgrade
Pricing Install it

Features

35 things it does, all in the free version

There is no paid tier to unlock. Grouped by when you need them: keeping bad packages out, the morning something gets through anyway, the developers and approvers who use it every day, and running it.

Formats and running it

Private npm registry

npm, pnpm, Yarn and Bun. Publish your own packages under reserved names, mirror the rest.

Read more

PyPI proxy and private index

pip, uv and Poetry. PEP 503, 691, 658 and 700, and twine uploads for your own projects.

Read more

Docker registry mirror

Pull through Docker Hub, GHCR, Quay or Harbor, and push your own images to reserved namespaces. Everything by digest, the layers scanned.

Read more

Private NuGet feed and proxy

dotnet and Visual Studio through nuget.org or a private feed, and dotnet nuget push for your own ids.

Read more

Maven repository proxy

mvn, Gradle and sbt through Maven Central, Nexus or Artifactory. Every file checked against its .sha1.

Read more

RubyGems mirror

Bundler and gem install through the compact index, with every .gem checked against its sha256.

Read more

Composer and Packagist proxy

Composer through Packagist. Each release is fetched once from its exact commit, scanned and kept.

Read more

CocoaPods CDN mirror

pod install through a CDN that lists only allowed pods, with their code fetched, checked and scanned here.

Read more

Swift package registry

SwiftPM through an SE-0292 registry that serves GitHub tags as releases, each archive scanned and kept.

Read more

RPM mirror for dnf and yum

AlmaLinux, Rocky Linux and Red Hat repositories, every package checked and scanned before dnf gets it.

Read more

APT mirror for Debian and Ubuntu

Debian and Ubuntu archives for apt, every .deb checked and scanned, with an optional filtered index.

Read more

Artifacts, SBOMs and lifecycle

Every file stored once by SHA-256, CycloneDX and SPDX out, properties and promotion stages.

Read more

S3 and Azure storage

Keep the cache in a bucket. Every upload checked by hash, and a local copy cap on the disk.

Read more

SSO, roles and allow lists

OpenID Connect, five roles checked on every request, IP allow lists and break glass keys.

Read more

SIEM and email

Signed webhooks, Splunk HEC and syslog in JSON or CEF. Digests instead of a mail per event.

Read more

More than one node

Point two nodes at one MariaDB, RDS included, and put a load balancer in front.

Read more

And the plumbing

The small things that make it pleasant

  • Every refusal in the traffic log has a why link that explains it in one place: the rule or check, the evidence, and what to do next.
  • Import and export of rules as JSON or CSV with no limit, in one transaction, with a try it first button.
  • Cache housekeeping that catches the database and the disk drifting apart, and puts things back.
  • Your own name, header icon and favicon in the portal.
  • Documentation built into the portal for each role, with your address in every example and a PDF of it.
  • Stale metadata served when npm or PyPI is down, for as long as you say.
  • Upgrades with one command that tag the running image first, so a bad one goes back in one more.
packages.example.com/_admin/
Traffic. Every request, filterable, with the token, application and environment behind it.

One container, about two minutes

A Linux box with Docker, or one without it, and a reverse proxy for TLS. The installer does the rest and it is safe to run twice. Free, MIT licensed, nothing to sign up for.