Product

Overview

How it works Watch it work All 35 features Screenshots How ForgeRepo™ is secured

Keep bad packages out

Malware scanning Typosquat detection Dependency confusion protection Cooling off new releases Allow lists and block lists

When something goes wrong

Kill switch Who has it Lockdown and degraded modes Vulnerability monitoring

Developers and approvals

Requests and auto approve Check, walk and review Waivers Dry run
Formats

Languages

Private npm registry PyPI proxy and private index Private NuGet feed and proxy Maven repository proxy RubyGems mirror Composer and Packagist proxy

Apple, containers and Linux

CocoaPods CDN mirror Swift package registry Docker registry mirror RPM mirror for dnf and yum APT mirror for Debian and Ubuntu

Use it as

An npm firewall Artifacts, SBOMs and lifecycle More than one node SSO, roles and allow lists
Learn

Guides

Learn secure development Secure coding Secure pipelines Unsafe vs safe Security and development

Supply chain

Supply chain attacks, 2016 to 2026 Software supply chain security
Compare Side by side, all four ForgeRepo™ vs JFrog ForgeRepo™ vs Sonatype ForgeRepo™ vs Cloudsmith
Docs

Start

Getting started Download All documentation Questions

For developers

npm setup pip setup docker login Push a Docker image CI basics

For administrators

First setup Rules and their order Six incidents, walked through Backup and upgrade
Pricing Install it

Privacy

What this site collects, and what it does not

The short version: the web servers keep ordinary access logs, and Google Analytics runs only if you say yes. There are no accounts, no forms, no ads, and nothing is sold.

Last updated 20 September 2026.

Who runs this site

www.forgerepo.com is run by Tim Rice, who writes and maintains ForgeRepo™. For privacy law purposes, that makes Tim Rice the controller of the personal data described here.

Server logs

Like almost every website, the servers and load balancers that serve this site record each request: your IP address, the date and time, the page asked for, the response code and size, the page you came from, and your browser's user agent.

These logs are used to keep the site running and secure: to find faults, and to spot and block abuse. They are not used to profile anyone and are not shared. The logs have a fixed size limit, so old lines are deleted automatically as new ones arrive. The legal basis is legitimate interest in operating a secure website.

Google Analytics, only if you accept

When you first visit, a small notice asks whether we may use Google Analytics. Until you choose Accept, nothing from Google is loaded. If you choose Decline, or your browser sends a Global Privacy Control signal, it never loads at all.

If you accept, Google Analytics records which pages you view, how you arrived, your device and browser type, and your approximate location, worked out from your IP address. Google Analytics 4 does not store the IP address itself. It sets two cookies, _ga and _ga_<id>, which last up to two years and let it tell a returning visitor from a new one. Google signals and ad personalization are switched off, so the data is not linked to your Google account or used for advertising.

Google processes this data on our behalf and may process it in the United States. See how Google uses information from sites that use its services and Google's privacy policy. Google Analytics keeps detailed event data for the retention period set on the property, two months unless changed. The legal basis is your consent.

Changing your mind: use , also at the bottom of every page. Switching to Decline removes the Google cookies from this site straight away.

Stored in your browser

Two small settings are kept in your browser's local storage and are never sent to the server:

  • flb-theme: whether you picked the light or dark theme, if you did.
  • fr-consent: your answer to the analytics question, so it is not asked again.

Site search runs entirely in your browser. What you type into it is not sent anywhere.

What this site does not do

  • No accounts, sign ups, newsletters or contact forms.
  • No advertising, and no advertising or social media trackers.
  • No fonts, scripts or images loaded from other companies, apart from Google Analytics after you accept.
  • Nothing is sold or shared for marketing.

The ForgeRepo™ software

This page is about this website. ForgeRepo™ itself runs on your own servers and sends nothing to its author: no telemetry, no license checks and no usage reports. What it records, such as who downloaded which package, stays on the box you run. See how ForgeRepo™ is secured.

Your rights

Depending on where you live, including under the GDPR, UK GDPR and California law, you can ask to see the personal data held about you, have it corrected or deleted, object to how it is used, or withdraw consent at any time. For analytics, Cookie settings does this directly. You can also complain to your local data protection authority.

Contact

For any privacy question or request, write to privacy@forgerepo.com.

Changes to this page

If what this site collects changes, this page changes first, and the date at the top moves with it.