Product

Overview

How it works Watch it work All 35 features Screenshots How ForgeRepo™ is secured

Keep bad packages out

Malware scanning Typosquat detection Dependency confusion protection Cooling off new releases Allow lists and block lists

When something goes wrong

Kill switch Who has it Lockdown and degraded modes Vulnerability monitoring

Developers and approvals

Requests and auto approve Check, walk and review Waivers Dry run
Formats

Languages

Private npm registry PyPI proxy and private index Private NuGet feed and proxy Maven repository proxy RubyGems mirror Composer and Packagist proxy

Apple, containers and Linux

CocoaPods CDN mirror Swift package registry Docker registry mirror RPM mirror for dnf and yum APT mirror for Debian and Ubuntu

Use it as

An npm firewall Artifacts, SBOMs and lifecycle More than one node SSO, roles and allow lists
Learn

Guides

Learn secure development Secure coding Secure pipelines Unsafe vs safe Security and development

Supply chain

Supply chain attacks, 2016 to 2026 Software supply chain security
Compare Side by side, all four ForgeRepo™ vs JFrog ForgeRepo™ vs Sonatype ForgeRepo™ vs Cloudsmith
Docs

Start

Getting started Download All documentation Questions

For developers

npm setup pip setup docker login Push a Docker image CI basics

For administrators

First setup Rules and their order Six incidents, walked through Backup and upgrade
Pricing Install it

Screenshots

Every screen, nothing mocked up

34 captures of ForgeRepo™ 1.0.0, taken with a headless browser against a seeded demo registry. Click any of them to see it full size, and use the arrow keys to move through them.

Or let it show you around

The same screens, in the order a developer meets them.

https://packages.company.internal/_admin/
Step 1

A developer's first ten minutes 0:00 / 0:00

A guided walkthrough built from real screenshots, not recorded video. Use the arrows, or the left and right keys, to go at your own pace.

Security at a glance

packages.example.com/_admin/
The dashboard. Registry mode, auto approve, and cards for what needs a look.
packages.example.com/_admin/
Dashboard cards: vulnerable, malicious, license violations, risky packages in use, integrity alerts, waivers and bandwidth.
packages.example.com/_admin/
The kill switch. One package, some versions, a file hash, an advisory, or a CSV of hundreds.
packages.example.com/_admin/
Vulnerabilities, with the developer switches: answer npm audit, warn during the install, record who downloaded what.
packages.example.com/_admin/
Quarantine. Every held file, why, and release or reject.
packages.example.com/_admin/
Waivers. Time boxed exceptions, scoped to an application or environment, with a ticket.

Packages and rules

packages.example.com/_admin/
Adding a rule: type, pattern, allow or deny, version range, priority, application and environment.
packages.example.com/_admin/
The version ranges a rule understands, the same ones npm does.
packages.example.com/_admin/
Packages. Everything asked for, what the rules say, and what is cached.
packages.example.com/_admin/
Artifacts. npm tarballs, Python wheels and image layers, each stored once by SHA-256.
packages.example.com/_admin/
Dry run. A proposed deny rule replayed against 30 days of real downloads.
packages.example.com/_admin/
Import and export. Rules as JSON or CSV, or the whole config, with a try it first button.

Developers and approvals

packages.example.com/_admin/
Requests as an approver sees them, each already scanned, with approve, block, clear and check deps.
packages.example.com/_admin/
A developer asking for a package, with the state of everything they asked for.
packages.example.com/_admin/
Check a package. What the rules say about a name and version before anybody installs it.
packages.example.com/_admin/
The dependency tree of axios: 29 packages, every one of them judged.
packages.example.com/_admin/
Reviewing a package-lock.json against the rules and the advisory feed.
packages.example.com/_admin/
Tokens. Name, expiry and a contact address for shared build tokens.
packages.example.com/_admin/
A new token, shown once, with the npm, pip and docker commands to use it.
packages.example.com/_admin/
The documentation built into the portal, written for the reader's role.

Watching and investigating

packages.example.com/_admin/
Traffic. Every request, with the token, application and environment, and a why link on each line.
packages.example.com/_admin/
Consumers. Who took a package, a version, a file or an advisory.
packages.example.com/_admin/
The audit trail. Who, from where, what, and whether it worked, failed or was refused.
packages.example.com/_admin/
Utilization. Live gauges for CPU, memory, disk and network, and trends you can zoom.

Settings and access

packages.example.com/_admin/
The sign in page. Local accounts, or single sign on with OpenID Connect.
packages.example.com/_admin/
Settings, Policy: whitelist or blacklist, audit only, quarantine, safe version resolution and cooling off.
packages.example.com/_admin/
Settings, Registries: package types, which clients to answer, and the upstream registries.
packages.example.com/_admin/
Settings, Malware: scanners, what each verdict does, and scan before serving.
packages.example.com/_admin/
Settings, Licenses: allowed, needs review and blocked, in SPDX.
packages.example.com/_admin/
Settings, Storage: local disk or an S3 or Azure bucket.
packages.example.com/_admin/
Settings, SSO: OpenID Connect against Okta, Entra ID, Google or Keycloak.
packages.example.com/_admin/
Users and their roles.
packages.example.com/_admin/
Whitelists: which networks may reach the portal and the registry, and break glass keys.
packages.example.com/_admin/
Integrations: a signed SIEM webhook and its deliveries.

Seen enough to try it?

A Linux box with Docker, or one without it, and a reverse proxy for TLS. The installer does the rest and it is safe to run twice. Free, MIT licensed, nothing to sign up for.