Software supply chain security
The registry is the one place every dependency passes
Scanners read what you already have. Signing proves who built what. A registry in the path is where you decide what gets in at all, and the only place that sees every install from every laptop and every pipeline. ForgeRepo™ is that registry for npm, PyPI, container images, NuGet, Maven, RubyGems, Composer, CocoaPods, Swift, RPM and APT.
1. Control what comes in
Every dependency passes one gate. Allow lists enforced in the metadata, reserved names against dependency confusion, lookalike names, a cooling off period for brand new releases, license rules, and a request and approval flow so the gate is not a wall.
Allow lists and block lists
Whitelist or blacklist by name, scope, wildcard or version range, for every type. A blocked version is not even listed to the client.
Read moreDependency confusion protection
Reserve your npm scopes, PyPI prefixes, image namespaces and NuGet ids. A public package with your internal name is never fetched.
Read moreTyposquat detection
lodahs, reqeusts, l0dash, python-numpy. Lookalike names are caught and warned about, or refused.
Read moreCooling off new releases
Brand new versions wait a few days before your builds see them, which is when hijacks get caught.
Read moreRequests and auto approve
A blocked install opens a request. Clean ones can approve themselves, risky ones wait for a person.
Read more2. Verify what it is
A file is only what its bytes are. Everything is stored and served by SHA-256, checked against what the registry published, scanned for malware, checked for Sigstore provenance, and held in quarantine when anything does not add up.
Malware scanning
ClamAV, a hash blocklist, your own scanner and the OpenSSF known malicious feed, on every cached file. Optionally before the first download.
Read moreProvenance verification
npm SLSA provenance and PyPI PEP 740 attestations checked against Sigstore, offline, on the box.
Read moreIntegrity alerts and quarantine
A file that changes after it was first seen is held. The original keeps being served.
Read moreLicense policy
Allowed, needs review and blocked SPDX lists, with holds that follow a license change.
Read more3. Know where it went
Every download is tied to a token, an application and an environment, and kept for a year. That gives you consumers by package, hash or CVE, and an SBOM of what each application actually pulled, not what its manifest claims.
Who has it
Search a package, a hash or a CVE and see the applications, environments and pipelines that pulled it.
Read moreArtifacts, SBOMs and lifecycle
Every file stored once by SHA-256, CycloneDX and SPDX out, properties and promotion stages.
Read moreTokens, apps and environments
Every download is tied to a token, an application and an environment. Rules can be scoped to them.
Read moreAudit trail
Every sign in and every change, with before and after, who, from where, and whether it worked.
Read more4. Act when it goes wrong
Advisories are rechecked against everything allowed and cached, with KEV and EPSS. A kill switch takes a bad release from everyone at once, and lockdown keeps building from what you hold while an ecosystem burns.
Vulnerability monitoring
OSV, CISA KEV and FIRST EPSS against everything allowed and cached. npm audit answered locally.
Read moreKill switch
Take a package, a version range, one file hash or a whole advisory away from everyone, at once.
Read moreLockdown and degraded modes
For the week an ecosystem is on fire. Stop fetching anything new, keep building from what you hold.
Read moreSafe version resolution
Versions with serious advisories are left out, so a range quietly settles on the newest safe one.
Read moreWhat a registry does not do
It does not read your own code for vulnerabilities, find secrets in your repositories, or sign your builds. Those are different tools. If you want the first two, free and self hosted as well, the same author wrote Git Code Review.
One container, about two minutes
A Linux box with Docker, or one without it, and a reverse proxy for TLS. The installer does the rest and it is safe to run twice. Free, MIT licensed, nothing to sign up for.