packages · containers · models · skills

The artifact registry that just works.

Your private registry for everything your builds produce, and a pull-through cache for everything they depend on — with policy enforced before anything reaches a developer, pipeline, or agent.

Point your tools at you.caskary.dev and ship.

Get early accessCompare us honestly
$ npm config set registry https://acme.caskary.dev/npm $ npm publish # pnpm & yarn work toopublished @acme/ui@2.1.0

Build once. Store it. Ship it anywhere.

An artifact registry is the warehouse between your build and your deploys: outputs get packaged, versioned, and stored once — then every pipeline, environment, and developer pulls the exact same bits.

you publishci builddev publishpull-through cachenpm.jsdocker hubcaskaryscan · signpolicy gateregistryglobal edgeci runnerskubernetesdevelopers

One repo, many package formats

Mix npm packages, JARs, OCI images, and AI models — Hugging Face, NVIDIA NIM, Ollama — in a single repository with one access model. No per-format repo sprawl.

Upstream proxy & cache

Proxy npmjs, Maven Central, Hex.pm, Docker Hub — even generic files your builds fetch with curl or wget — through one stable endpoint. Builds keep working when upstreams don't. Every artifact is delivered from a global edge network, close to your runners and developers.

Policy at the gate

Block on scan, quarantine suspect packages, and enforce license policy before an artifact ever reaches a developer or pipeline.

Whatever you use, we probably speak it.

Native support for most package formats — real indexes, real metadata, verified working against each ecosystem's real clients. Not a raw-file bucket with a format label on it.

npm
pnpmvia npm
Yarnvia npm
JSRdeno, bun
Dockervia OCI
Helmvia OCI
Podmanvia OCI
ORASvia OCI
WASMvia OCI
Ollamavia OCI
PyPIpip, twine
uvvia PyPI
Poetryvia PyPI
Conda
Maven
Gradle
sbt
NuGet
PowerShellvia NuGet
Chocolateyvia NuGet
Go
Cargo
RubyGems
PHP Composer
Debianapt, dpkg
RPMdnf, yum
Alpineapk
Hugging Face
NVIDIAnim
Swift
CocoaPods
Dartvia Pub
Fluttervia Pub
Terraform
Ansible
Chef
Vagrant
Homebrewtaps, bottles
winget
Snap
Flatpak
Git LFS
CRAN
Hex
Nix
Bazel
Conan
vcpkg
CPANperl
LuaRocks
Spack
P2eclipse
Unityupm
Genericcurl, wget
And growing

Supported package formats, by comparison

Package formats and clients, counted the way vendors count. As of mid-2026.

Caskary
50+
JFrog Artifactory
40+
Cloudsmith
30+
Sonatype Nexus
~18
AWS CodeArtifact
~8
GitHub Packages
6

Set up in minutes, not sprints.

No dedicated admin, no week of plumbing. Caskary meets your tooling where it already is.

CI-native from day one

Drop-in integrations for GitHub Actions, GitLab CI, CircleCI, and Jenkins. Authenticate with short-lived OIDC tokens — no long-lived secrets to rotate or leak.

One CLI, zero config archaeology

The Caskary CLI writes the .npmrc, pip.conf, and settings.xml for you — point every package manager at your registry with a single command, per project or machine-wide.

A dashboard worth opening

See what's flowing, what's cached, and what the policy gate blocked — with per-repo usage and download trends. Monitoring built in, not bolted on.

Stage, test, promote

Promote immutable versions from staging to production repos — what you tested is byte-for-byte what ships. No rebuild, no drift.

Automate everything

A full REST API, Terraform provider, and webhooks — with the CI integrations above included out of the box. If you can click it, you can script it.

Find anything, instantly

Search every repo by name, version, checksum, or metadata — one search across all formats, packages and models alike.

supply chain integrity

Nothing enters the cask unverified.

AI agents now write, resolve, and install dependencies at machine speed — and attackers publish packages built for exactly that. Caskary verifies every artifact at ingestion. All of it is built into the base price — security is never an add-on.

Dependency firewall

Every upstream pull is held until scanning completes — malware, CVEs, license violations, and install-script behavior. Blocked packages never touch your builds; quarantined ones wait for human review.

Provenance, signed end to end

Sigstore signing, SLSA build attestations, and a per-artifact SBOM — generated automatically on publish. Trace any binary in production back to the commit, builder, and dependencies that produced it.

Built for the AI threat landscape

Caskary screens for the full spectrum of AI-era attacks: slopsquats and dependency confusion, prompt-injection payloads hidden in READMEs and metadata, poisoned model weights and pickled code, hijacked maintainer accounts, and install scripts that exfiltrate at build time.

Models and skills, governed

AI models and agent skills are artifacts too. Store them with the same policy engine, scanning, and audit trail as your packages — one source of truth for everything your agents consume.

Policy as code

Write declarative rules in Cedar, managed in one central place — enforced across all your package formats, or scoped to just the repos you choose. Every decision is logged, so compliance is easy to see.

// caskary serving policy
forbid (
principal,
action == Action::"serve",
resource
)
when {
resource.age_hours < 48 ||
resource.max_cvss >= 7.0 ||
["AGPL-3.0", "SSPL-1.0"]
.contains(resource.license)
};
policyallowedquarantined☠︎

SOC 2 on the enterprise roadmap

A Type II examination is an enterprise launch gate. We publish the report only after the independent examination is complete.

SSO & fine-grained access

SAML login, per-repo roles, and scoped tokens for humans, pipelines, and agents.

Retention & cleanup policies

Expire old versions automatically, per repo — storage stays flat instead of growing forever.

Published. Predictable. No sales call to start.

A flat platform fee per seat with generous transfer included — published, self-serve, and priced so a small team can start today with no sales call.

$45per seat / month
All package formats, all clientsSecurity built in — scanning, signing & policy gate at no extra costSSO & role-based access included50 GB data transfer per seat, pooled, then $0.25/GB25 GB storage per seat, pooled, then $0.25/GB/mo
Get early accesspricing may vary while in early access — but we'll never surprise you
Enterprise
Everything in self-serveSCIM provisioning & audit log exportsUptime SLA & support commitmentsVolume and multi-year pricingA migration engineer assigned to your rollout
Talk to an engineersame transparency as the published plan — no renewal squeeze

Already on another registry?

One-command importers for every major registry mirror your repositories, versions, and metadata — pipelines cut over with a URL change. Every migration path is documented step by step — and if you want a hand, our engineers will guide you through it.

Take control of your assets.

Caskary is in early access. Tell us where your artifacts live today and we'll get you set up.