Your private registry for everything your builds produce, and a pull-through cache for everything they depend on — with policy enforced before anything reaches a developer, pipeline, or agent.
Point your tools at you.caskary.dev and ship.
An artifact registry is the warehouse between your build and your deploys: outputs get packaged, versioned, and stored once — then every pipeline, environment, and developer pulls the exact same bits.
Mix npm packages, JARs, OCI images, and AI models — Hugging Face, NVIDIA NIM, Ollama — in a single repository with one access model. No per-format repo sprawl.
Proxy npmjs, Maven Central, Hex.pm, Docker Hub — even generic files your builds fetch with curl or wget — through one stable endpoint. Builds keep working when upstreams don't. Every artifact is delivered from a global edge network, close to your runners and developers.
Block on scan, quarantine suspect packages, and enforce license policy before an artifact ever reaches a developer or pipeline.
Native support for most package formats — real indexes, real metadata, verified working against each ecosystem's real clients. Not a raw-file bucket with a format label on it.
Package formats and clients, counted the way vendors count. As of mid-2026.
No dedicated admin, no week of plumbing. Caskary meets your tooling where it already is.
Drop-in integrations for GitHub Actions, GitLab CI, CircleCI, and Jenkins. Authenticate with short-lived OIDC tokens — no long-lived secrets to rotate or leak.
The Caskary CLI writes the .npmrc, pip.conf, and settings.xml for you — point every package manager at your registry with a single command, per project or machine-wide.
See what's flowing, what's cached, and what the policy gate blocked — with per-repo usage and download trends. Monitoring built in, not bolted on.
Promote immutable versions from staging to production repos — what you tested is byte-for-byte what ships. No rebuild, no drift.
A full REST API, Terraform provider, and webhooks — with the CI integrations above included out of the box. If you can click it, you can script it.
Search every repo by name, version, checksum, or metadata — one search across all formats, packages and models alike.
AI agents now write, resolve, and install dependencies at machine speed — and attackers publish packages built for exactly that. Caskary verifies every artifact at ingestion. All of it is built into the base price — security is never an add-on.
Every upstream pull is held until scanning completes — malware, CVEs, license violations, and install-script behavior. Blocked packages never touch your builds; quarantined ones wait for human review.
Sigstore signing, SLSA build attestations, and a per-artifact SBOM — generated automatically on publish. Trace any binary in production back to the commit, builder, and dependencies that produced it.
Caskary screens for the full spectrum of AI-era attacks: slopsquats and dependency confusion, prompt-injection payloads hidden in READMEs and metadata, poisoned model weights and pickled code, hijacked maintainer accounts, and install scripts that exfiltrate at build time.
AI models and agent skills are artifacts too. Store them with the same policy engine, scanning, and audit trail as your packages — one source of truth for everything your agents consume.
Write declarative rules in Cedar, managed in one central place — enforced across all your package formats, or scoped to just the repos you choose. Every decision is logged, so compliance is easy to see.
A Type II examination is an enterprise launch gate. We publish the report only after the independent examination is complete.
SAML login, per-repo roles, and scoped tokens for humans, pipelines, and agents.
Expire old versions automatically, per repo — storage stays flat instead of growing forever.
A flat platform fee per seat with generous transfer included — published, self-serve, and priced so a small team can start today with no sales call.
One-command importers for every major registry mirror your repositories, versions, and metadata — pipelines cut over with a URL change. Every migration path is documented step by step — and if you want a hand, our engineers will guide you through it.
Caskary is in early access. Tell us where your artifacts live today and we'll get you set up.