Skip to content

Supported features and formats

Ravenstash is a hosted private artifact repository for PyPI, npm, Maven, Container, and Helm OCI workflows.

  • Private, authenticated publishing and retrieval for every supported registry.
  • Any supported non-empty combination of PyPI, npm, Maven, and OCI in one repository.
  • Personal and organization ownership with namespace membership, invitations into namespaces, member suspension and seat limits, organization and namespace Teams, namespace administrators, Reader, Publisher, Maintainer, and Admin repository roles plus custom roles, additive grants, per-namespace base permissions, and explainable effective access.
  • Package and version views for PyPI, npm, and Maven.
  • Repository paths, tags, digests, platforms, manifests, layers, and attachments for Container and Helm.
  • Package and version lifecycle actions, a repository trash that keeps deleted content restorable for seven days, repository deletion, and a seven-day recovery window.
  • Browser-backed rvs login with revocable device sessions.
  • Repository discovery, explicit repository selection, temporary package-tool authentication, package lifecycle management, and local runtime management.
  • rvs wrappers for pip, uv, Twine, npm, Maven, Docker, Helm, and ORAS.
  • Native configuration guidance for compatible tools such as Gradle and sbt.

Private mirrors and supply-chain protection

Section titled “Private mirrors and supply-chain protection”
  • Private mirrors for PyPI, npmjs.org, Maven Central, and supported custom sources.
  • Package Protection provides asynchronous security assessment for PyPI, npm, and Maven package versions.
  • Minimum package age to reduce exposure to brand-new compromised releases.
  • Direct private-mirror targets or mirrors connected to private repositories.
  • Package resolution rules that choose which upstreams can supply specific PyPI, npm, and Maven packages, with optional Version-level resolution.
  • Mirrored-package inspection, refresh, removal, findings, and usage visibility.
  • Ravenstash-managed North America and European Union storage, subject to plan availability.
  • Eligible organizations can connect Cloudflare R2 or OVH Object Storage.
  • Authenticated delivery through more than 300 locations for package clients, CI, browser downloads, containers, and Helm charts.
  • Personal and organization automation tokens for CI and releases.
  • Namespace-restricted organization automation tokens managed by namespace or organization administrators.
  • Usage views for members, storage, artifact reads, and informational package delivery bandwidth.
  • Online checkout and paid-plan management in the Ravenstash dashboard.