Supported features and formats
Ravenstash is a hosted private artifact repository for PyPI, npm, Maven, Container, and Helm OCI workflows.
Repositories and content
Section titled “Repositories and content”- Private, authenticated publishing and retrieval for every supported registry.
- Any supported non-empty combination of PyPI, npm, Maven, and OCI in one repository.
- Personal and organization ownership with namespace membership, invitations into namespaces, member suspension and seat limits, organization and namespace Teams, namespace administrators, Reader, Publisher, Maintainer, and Admin repository roles plus custom roles, additive grants, per-namespace base permissions, and explainable effective access.
- Package and version views for PyPI, npm, and Maven.
- Repository paths, tags, digests, platforms, manifests, layers, and attachments for Container and Helm.
- Package and version lifecycle actions, a repository trash that keeps deleted content restorable for seven days, repository deletion, and a seven-day recovery window.
Developer experience
Section titled “Developer experience”- Browser-backed
rvslogin with revocable device sessions. - Repository discovery, explicit repository selection, temporary package-tool authentication, package lifecycle management, and local runtime management.
rvswrappers for pip, uv, Twine, npm, Maven, Docker, Helm, and ORAS.- Native configuration guidance for compatible tools such as Gradle and sbt.
Private mirrors and supply-chain protection
Section titled “Private mirrors and supply-chain protection”- Private mirrors for PyPI, npmjs.org, Maven Central, and supported custom sources.
- Package Protection provides asynchronous security assessment for PyPI, npm, and Maven package versions.
- Minimum package age to reduce exposure to brand-new compromised releases.
- Direct private-mirror targets or mirrors connected to private repositories.
- Package resolution rules that choose which upstreams can supply specific PyPI, npm, and Maven packages, with optional Version-level resolution.
- Mirrored-package inspection, refresh, removal, findings, and usage visibility.
Storage and delivery
Section titled “Storage and delivery”- Ravenstash-managed North America and European Union storage, subject to plan availability.
- Eligible organizations can connect Cloudflare R2 or OVH Object Storage.
- Authenticated delivery through more than 300 locations for package clients, CI, browser downloads, containers, and Helm charts.
Plans and access
Section titled “Plans and access”- Personal and organization automation tokens for CI and releases.
- Namespace-restricted organization automation tokens managed by namespace or organization administrators.
- Usage views for members, storage, artifact reads, and informational package delivery bandwidth.
- Online checkout and paid-plan management in the Ravenstash dashboard.

