Skip to content

Manage a private mirror

A Ravenstash private mirror gives one approved PyPI, npm, or Maven source an authenticated home with security scanning and package-age controls.

Use its private URL directly, or connect it to one or more private repositories owned by the same personal account or organization.

Use Package caches in the Ravenstash app or follow the link from a repository’s upstream settings.

The mirror detail shows:

  • Ecosystem and connected package source.
  • Direct authenticated repository URL and access settings.
  • Connected package repositories.
  • Mirrored packages, versions, and files.
  • Storage, downloads, bandwidth, access recency, and latest activity.

You can remove an individual mirrored package or version from the detail page. Removing a stored copy does not block the package at its source; use security and package-age policy to control which dependencies are eligible for builds.

Browser downloads require Ravenstash authorization. For developer and CI installs, use the connected repository or the mirror’s direct rvs target.

You can update a custom package source or replace its authentication details from the mirror settings.

Clearing a mirror removes its stored package content. Deleting a mirror also removes its configuration. Disconnect private repositories before deleting a mirror that they still use.