Now with CRA Compliance Reports

Your private registry.
Supply chain secured.

Publish npm, NuGet, Maven, PyPI, and Docker packages to your own registry — with SLSA provenance, Sigstore signing, vulnerability scanning, and SBOM generation on every push.

npm · NuGet · Maven · PyPIDocker/OCI · Go · Helm
depaegis-cli
$ depaegis publish --sign --sbom --scan
Signing with Sigstore... done
Generating SBOM (CycloneDX)... done
Scanning for vulnerabilities... 0 found
✓ my-lib@1.2.3 published securely
$

How it works

Secure your pipeline in 60 seconds

No complex setup. No config hell. Install, point, publish.

01

Install

One command to install the CLI. Docker, Helm, or bare-metal — your choice.

curl -fsSL https://get.depaegis.com | sh
02

Configure

Point your package manager at your private registry. Works with npm, NuGet, pip, Maven, and more.

npm config set registry https://registry.depaegis.com
03

Publish

Publish with signing, SBOM generation, and vulnerability scanning — all automatic.

depaegis publish --sign --sbom --scan

Built-in security

Not bolted on. Built in.

Every publish is signed, scanned, and attested. Every dependency is checked at the gate.

Supply Chain Security

SLSA provenance, Sigstore signing, SBOM generation, and VEX/VDR compliance reports built into every publish.

Vulnerability Scanning

Real-time OSV.dev + NVD scanning. Secrets detection, license compliance, and typosquatting analysis on every package.

Universal Registry

npm, NuGet, Maven, PyPI, Docker/OCI, Go Modules, Helm — one registry for all your packages and containers.

Dependency Firewall

8 built-in policy types with OPA Rego integration. Block vulnerable packages before they enter your codebase.

CRA Compliance Reports

EU Cyber Resilience Act compliance reports with SBOM attestations, vulnerability summaries, and audit trails.

CI/CD Native

GitHub Actions, GitLab CI, Jenkins integrations. CLI tool for publish, scan, and SBOM generation in your pipeline.

Pricing

Simple, transparent pricing

Start free, scale as you grow. No hidden fees. All prices in EUR.

Community

Freeforever
  • Up to 3 users
  • Up to 5 feeds
  • Up to 50 packages
  • 1 GB storage
  • npm & NuGet registries
  • Vulnerability scanning (OSV.dev)
  • Community support
Get Started

Starter

€39/org/month
  • Up to 10 users
  • Up to 500 packages
  • 25 GB storage
  • 7 registry formats
  • SBOM generation
  • Dependency firewall & policy engine
  • Email support
Start Free Trial

Business

€449/org/month
  • Up to 100 users
  • Up to 25,000 packages
  • 500 GB storage
  • SAML SSO & SCIM provisioning
  • CRA/DORA/NIS2 compliance reports
  • SLA 99.9%
  • All formats incl. Cargo, RubyGems
Start Free Trial

Enterprise

Custom
Unlimited users & packagesUnlimited storage & bandwidthAll formats incl. Cargo, RubyGems, HelmAir-gapped deploymentDuende IdentityServer (OIDC/SAML)FIDO2/WebAuthnCustom SLA & dedicated supportOn-premise or private cloud
Contact Sales

Compare

DepAegis vs the alternatives

See why teams switch from ByteSafe and Artifactory.

FeatureDepAegisByteSafeArtifactory
Package Formatsnpm, NuGet, Maven, PyPI, Docker/OCI, Go, Helmnpm, NuGet, Maven, PyPIAll major
SLSA Provenance✅ Built-in
Sigstore Signing✅ Keyless
SBOM Generation✅ CycloneDX + SPDX✅ Basic⚠️ Plugin
CRA Compliance✅ Built-in
Dependency Firewall✅ OPA + 8 policies✅ Basic⚠️ Xray add-on
License Compliance✅ AI-assisted⚠️ Xray add-on
Secrets Detection✅ 10+ patterns
FIDO2/WebAuthn✅ Enterprise⚠️ SAML only
Starting PriceFree€49/mo€98/mo

Get in touch

Questions about enterprise plans, compliance, or deployment? We'd love to help.

Contact Sales

Ready to secure your supply chain?

Start with our free Community plan. No credit card required. Publish your first secure package in under a minute.