Security and trust
Security you can explain to developers and buyers.
Ravenstash protects package publishing, installs, storage, and dashboard actions with clear access controls built for individual developers and organizations.
Account access
Practical controls for private package teams
- Choose a Ravenstash password, Google, GitHub, or a passkey for account sign-in.
- Add a passkey or authenticator app for an extra check after password sign-in, and optionally after Google or GitHub.
- Keep one-time recovery codes offline for a lost device or unavailable authenticator.
- Important account changes ask for a fresh confirmation with a method already connected to the account.
- Private repositories require approved access for publishing, installs, and browser downloads.
- Teams can use organization automation tokens for CI instead of tying builds to one developer account.
- Browser package downloads use short-lived access links for the current download action.
- Organizations can keep package data at rest inside the EU for GDPR compliance.
- Package files can remain in Cloudflare R2 or OVH Object Storage controlled by the customer.
- Deleting a repository cuts off package access immediately while keeping a short recovery window.
- Repository, package, download, and storage views help teams see how packages are being used.
Packages and policy
Control what reaches developers and CI
- Private packages and mirrored dependencies are scanned for malware and known security risks before they enter trusted build workflows.
- Security findings make risky dependencies visible and help prevent known malicious packages from reaching developers and CI.
- Organization access and separate automation tokens keep human and build-system access independent.
- Storage and download views help teams understand package usage.
- Minimum package age can delay brand-new upstream releases during the riskiest hours after publication.
- Private mirrors keep public and authenticated external sources behind one protected path.
