Public registries, privately mirrored
Use PyPI, npmjs.org, and Maven Central through an authenticated Ravenstash mirror.
Use PyPI, npmjs.org, Maven Central, or your own package source through an authenticated mirror with security scanning and minimum package age.
rvs art mirror select pypiorg
rvs pip install torchGive developers and CI one authenticated mirror with scanning and release-age controls, without paying for and maintaining separate security systems.
Choose PyPI, npmjs.org, Maven Central, or another package source your team trusts.
Put the source behind a private, authenticated Ravenstash mirror.
Set a minimum package age to hold back releases during their riskiest first hours.
Builds use dependencies that meet your security and release-age rules.
Use PyPI, npmjs.org, and Maven Central through an authenticated Ravenstash mirror.
Screen mirrored dependencies for malware and known security risks before they become trusted build inputs.
Delay brand-new releases so attacks have less chance to move from publication into CI within minutes.
Use the mirror directly or connect it to a matching private PyPI, npm, or Maven repository.
Replace separate mirror and security systems with one managed service and one familiar workflow.
Review mirrored packages, connected repositories, downloads, storage, findings, and recent activity.
Protect the public dependencies your team relies on while keeping costs predictable and workflows familiar through rvs.
Yes. A private mirror can connect to a public or private HTTPS package repository, including sources that require authentication.
Yes. Every mirror has its own private package URL and can also supply dependencies to one or more private repositories.
Many dependency attacks rely on a compromised release being adopted immediately. A minimum package age creates time for malicious releases to be reported, removed, or flagged before they enter your builds.