
RepoFlow
Simple, scalable package management for private and public repositories.
RepoFlow is a self-hosted package management platform designed to manage private and public repositories in the cloud or on your own servers. It supports multiple package types, enforces upload rules, and emphasizes security and scalability for teams.
Key Features
- Vulnerabilities Scanning: on-demand CVE scanning to assess security risks
- Smart package search: fast discovery across descriptions and READMEs
- Supports major package types: Docker, NPM, PyPI, Maven, NuGet, Helm, RPM, Gems, Go, Cargo, Composer, Debian, Universal
- Keep Your Repositories Clean: strict upload-validation to reject non-packages
- Self hosted: deploy on your own servers for security/compliance
- Built for scale: designed to handle large catalogs with reliable performance
- SSO + LDAP Support: integrated authentication and user management
- Upload Restriction Rules: granular controls on what can be uploaded
- No more Registry indexing: instant package access without slow indexing
Use Cases
- Enterprise artifact hosting: centralize private/public packages with secure access and policy enforcement
- CI/CD integration: support for multiple package types within self-hosted pipelines with governance
- Regulated environments: on-prem deployments with access controls, CVE scanning, and compliance rules
Conclusion
RepoFlow provides a self-hosted, scalable solution for managing software artifacts across multiple ecosystems, combining security, fast search, and flexible deployment to fit enterprise policies.
Categories:
Tags:
Similar Services

Gitea
Self-hosted Git hosting with code review, issues, and CI/CD
Gitea is a lightweight, self-hosted Git service with repositories, pull requests, issues, wiki, packages, and built-in CI/CD via Actions and runners.

Harbor
Trusted cloud native registry for storing, signing, and scanning artifacts
Harbor is an enterprise-grade cloud native registry for container images and artifacts with RBAC, vulnerability scanning, signing, replication, and audit logging.

VERT
On-device file converter running in WebAssembly.
WebAssembly-powered on-device file converter built with Svelte and TypeScript, enabling offline, privacy-first conversions.

Unregistry
Push Docker images to remote hosts over SSH without a registry
Unregistry is a lightweight OCI image registry plus Docker CLI plugin that pushes images directly to remote Docker hosts over SSH, transferring only missing layers.

Zot
OCI-native container and artifact registry (OCI Distribution compliant)
Open-source, production-ready OCI-native container image and artifact registry with single-binary deployment, S3/local storage, web UI and CLI.

F-Droid
FOSS Android app repository with a client for browsing and updates
F-Droid is a free and open source Android app repository and client for browsing, installing, and updating FOSS apps, with tooling to run and publish your own repo.