the software-supply-chain registry
The Artifact Intelligence Layer for Securing Your Pipeline
Identity, provenance, advisories, SBOMs, and a full audit trail attached to every artifact in one product — the work other products sell as separate add-ons. Cloud or self-hosted, for less.
Catch a bad package before it spreads.
@acme-internal application. Gastropod flags it at intake on a
namespace mismatch, along with the 100.100.100 version and can
tell you the four internal applications that pulled and are using it. Microsoft flagged
33 similar packages impersonating internal corporate scopes in May 2026.
See more of the product →Stop rediscovering what you already know.
The same artifact appears in dozens of packages, apps, and dependency chains across one company. Resolving and scanning it from scratch each time burns compute, scanner seats, analyst hours, and AI tokens. Gastropod treats the artifact as the unit of intelligence: it resolves and scans each digest once and reuses the result everywhere that digest reappears.
- Gastropod reuses a prior high-quality result instead of re-running it on the same digest.
- When AI-assisted scanners run against an artifact, the same deduplication cuts duplicate token spend.
- When a new advisory is published, Gastropod already knows every place that artifact exists: one query, not a fleet-wide rescan.
- A policy can force high-criticality artifacts to rescan; everything else reuses the cached result.
The whole supply chain in one tool.
Artifactory requires Xray. Nexus requires Lifecycle. Each added capability becomes another product, another integration, another renewal. Gastropod provides the registry, the intelligence, the SBOMs, the advisories, and the audit spine as one system, and costs less than the stack it replaces.
other products
- Repository manager
- + security / scanner add-on
- + SBOM & policy tier
- + audit / compliance tier
- = several products, several bills
Gastropod
- Registry + intelligence + SBOM
- + advisories + blast-radius + audit
- one self-hostable system
- = one product, one bill
What you get on day one.
Artifact intelligence
Exact PURL identity, where-seen history, and findings attach to each artifact. That knowledge is recorded once instead of re-learned per project.
Vulnerability advisories
OSV advisories correlate to each package version and are shown as flags, including their inherited reach across dependents.
Blast-radius mapping
Direct and transitive dependents flatten into queryable edges. When a finding appears, every affected package and consumer is shown.
SBOM & provenance
A CycloneDX SBOM reconstructs on demand, with every pull verified against the authoritative source for its ecosystem.
Audit spine
Every pull records who did it: what they pulled, from where, and when. That record is available for export in audit and incident response.
Scanner findings ingest
Scanner output from your own tooling, including Trivy, Grype, Snyk, and Anchore (CycloneDX, OpenVEX, native JSON), is accepted and attached back to the artifact record.
Eleven ecosystems and growing.
Gastropod proxies or hosts Go, npm, Debian, OCI, PyPI, Maven, Alpine, RHEL, NuGet, Ruby, Helm, and more behind one URL. Point existing clients at it, and Gastropod fills in identity, provenance, and the audit trail automatically.
Secure by design.
Gastropod isolates each tenant, encrypts data in transit and at rest, and includes OIDC SSO on every plan. Every pull records who did it, and the audit trail exports on demand. The registry runs on a scalable CDN built in-house, so security and performance both hold up under real load. The security page documents each of these controls in detail.
Cloud or self-host; Same capabilities.
Get started in minutes, or deploy it self-hosted on your own hardware. See plans →