one identity, every ecosystem
Normalize packages and artifacts into a single PURL-based catalog across Go, npm, Debian, and additional ecosystems as they land.
gastropod.io
gastropod.io is a developer-friendly artifact registry and control plane for Go, npm, Debian, and more. It gives teams a PURL-keyed catalog, pull-through provenance, scanner-ready artifacts, and audit evidence without changing how developers want to work.
The placeholder version: enough to say what matters, not so much that it reads like enterprise wallpaper.
Normalize packages and artifacts into a single PURL-based catalog across Go, npm, Debian, and additional ecosystems as they land.
Publish private packages, cache public ones, or route installs through a controlled endpoint that still feels natural to developers.
Attribute every pull to a principal, repo, token, and consumer so teams can reconstruct exactly where an artifact went.
Pull the exact artifact once, preserve its identity, and present it cleanly to the tools your team already uses.
Checksums, versions, access events, SBOM context, and provenance become part of the normal artifact flow.
API tokens, registry config, role-based access, exportable records, and deployment choices that fit real engineering teams.
Developers keep pulling packages. Security gets the artifact-level trail it has always wanted.
example
# .npmrc registry=https://registry.gastropod.io/npm/acme/platform/ //registry.gastropod.io/:_authToken=$GASTROPOD_TOKEN # then install normally npm install ✓ artifact resolved ✓ digest recorded ✓ pull attributed ✓ evidence retained
| mode | shape | status |
|---|---|---|
| cloud | hosted registry | soon |
| self-hosted | your environment | soon |
| enterprise | dedicated setup | talk |
Free for early builders, business plans for growing teams, and dedicated enterprise options when procurement gets involved.
Public packages, small private usage, enough storage to kick the tires, and a clean path to production.
Private repositories, more seats, role-based access, audit logs, and priority support for engineering teams.
Dedicated deployment choices, compliance support, procurement paperwork, and help getting the control plane in place.