Security and trust
Security you can explain to developers and buyers.
Ravenstash protects package publishing, installs, storage, and dashboard actions with clear access controls built for individual developers and organizations.
Access and identity
Practical controls for private package teams
- Developers can sign in with email and password, Google, GitHub, or passkeys.
- Repositories support private authenticated access and controlled public package distribution.
- Teams can use organization API tokens for CI instead of tying builds to one developer account.
- Browser package downloads use short-lived access links for the current download action.
- Organizations can keep package data at rest inside the EU for GDPR compliance.
- Package files can remain in S3-compatible storage controlled by the customer.
- Deleting a repository cuts off package access immediately while keeping a short recovery window.
- Repository, package, download, and storage views help teams see how packages are being used.
Packages and policy
Control what reaches developers and CI
- Vulnerability scanning identifies security issues in package dependencies.
- Package policies help teams control which dependencies enter their builds.
- Repository roles and scoped tokens keep access aligned with each team and workflow.
- Plan limits and usage controls keep storage and delivery predictable.
- Minimum package age can delay brand-new upstream releases before they reach builds.
- Custom caches keep public and authenticated external sources behind one controlled path.
