Host your own
RPM, APK and DEB repositories.
One platform. On-premise. Sovereign. No cloud dependency. Native validation, GPG signing and distribution for Debian/Ubuntu, RHEL/Alma/Rocky and Alpine — in a single instance you control end to end.
Every package goes through
RepoD is...
A private, self-hosted software repository infrastructure that natively manages RPM, APK and DEB in a single instance — for teams who want full control over their software supply chain.
Three package formats.
One tool that only speaks for one of them.
Debian/Ubuntu, RHEL/Alma/Rocky/Fedora, Alpine — most teams end up with one tool per format, separate access controls, and zero unified view. RepoD brings all three together in a single self-hosted instance.
Three tools, three learning curves
A different tool for DEB, a different tool for RPM, and home-grown scripts for APK — each format comes with its own toolbox, its own conventions, its own credentials. Your teams juggle three systems for a single mission: distributing trusted packages.
No unified audit trail
When an auditor asks "who published this package, when, and after what verification?", the answer depends on the format — and often there is no answer at all. NIS2 Article 21 requires proof, not three separate logs.
Cloud tools don't work in sovereign environments
Most modern package management platforms are built for SaaS — external dependencies, telemetry, mandatory cloud accounts. In air-gapped environments, the public sector, defence or finance, that simply isn't an option.
Security built into every distribution, for every format
Whether it's a .deb, .rpm or .apk, the same 7-step pipeline runs automatically before a package reaches your repository — humans only intervene at the review step.
Fits into your existing stack
Repod exposes a full REST API. Every pipeline, tool, and platform that can make an HTTP call can integrate with it.
Upload packages on release via the REST API. SARIF results post directly to GitHub Code Scanning.
Publish .deb and .rpm artefacts to Repod from your pipeline with a single curl call.
Use the Repod REST API in a post-build step to push packages and gate on CVE scan results.
Point apt/dnf at your Repod endpoint. All nodes consume only GPG-verified, CVE-cleared packages.
Provision Repod alongside your infrastructure. Bootstrap distributions and upload base packages on first apply.
Configure base images to pull from Repod. Your containers only ever install scanned, approved packages.
Stream the immutable audit trail via webhook or JSON export into your SIEM for unified security monitoring.
Export CVE scan results as SARIF 2.1.0 and upload directly to GitHub Security tab — no extra tooling needed.
Webhook notifications on new critical CVEs let your VM platform (Tenable, Qualys, Wiz) stay in sync with your package inventory.
/api/docs on your Repod instance.
Designed for security teams, not just developers
A clean, information-dense UI that gives your CISO real-time visibility without opening a terminal.
Dashboard
Last updated 2 minutes ago
| Package | Version | Distribution | Status | Uploaded |
|---|---|---|---|---|
| nginx | 1.27.3-1 | focal | Approved | 2h ago |
| openssl | 3.0.14-0 | jammy | Pending | 3h ago |
| libssl-dev | 3.0.14-0 | jammy | Scanning | 3h ago |
| curl | 8.7.1-1 | noble | Approved | 5h ago |
| openssh-server | 9.7p1-1 | noble | Rejected | 1d ago |
How RepoD stacks up
The only self-hosted repository manager handling DEB, RPM and APK natively in one instance — with security validation built in, no add-ons, no extra licences.
| Feature | Repod You | Nexus OSS | Artifactory CE | Aptly | Cloudsmith |
|---|---|---|---|---|---|
| APT & RPM repository | |||||
| Native APK (Alpine) repository | |||||
| Web UI | |||||
| Built-in CVE scanning | |||||
| AV malware scan | |||||
| CISO review queue | |||||
| GPG auto-sign | |||||
| Audit trail | |||||
| NIS2 compliance mode | |||||
| RBAC (5 roles) | |||||
| Self-hosted / air-gap | |||||
| Single container | |||||
| Open source (Community) |
Comparison based on publicly available documentation. Last reviewed May 2026.
Compliance out of the box
Repod maps directly to NIS2 Article 21 requirements. Every action is logged, every package is traceable, every approval is documented — so your audit is ready when the auditor arrives.
Architecture documented for SecNumCloud qualification reviews. Self-hosted deployment with no foreign cloud dependencies meets sovereignty requirements.
RepoD Community
is here.
RepoD Community natively manages DEB, RPM and APK in a single self-hosted instance, under the AGPL-3.0 license. Clone the repo, spin it up with Docker Compose — no account required, no telemetry.
Community Edition · AGPL-3.0 + commercial · Read the docs →
Simple, transparent pricing
Start free with the open-source Community Edition — DEB, RPM and APK in one instance. Enterprise plans are sized by the number of client machines (nodes) in your inventory and unlock fleet management, SSO and advanced security controls.
- DEB, RPM and APK hosting — in a single instance
- Package upload via REST API & drag-and-drop UI
- Antivirus scan on every upload (blocking)
- GPG auto-signing — Release/repomd/APKINDEX signed automatically
- CVE vulnerability scan — informational, never blocking
- Email support
- Fleet inventory & SSH scanning with CVE analysis
- Remote package deployment (SSH, dry-run + confirm)
- SBOM export — SPDX & CycloneDX
- Everything in Starter
- LDAP / Active Directory + OIDC SSO + TOTP MFA
- API tokens for CI/CD pipelines
- Advanced CVE policy + SLA alerts
- Everything in Business
- Scheduled mirroring of upstream repositories
- High availability (multi-replica, shared storage)
- Dedicated onboarding & roadmap input
- Everything in Community
- Fleet inventory & SSH scanning with automated CVE analysis
- Remote package deployment over SSH (dry-run + confirm)
- SBOM export — SPDX & CycloneDX
- Automated PostgreSQL + repository backups
- LDAP / Active Directory + OIDC SSO + TOTP MFA
- API tokens for CI/CD pipelines
- Advanced CVE policy (block/review/warn) + SLA alerts
- Email & webhook notifications (Slack/Teams/Mattermost)
- Scheduled mirroring & high-availability (multi-replica)
No commitment · 30-day pilot available on all Enterprise plans
See RepoD Enterprise in action
Get a personalised 30-minute walkthrough with a live RepoD instance. We'll show you the security pipeline, the CISO dashboard, and how to deploy DEB, RPM and APK repositories in your environment.