Repkg
RepKG – because your dependencies shouldn’t be a liability.
| Principle | What it means | |-----------|----------------| | | Packages are retrieved by hash(contents) → no more mutated tarballs. | | Offline‑first | A full RepKG mirror can be air‑gapped and still serve any package ever seen. | | Verifiable by default | Every repkg pull checks inclusion proofs, signature chains, and timestamps. | | Registry agnostic | Same CLI for npm, PyPI, Cargo — your CI doesn’t change, only your resolver. | RepKG – because your dependencies shouldn’t be a
We are tired of fixing builds because a package vanished, or chasing CVEs that could have been caught at install time. RepKG is the tool we wished existed five years ago. | | Verifiable by default | Every repkg
He had unpacked them only four months ago. He remembered the optimism he felt when he hung the coat in the closet, thinking, This is it. I’m staying. But life, fickle and restless, had other plans. The job evaporated. The lease broke. The relationship dissolved. And now, the items had to be repackaged. RepKG is the tool we wished existed five years ago