Nothing reaches your servers unverified
RepoD secures your software supply chain end to end. Built-in CVE scanning, antivirus validation, CISO approval workflow and NIS2 compliance — for every DEB, RPM, APK, Maven, npm and PyPI package, before it reaches production.
From upload
to production
Every package passes through a 6-step automated pipeline before it reaches your repository. Your security team only intervenes at the CISO review step — everything else runs on its own.
Each detected CVE is enriched in real time with EPSS exploit probability, CISA KEV status and NVD severity, so your team prioritizes real threats — not noise.
Every action — upload, scan result, approval, rejection — feeds an immutable audit trail built for NIS2 Article 21, ISO 27001 and SBOM export.
Three gaps in your
Linux security
You have vulnerability scanners, repository managers and patch tools — but no single platform that validates packages before they reach your servers.
Vulnerability scanners detect, but don't protect the supply
Qualys and Tenable detect vulnerabilities on your servers. But they can't control what packages get installed in the first place. If a compromised or unvetted package reaches production, scanning happens too late — the supply chain was already breached.
RepoD scans every package for CVEs, malware and known exploits before it enters your repository — not after it's installed.
Repository managers store packages, but don't secure them
Nexus and Artifactory store packages, but they don't scan them for CVEs, don't run antivirus, don't require CISO approval before distribution. Security is always a bolt-on — a separate product, a separate licence, a separate workflow.
RepoD combines hosting, CVE scanning, antivirus, GPG signing and CISO approval in a single pipeline — no add-ons needed.
Patch tools deploy updates, but don't validate the source
Rudder and Ansible push updates to your fleet. But who validated those packages before they were distributed? Who signed them? Who approved the CVE exceptions? Without a validated supply chain, patch management is distributing trust you never verified.
RepoD closes the loop — validate, approve, sign, then distribute. Your fleet only receives packages that passed your security policy.
Build and patch
containers from
verified packages
Point your Dockerfiles at RepoD instead of public repositories. Every apt install, dnf install and apk add inside your builds pulls only packages that passed your 6-step security pipeline.
Patch existing images by rebuilding with updated, scanned packages — no more pulling unverified binaries from the internet at build time. Your CI pushes the package, RepoD validates it, your image build pulls it. Shift-left, closed loop.
Fits into your existing stack
Repod exposes a full REST API. Every pipeline, tool, and platform that can make an HTTP call can integrate with it.
Upload packages on release via the REST API. SARIF results post directly to GitHub Code Scanning.
Publish .deb and .rpm artefacts to Repod from your pipeline with a single curl call.
Use the Repod REST API in a post-build step to push packages and gate on CVE scan results.
Point apt/dnf at your Repod endpoint. All nodes consume only GPG-verified, CVE-cleared packages.
Provision Repod alongside your infrastructure. Bootstrap distributions and upload base packages on first apply.
Configure base images to pull from Repod. Your containers only ever install scanned, approved packages.
Auto-create tickets on critical CVE detections. Bidirectional sync — closing a ticket in GLPI resolves the CVE decision in RepoD.
Push CVE findings as Jira issues with severity labels. Track remediation alongside your existing sprint workflow.
Create incidents and change requests from CVE scan results. Map RepoD severity levels to ServiceNow priority matrix.
Stream the immutable audit trail via webhook or JSON export into your SIEM for unified security monitoring.
Export CVE scan results as SARIF 2.1.0 and upload directly to GitHub Security tab — no extra tooling needed.
Webhook notifications on new critical CVEs let your VM platform (Tenable, Qualys, Wiz) stay in sync with your package inventory.
/api/docs on your Repod instance.
Built for CISOs. Loved by DevOps.
Real-time visibility on your supply chain — CVE posture, pending approvals, audit trail — without opening a terminal or buying a separate dashboard.
Dashboard
Last updated 2 minutes ago
| Package | Version | Distribution | Status | Uploaded |
|---|---|---|---|---|
| nginx | 1.27.3-1 | focal | Approved | 2h ago |
| openssl | 3.0.14-0 | jammy | Pending | 3h ago |
| libssl-dev | 3.0.14-0 | jammy | Scanning | 3h ago |
| curl | 8.7.1-1 | noble | Approved | 5h ago |
| openssh-server | 9.7p1-1 | noble | Rejected | 1d ago |
Why not just use Qualys, Rudder or Nexus?
Because each solves one piece. Repod is the only platform that validates, hosts, deploys and audits Linux packages in a single pipeline — self-hosted or SaaS.
| Feature | Repod You | Qualys VMDR | Rudder | Nexus OSS | Cloudsmith |
|---|---|---|---|---|---|
| CVE scan at package ingestion (repository) | — | — | |||
| CVE scan on deployed fleet (hosts) | — | — | |||
| Antivirus / malware scan | |||||
| EPSS + CISA KEV enrichment | 3 | ||||
| CISO approval workflow | 4 | ||||
| GPG package signing | 5 | ||||
| SBOM export (SPDX / CycloneDX) | 7 | ||||
| DEB + RPM + APK + Maven + npm + PyPI hosting | — | — | |||
| Package upload (API + UI) | — | — | |||
| Mirror upstream repositories | — | — | |||
| Fleet inventory (SSH scan) | — | — | |||
| Remote patch deployment | 8 | — | — | ||
| CIS compliance checks | — | — | |||
| NIS2 compliance mode | 9 | — | — | ||
| Immutable (append-only) audit trail | 10 | 11 | 12 | 13 | |
| Self-hosted / air-gap | 14 | ||||
| SaaS option | |||||
| Open source Community tier |
- 1. Requires a separate paid product (Sonatype Lifecycle / IQ Server) — not included in the free OSS/Community edition.
- 2. Requires a separate paid product (Sonatype Repository Firewall).
- 3. Part of Qualys TruRisk scoring (QDS).
- 4. No named approval step, but quarantine + policy-gated promotion achieves the same outcome.
- 5. Signs repository metadata (Apt/Yum), not individual packages — the same convention Repod itself uses.
- 6. Requires a separate paid product (Sonatype SBOM Manager).
- 7. Auto-generates CycloneDX SBOMs for container images during sync — not for other formats.
- 8. Separate add-on module ("VMDR with Patch Management") — not bundled with every VMDR license by default.
- 9. Marketed as NIS2-aligned via general platform capabilities — no distinct dedicated "mode" or report generator.
- 10. Has audit logs and change tickets — append-only/tamper-evidence not documented.
- 11. Has configuration versioning and activity logs — append-only/tamper-evidence not documented.
- 12. Has a login/permission audit log (Log Viewer) — append-only/tamper-evidence not documented.
- 13. Has queryable audit logs — append-only/tamper-evidence not documented.
- 14. An Offline Scanner Appliance exists for air-gapped networks, but needs periodic "Cloud Sync" to refresh signatures — not a fully disconnected install.
- 15. Sonatype offers a separate paid "Nexus Repository Cloud" product — not part of the free OSS tier being compared here.
"—" means the feature doesn't apply to that product's category (e.g. a vulnerability scanner isn't a package repository). Comparison based on each vendor's own public documentation. Last reviewed July 2026.
Compliance out of the box
RepoD maps directly to NIS2 Article 21 requirements. Every action is logged, every package is traceable, every approval is documented — so your audit is ready when the auditor arrives.
Architecture documented for SecNumCloud qualification reviews. Self-hosted deployment with no foreign cloud dependencies meets sovereignty requirements. Audit trail covers ISO 27001 controls A.12.5 and A.12.6.
Read the full NIS2 compliance matrix
RepoD Community
is here.
RepoD Community natively manages DEB, RPM, APK, Maven, npm and PyPI in a single self-hosted instance, under the AGPL-3.0 license. Clone the repo, spin it up with Docker Compose — no account required, no telemetry.
Community Edition · AGPL-3.0 + commercial · Read the docs →
Simple, transparent pricing
Start free with the open-source Community Edition — DEB, RPM, APK, Maven, npm and PyPI in one instance. Enterprise plans are sized by the number of client machines (nodes) in your inventory and unlock fleet management, SSO and advanced security controls.
- DEB, RPM & APK hosting — in a single instance
- Package upload via REST API & drag-and-drop UI
- Antivirus scan on every upload (blocking)
- GPG auto-signing — Release/repomd/APKINDEX signed automatically
- CVE vulnerability scan — informational, never blocking
- Everything in Community
- Fleet inventory & SSH scanning with CVE analysis
- SBOM export (SPDX & CycloneDX)
- Advanced CVE policy (block / review / warn / allow)
- Everything in Starter
- Maven, PyPI & npm hosting
- OCI container registry
- Automated SLA alerts
- Everything in Business
- SSO / OIDC
- CIS + STIG compliance profiles
- High availability (multi-replica)
| Feature | Community | Starter | Business | Enterprise |
|---|---|---|---|---|
| Repository | ||||
| DEB, RPM & APK hosting | ||||
| Antivirus scan on upload | ||||
| GPG auto-signing | ||||
| Maven, PyPI & npm hosting | — | — | ||
| OCI container registry | — | — | ||
| Content filters (allow/deny) | — | — | ||
| Upstream cache (air-gap) | — | — | ||
| Security | ||||
| CVE scan (informational) | ||||
| Advanced CVE policy (block/review/warn) | — | |||
| SBOM export (SPDX/CycloneDX) | — | |||
| SLA alerts | — | — | ||
| CIS + STIG compliance profiles | — | — | — | |
| Configuration drift detection | — | — | — | |
| NIS2 report (PDF export) | — | — | — | |
| Fleet & access | ||||
| Local RBAC (5 roles) | ||||
| TOTP multi-factor authentication | ||||
| Fleet inventory & SSH scanning | — | |||
| API tokens for CI/CD | — | |||
| LDAP / Active Directory | — | — | — | |
| SSO / OIDC | — | — | — | |
| Per-distribution & per-machine RBAC | — | — | — | |
| Operations | ||||
| Immutable audit trail | ||||
| GitHub Advisory / CISA KEV webhooks | — | |||
| Historical version snapshots | — | |||
| Email notifications (SMTP) | — | |||
| Verified backup & restore | — | — | ||
| Executive (CISO) dashboard | — | — | — | |
| High availability (multi-replica) | — | — | — | |
| GDPR self-service (export/erasure) | — | — | — | |
No commitment · 30-day pilot available on all Enterprise plans
See RepoD in action
Get a personalised 30-minute walkthrough — the security pipeline, fleet inventory, CVE remediation workflow and NIS2 compliance dashboard. Or start free instantly — no credit card, no call.