Skip to content

Frequently asked questions

View as Markdown

Short answers, each with a link to the page that has the detail. If a question is missing, contact support.

CloudRepo is a hosted artifact repository. You publish packages to it and download them from it with the tools you already use, and CloudRepo runs the servers. It hosts Maven, Python, npm and Docker repositories.

Maven and Gradle read a Maven repository. pip and twine read and write a Python repository. npm reads and writes an npm repository. docker logs in to, pushes to and pulls from a Docker repository. Each tool’s page shows the file or command that connects it: Maven, Python, npm and Docker.

Create your account, create a repository, then create a repository token for your build tool. The sign-up and first repository guides walk through the first two, and Repository Tokens covers the third for every client.

CloudRepo offers a free trial. Its length and terms are on the pricing page, which is where they are kept current.

See the pricing page. These docs carry no prices, so none of them can go out of date.

A repository holds one format (Maven, Python, npm or Docker) and has a mode. A local repository stores what you publish. A proxy repository fetches from an upstream and keeps a copy. For Maven and Docker only, a group repository is one address in front of several repositories. See Repository Management.

What is the difference between a release and a snapshot?

Section titled “What is the difference between a release and a snapshot?”

In Maven, a version that ends in -SNAPSHOT is a development build that can be published over and over. Any other version is a release, and by default CloudRepo refuses to replace one that exists. See Maven Overwrite Protection.

What happens if I publish the same version twice?

Section titled “What happens if I publish the same version twice?”

In a Maven, Python or npm repository, CloudRepo by default refuses it with 409 Conflict and leaves the file that is already there. This is Overwrite Protection, a setting on each repository. Docker repositories do not offer it: a tag you push again points to the new image. See Maven Overwrite Protection, Python Overwrite Protection and Overwrite Protection.

For Maven, Python and npm, yes: the Public Access card on a repository lets anyone read it without credentials. A Docker repository does not serve anonymous pulls. See Enabling Public Repository Access.

Yes. In a Maven or Python repository that holds your own files, a file you delete is listed in the repository’s Trash, and someone with the Manage Repositories permission can restore it. The Trash tab carries its own notice about how long deleted items stay. See Trash and Recovery. For npm, see Unpublish a package.

A proxy repository fetches a dependency from its upstream, such as Maven Central, the first time someone asks for it and keeps a copy in your organization. See Proxy Repositories.

With a repository token. You create it in the admin portal, choose the repositories it reaches and whether it can publish, and give it to your tool: the username is the email address of the account that created it, and the password is the token. See Repository Tokens.

A user has either read and write access to every repository in your organization, or read only access to all of them. You can also grant a user administrator permissions one area at a time: billing, repositories, software distribution, users and webhooks. See User Management.

How do I give a customer access to download my software?

Section titled “How do I give a customer access to download my software?”

Use Software Distribution: you put customers in subscriber groups, give each group read only access to the repositories you choose, and create access keys for each subscriber. Subscribers can only read the repositories you assign to them. See Software Distribution.

Does CloudRepo scan packages for vulnerabilities?

Section titled “Does CloudRepo scan packages for vulnerabilities?”

No. CloudRepo does not scan the packages you store. Run a scanner such as Snyk, Trivy or Dependabot in your pipeline.

See CloudRepo’s security page, which is where the security practices are published.

The CI/CD overview has a guide for GitHub Actions, GitLab CI/CD, CircleCI, Jenkins and Bitbucket Pipelines. Any other platform that can set an environment variable from a secret can use the same blocks.

Yes. A webhook tells a server outside CloudRepo when a file is uploaded, downloaded or deleted in a Maven, Python or npm repository. See Webhooks, including the note that Docker repositories send no webhook events.

At status.cloudrepo.io.

My build fails with a 401, 403, 404 or 409. What do I check?

Section titled “My build fails with a 401, 403, 404 or 409. What do I check?”

Start with Troubleshooting, which maps each status to its usual cause and its fix. The credential checks are on Repository Tokens.

Email support@cloudrepo.io. Support lists what to include so the first reply can be an answer.

No. CloudRepo is a hosted service that CloudRepo runs for you. It is not software you install.