Dependably Packages · Cargo

A private Cargo registry with a sparse index

A sparse registry that stable Cargo speaks natively. crates.io crates come through a pull-through cache that verifies every checksum; your own crates publish with a token; the policy gate decides what reaches a build.

cargo · crates.io

Point Cargo at your registry

One block in config.toml names the registry and holds no secret; cargo login stores the token in its own credential store.

The placeholders are your base URL and a token from the web UI. The guide covers the same steps for a single project, plain HTTP, verifying the change, and reverting it.

toml · repo.example.com
# ~/.cargo/config.toml — holds no secret
[registries.dependably]
index = "sparse+https://repo.example.com/cargo/"

# then: cargo login --registry dependably
[dependencies]
my-internal-crate = { version = "1.0", registry = "dependably" }

What happens to every fetch

The client sees a registry. Behind it, Dependably Packages stages each upstream artefact and refuses the ones that fail a check you configured.

  • The checksum is verified against the digest the upstream publishes before the artefact is stored.
  • The version is screened against OSV, and the policy gate can refuse on licence, severity, CISA KEV, EPSS, install scripts, or release age.
  • A name your organization reserves cannot be squatted upstream and resolved into your builds.
  • Every refusal is written to the audit log with the arm that refused it, so a 403 in CI is explained in the web UI.

Verify, publish, revert

The Cargo guide continues with a verification step, publishing your own packages, and reverting the configuration if you need to.