Dependably Packages · PyPI

A private PyPI index for pip and uv

One index URL for pip and uv. PyPI packages come through a pull-through cache that verifies every checksum; your own packages publish with twine or uv; the policy gate decides what reaches a build.

pip · uv

Point PyPI at your registry

pip writes the index URL into its own config; uv reads the credentials straight from the URL.

The placeholders are your base URL and a token from the web UI. The guide covers the same steps for a single project, plain HTTP, verifying the change, and reverting it.

bash · repo.example.com
pip config set --user global.index-url https://user:<your token>@repo.example.com/simple/
# uv reads the credentials straight from the URL
uv add --default-index https://user:<your token>@repo.example.com/simple/ requests

What happens to every fetch

The client sees a registry. Behind it, Dependably Packages stages each upstream artefact and refuses the ones that fail a check you configured.

  • The checksum is verified against the digest the upstream publishes before the artefact is stored.
  • The version is screened against OSV, and the policy gate can refuse on licence, severity, CISA KEV, EPSS, install scripts, or release age.
  • A name your organization reserves cannot be squatted upstream and resolved into your builds.
  • Every refusal is written to the audit log with the arm that refused it, so a 403 in CI is explained in the web UI.

Verify, publish, revert

The PyPI guide continues with a verification step, publishing your own packages, and reverting the configuration if you need to.