Features
Craftifact connects repository operations with SBOM-backed supply-chain visibility, access control, and operated lifecycle workflows.
Feature areas
Key capabilities available today; plan-specific items and roadmap notes are marked on the detail pages.
Repository foundation
The package workflows, identity controls, and lifecycle features that keep artifacts usable and governed day to day.
Repositories & package formats
- Hosted, proxy, and group repositories for common workflows.
- Maven, npm, Python, OCI (Docker), and Gobeta support.
Access & identities
- OIDC SSO or SoluForge IdP with 2FA options.
- RBAC, groups, robot accounts, and scoped tokens.
Artifacts & lifecycle
- Upload, download, metadata, and deletion workflows.
- SBOM links, cooldown gates, cleanup, and import paths.
Supply chain insight
Dedicated views for understanding what is inside artifacts, where components are used, and which risk signals matter.
Dependencies
- Inspect components and transitive dependencies from SBOMs.
- Find where a component is used across repositories.
Vulnerabilities
- Map known vulnerabilities to affected components and artifacts.
- Prioritize with severity, CISA KEV, and EPSS signals.
Secrets
- Trace possible leaked credentials or tokens to the affected artifact.
- Review secret-specific suppressions separately.
Licenses & policy gates
- Review SBOM license signals before they become release risk.
- Manage license policies, cooldown holds, and Fast-track decisions.
Operated control
Operational capabilities that reduce self-hosting burden while keeping instances understandable and manageable.
Storage & custom domains
- External storage configuration for S3-compatible backends.
- Custom public domains for Craftifact instances.
Backups & recovery
- Self-service backups and restores.
- Restore workflows can cover different instances.
Log exports
- Export Craftifact application logs directly from the Control Plane.
- Get the log data you need for analysis, support, and incident response.
Organizations & delegation
- Invite owners or instance admins with scoped access.
- Keep organization members, pending invitations, and instance grants visible.
Provisioning & autonomy
- Create, delete, upgrade, update, back up, and restore instances.
- Administrative UI flows reduce dependency on vendor tickets.
Product principles in operation
Secure defaults over patchwork
Secure baseline settings reduce rework and misconfigurations in day-to-day operations.
Traceable configuration
Changes stay visible and reviewable so teams can validate and reproduce them.
Controlled access
Roles and groups remain clearly assigned, and access stays auditable.
Maintainable operations
Updates and operational tasks are intentionally streamlined so the system stays stable.
Focus on artifacts and supply-chain visibility
Craftifact stays close to repository workflows and avoids side products that blur ownership.
Transparency on changes
We communicate relevant product changes, major updates, and plan-dependent expansions clearly and predictably. For supply-chain or CRA-relevant evaluation, use the CRA readiness page and contact path to align on fit and boundaries.