Skip to content

Artifacts & lifecycle

Artifact upload, metadata, SBOM links, cooldown gates, cleanup, and import workflows.

Artifacts can be uploaded and downloaded through the UI and programmatically. Manual deletion is available in the UI; OCI also supports programmatic deletion.

Craftifact captures artifact metadata, links CycloneDX SBOMs to package artifacts and OCI content, and can generate SBOMs for supported package formats when none is provided.

Lifecycle controls include cooldown gates for new packages, Fast-track decisions for trusted releases, rule-based cleanup from Pro, and imports from external repositories such as Sonatype Nexus.

Lifecycle gates

  • Hold newly seen packages until cooldown and analysis requirements pass
  • Fast-track trusted releases and keep an auditable decision trail