DepAegis review
A focused registry for teams that need dependency security and provenance controls.
Reviewed by iTechGuides Editors · Editorial team · Updated Oct 2026
DepAegis is a private package registry for engineering teams managing software dependencies and artifact supply-chain controls. It supports npm, NuGet, Maven, PyPI, Docker/OCI, Go Modules, and Helm packages, with publishing through a command-line tool. The service combines registry management with vulnerability scanning using OSV.dev and NVD, SBOM generation, Sigstore signing, SLSA provenance, secrets detection, license compliance, and typosquatting analysis. Its fit is strongest for organizations that want security checks and provenance workflows alongside package storage.
The plan structure gives teams a free starting point, then adds broader format support and governance features. Community is free forever and includes npm and NuGet registries, vulnerability scanning, and community support. Starter costs €39 per organization per month and adds seven registry formats, SBOM generation, a dependency firewall with policy engine, and email support. Pro is €149 per organization per month, adding AI-powered vulnerability scanning, SLSA provenance, Sigstore signing, SSO, custom roles, and priority support. Business costs €449 per organization per month and adds SAML SSO, SCIM provisioning, CRA, DORA, and NIS2 compliance reports, a 99.9% SLA, and additional artifact formats.
Security and delivery workflows are the product’s clearest focus. The dependency firewall supports OPA Rego integration, while CI/CD connections cover GitHub Actions, GitLab CI, and Jenkins. Enterprise adds unlimited users and packages, unlimited storage and bandwidth, air-gapped deployment, on-premise or private-cloud options, and dedicated support. Teams seeking a registry centered on dependency analysis, signing, compliance, and provenance should find the tier progression relevant. Organizations prioritizing a broader platform ecosystem or a narrow package-hosting service may prefer an alternative.
DepAegis pros and cons
- Where it wins
- SBOMs, vulnerability scanning, signing, and SLSA provenance
- Dependency firewall with OPA Rego policy integration
- CI/CD integrations for GitHub Actions, GitLab CI, and Jenkins
- Where it doesn't
- Community supports only npm and NuGet registries
- The web platform is the listed platform option
- Air-gapped, on-premise, and private-cloud deployment requires Enterprise
DepAegis fact sheet, pricing and score →
Advertiser disclosure: iTechGuides is reader-supported. We may earn a commission when you click some links. How we rank.
Last updated · How we research and update
