Hort is a secure, self-hostable, multi-format artifact repository and supply-chain registry — one server that proxies, stores, scans, and governs packages across your package ecosystems, so you don't have to trust an upstream registry with your build pipeline's integrity.

If you're evaluating it alongside Artifactory, Nexus, or Harbor, here's what's structurally different, not just configurable:

The name captures the first four of these as a mnemonic:

HORT = Hashed · Origin · Repository · Trail

Quickstart: self-contained install Browse the docs View on GitHub

Supported formats

EcosystemClient
OCI / Dockerdocker, skopeo, cosign
npmnpm, yarn, pnpm
PyPIpip, uv
Cargocargo
Maven / Gradlemvn, gradle

Roadmap (not yet shipped): additional ecosystems (Helm, RPM/YUM, Debian/APT, …), and loading format handlers as sandboxed, deploy-time WASM modules rather than today's compiled-in per-format adapters. See docs/architecture/ for the design.