You can use boolean logic (e.g. AND/OR/NOT) for complex search queries. For more help and examples, see the search documentation.
Search by package name:
my-package (implicit)
name:my-package (explicit)
Search by package filename:
filename:my-package.ext
Search by package tag:
tag:latest
Search by package version:
version:1.0.0
prerelease:true (prereleases)
prerelease:false (no prereleases)
Search by package architecture:
architecture:x86_64
Search by package distribution:
distribution:el
Search by package license:
license:MIT
Search by package format:
format:deb
Search by package status:
status:in_progress
Search by package file checksum:
checksum:5afba
Search by package security status:
severity:critical
Search by package vulnerabilities:
vulnerabilities:>1
vulnerabilities:<1000
Search by # of package downloads:
downloads:>8
downloads:<100
Search by package type:
type:binary
type:source
Search by package size (bytes):
size:>50000
size:<10000
Search by dependency name/version:
dependency:log4j
dependency:log4j=1.0.0
dependency:log4j>1.0.0
Search by uploaded date:
uploaded:>"1 day ago"
uploaded:<"August 14, 2022 EST"
Search by entitlement token (identifier):
entitlement:3lKPVJPosCsY
Search by policy violation:
policy_violated:true
deny_policy_violated:true
license_policy_violated:true
vulnerability_policy_violated:true
Search by repository:
repository:repo-name
Search by last download date:
last_downloaded:<"30 days ago"
last_downloaded:>"August 14, 2022 EST"
Search queries for all Debian-specific (and related) package types
Search by component:
deb_component:unstable
Search queries for all Maven-specific (and related) package types
Search by group ID:
maven_group_id:org.apache
Search queries for all Docker-specific (and related) package types
Search by image digest:
docker_image_digest:sha256:7c5..6d4
(full hashref only)
Search by layer digest:
docker_layer_digest:sha256:4c4..ae4
(full hashref only)
Search queries for all Generic-specific package types
Search by file path:
generic_filepath:path/to/file.txt
Search by directory:
generic_directory:path/to
Field type modifiers (depending on the type, you can influence behaviour)
For all queries, you can use:
~foo for negation
For string queries, you can use:
^foo to anchor to start of term
foo$ to anchor to end of term
foo*bar for fuzzy matching
For number/date or version queries, you can use:
>foo for values greater than
>=foo for values greater / equal
<foo for values less than
<=foo for values less / equal
Need a secure and centralised artifact repository to deliver Alpine,
Cargo,
CocoaPods,
Composer,
Conan,
Conda,
CRAN,
Dart,
Debian,
Docker,
Generic,
Go,
Helm,
Hex,
HuggingFace,
LuaRocks,
Maven,
MCP,
Nix,
npm,
NuGet,
P2,
Python,
RedHat,
Ruby,
Swift,
Terraform,
Vagrant,
VSX,
Raw & More packages?
Cloudsmith is the new standard in Package / Artifact Management and Software Distribution.
With support for all major package formats, you can trust us to manage your software supply chain.
Tool-Specific Instructions
Although we use GPG (and RSA) keys across each repository and package format, client-side tools might have specific instructions that differ (or require manual steps). To add or use the signing key for these tools, please click on the package format specific tabs above.
Public GPG Key
GPG-based keys/signatures are used by:
The public GPG key for the openhd/openhd-2-3-evo-dev is:
-----BEGIN PGP PUBLIC KEY BLOCK-----
mQGNBGPIVqoBDAC8Unk8C1PIS67dJK1u8vzDSFExEW2sSwU59J/4HroCMsKb8DnU
FHIXlcEjZZrivxhbEQGwTijPTULE1fthnkMhAMkd7hz4pVIAZCgX5v+6AYAsaCnq
ZipGNWFSyMpSPOU42azKwi3xLYisQvE60Y7Ib2cyyVI7vmJ2PRqFUhJTLjl0oen6
S61z1DFmjj/UBNbei+xd+w57PoXJVSqLwpKZbFNHQpkoI7GKEQ7ATf/LY1X86HT7
1hpkqwd4AbaBcLdxfAHQkzrWnbTBEmG2YnoyLU+TK3YYbr2QF4uOMdaMKrNVM0TP
tqUJP0UszqGb2Qd+dUqa6skHKJwB2LQ6MC0eAAplZwi9Iw5VX96xyqf2oK6ZDDGT
idAK4FaBNUh+L/jM28vMdYK8kjgUBZ1qQdvbDeRJ8jeLJKo1YQsq5tahy1U6qJLy
S7fcHTGEK7USBLMwYL7/zkkmRmCBWR90yB7Y7vN1Qhz+LSMxOqn+HshKKhWuSvm9
UlC0Gh5bNIAnUbcAEQEAAbRCQ2xvdWRzbWl0aCBQYWNrYWdlIChvcGVuaGQvb3Bl
bmhkLTItMy1kZXYpIDxzdXBwb3J0QGNsb3Vkc21pdGguaW8+iQHOBBMBCAA4FiEE
/NWIivcJQ3xSf8JfYvo8s+F10yAFAmPIVqoCGy8FCwkIBwMFFQoJCAsFFgIDAQAC
HgECF4AACgkQYvo8s+F10yCszAv7BWoak0HR/Sxw8W83v/90y6JXhEs8XFmLFZfp
dIfdIOIutYSjK45chSZqXderpWbCrIKJ7mMm/zjOLo1qwVlf80HWz0a+ZNDrNWTj
c8i9coumk2dpYYzK/xeXcaD3rbEh1XICLrKo1Ar06VvZnhWQuhYXRsKkbbYtx4TI
lWPtR6LFELGIcUBbuyoDuVA1+5jpeoLezN0lNlRVK56otFwINeWQoxkTf8oWoq02
XtvtHghoNYTs0wcW9nBUs4RoCzvNNxY+RLZ9tO/wHqS5EwgmZEvV30nnfo0jgLx3
Zux5JoxQnCXsZ6/iqYmyhjiFhFr+hbYse21//ws3TfOEhG+IPlvU4w83kmAOpzpv
A+ZRcjvqESwHMqG140MRVc81f71jTb+9y1c9ip8OxEM1B/8iM+pUag03i8pDAWNb
2eQYEkjjy2qQdSVBu6eE5Qu4aO2ZTPI44n/InS0lx4P8TU9IHjO/fsFel6OnXANl
S1QB1iqs7qLi0xMCjJNQ21icGFml
=j6wX
-----END PGP PUBLIC KEY BLOCK-----
It has the following long (20 bytes) and short (8 bytes) fingerprints:
FCD5888AF709437C527FC25F62FA3CB3E175D320
62FA3CB3E175D320
You can download the GPG key or fetch it via the command-line:
curl -1sLf 'https://dl.cloudsmith.io/public/openhd/openhd-2-3-evo-dev/gpg.62FA3CB3E175D320.key'
Public RSA Key
RSA-based keys/signatures are used by:
The public RSA key for the openhd/openhd-2-3-evo-dev is:
-----BEGIN PUBLIC KEY-----
MIIBojANBgkqhkiG9w0BAQEFAAOCAY8AMIIBigKCAYEAvkgonVJ1tw2gh21dFiJc
JP2OvHwi3samNDN4iE3STKUUOf41H+8ETydRVLDg3bXbnfQh2zRxqEEXi5Iyfc5h
wHani6YD2Dy/Kwvrp5Vgjlrshu65vD9eN/jXWPHTOdHH+n7GZia+W+lTlKql4TOw
GaktPrVSj5zDuE0cToOiwCQ3bQkGSaEO7qvS3Z7nCeIUCGwo6R4XtntR8MNZt7ta
PVi/enE73rLswf5j/CXMFSwnLMgAInyNEefe2ney5Q2Dnw3DI/7ha0Rl5K00BdCh
cFbMjuSS8ifHVvfvR20UBs0UTsxNc4t3ywUNa1e2TCEp5Ts7sJzRNevAjsDiv6vz
UgWGTg49EEQK1N5mqcTZM+LEfHj+rkMEt2xILuQKslhq4Af05meeedtfCDuZpOZb
qanhQvp6gEzrh3itELSf9opLYB7vNNktF27l9VRQv427c/VNi7f/rJ3WvXC1Nbyv
/piBmzizBIr+cNZ4YM1zWku4NgyuwrjlVk/nsP+nPFuJAgMBAAE=
-----END PUBLIC KEY-----
It has the following long (16 bytes) and short (8 bytes) fingerprints:
63BDB2112BA4D689BDF5DA5D3094E55A
BDF5DA5D3094E55A
You can download the RSA key or fetch it via the command-line:
curl -1sLf 'https://dl.cloudsmith.io/public/openhd/openhd-2-3-evo-dev/rsa.BDF5DA5D3094E55A.key'
Public ECDSA Key
ECDSA-based keys/signatures are used by:
The public ECDSA OpenSSH key for the openhd/openhd-2-3-evo-dev is:
-----BEGIN PUBLIC KEY-----
MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAElGJqkxsamHMNpuLbRLoPYRMeQOF3
bgsmtq520F/Q5V8DfZIBrRccouNAvwqURAgvyv8urbOM2L3TJocJpexKaQ==
-----END PUBLIC KEY-----
It has the following long (16 bytes) and short (8 bytes) fingerprints:
83717DA83C68E337150E0EF787516F4F
150E0EF787516F4F
You can download the ECDSA key or fetch it via the command-line:
curl -1sLf 'https://dl.cloudsmith.io/public/openhd/openhd-2-3-evo-dev/ecdsa.150E0EF787516F4F.key'
Please note however that the NPM client does not require this key to be installed system-wide in order to allow for package verification - NPM tooling will handle keys automatically.
Public Ed25519 Key
Ed25519-based keys/signatures are used by:
The public Ed25519 key for the openhd/openhd-2-3-evo-dev is:
-----BEGIN PUBLIC KEY-----
MCowBQYDK2VwAyEAIDqfNS/8PXKXf3WZyXLnYlpdlTsvCfQYui1sH05JN8Q=
-----END PUBLIC KEY-----
It has the following long (32 bytes) and short (8 bytes) fingerprints:
895193109B5758415BC7C71B1BF9DE508B52A97D64CD9914D178A54A0BDDFDAF
D178A54A0BDDFDAF
You can download the Ed25519 key or fetch it via the command-line:
curl -1sLf 'https://dl.cloudsmith.io/public/openhd/openhd-2-3-evo-dev/ed25519.D178A54A0BDDFDAF.key'
For Nix, add this name:base64 line to trusted-public-keys:
openhd-openhd-2-3-evo-dev-16760:IDqfNS/8PXKXf3WZyXLnYlpdlTsvCfQYui1sH05JN8Q=
Need Help?
If you couldn't find what you needed in our documentation, then you can always chat to a member of our team instead. It's our mission to be your dedicated off-site team for package management, and we mean it. Come and chat with us, anytime.
What's this page? All Cloudsmith repositories and packages are signed using GPG, RSA or ECDSA keys where supported. Signatures and checksums provide reliable mechanisms to ensure that the packages that you download/install are neither corrupt nor modified. GPG is generally preferred, but RSA or ECDSA is used for some package formats (such as Alpine or NPM). Learn more in the signing keys documentation.