MirriX: a verifiable multi-ecosystem dependency gateway for secure builds
MirriX sits between native package managers and upstream registries, fetching, verifying, and caching artifacts from npm, PyPI, Go, Maven, Debian, and Alpine. It supports connected, promotion, and fully disconnected modes, letting teams enforce policy, trace provenance, and operate in air‑gapped environments. Built in Go with a web UI and S3‑compatible storage, it works for any CI/CD pipeline needing reliable, signed dependencies. Compared to generic caches, MirriX adds cryptographic verification and controlled promotion, making builds repeatable and auditable.
View on GitHub →naqvi-labs/mirrix