Spergs, LLC

← All products

LibWorld

In progress

Mirror, cache, and preserve your software supply chain.

About LibWorld

LibWorld stands in front of the package ecosystems your builds depend on — apt, pip, npm, git, cargo, go, maven, rubygems, nuget, cocoapods and the Docker Registry API — proxies them, caches every artifact it fetches, and serves it from inside your network. A deleted package, an upstream outage, or a flaky mirror no longer breaks the build you need today or the one you need to reproduce in five years.

Pin versions, freeze mirrors, prefetch whole pin sets before going offline, and garbage-collect by retention policy while protecting what you have pinned. Pull-audit logs record who pulled what and when; optional write-once stores and snapshots preserve a known-good supply chain you can replay later.

It is a small set of C++ services built from vendored dependencies with no system-package requirements: a Boost.Beast proxy/mirror with per-ecosystem backends, a Postgres catalog of everything mirrored, S3-compatible blob storage, a self-hosted git forge, and a build service that builds your projects against the mirrors so every dependency they pull gets catalogued as a side effect. Self-hostable, MIT-licensed, host-native Ansible + systemd deploy, no Docker.

At a glance

  • Drop-in proxy + cache for eleven package ecosystems
  • Deterministic, reproducible, offline-capable builds
  • Prefetch to warm the cache before you go air-gapped
  • Retention/TTL + garbage collection, pull-audit logs
  • Snapshots, write-once stores, integrity verification
  • Self-hosted C++ services, MIT-licensed

More from Spergs

Other independent software we ship, or are working on.