A computational biology paper lists repkg://alpine/3.18/... as a dependency. Reviewers can run repkg verify --receipt paper.receipt and get bit‑for‑bit identical containers and packages, even if the original registries are gone.
RepKG (Replicated Package Knowledge Graph) is a distributed cache + verifiable archive that:
# Install repkg curl -sSL https://repkg.io/install.sh | sh
When event-stream was compromised, most users were already infected. With RepKG:
RepKG does replace upstream registry security — it augments it.
We are 100% open source (Apache 2.0). Contributions welcome: github.com/repkg/repkg