~/tools/verdaccio
Verdaccio
tool

Verdaccio

Verdaccio is an open source private npm registry and proxy you can self-host — a JFrog Artifactory and GitHub Packages alternative that hosts your private packages and caches the public npm registry, with zero config and no database to run.

What is Verdaccio?

Verdaccio is a lightweight, open source private npm registry that runs as a Node.js application. It hosts your organization’s private packages and, at the same time, proxies and caches the public npm registry — so your team installs both private and public dependencies from a single endpoint you control. It needs no database and works with zero configuration out of the box.

What is Verdaccio best for?

Small to mid-sized teams that want a private place to publish internal packages, faster and more reliable installs through a local cache, or a way to override public packages during development. It’s ideal when you want full control on your own infrastructure without paying for a hosted artifact service, and it’s a common choice for monorepos and end-to-end testing where you need a throwaway registry that starts in seconds.

What can Verdaccio do?

  • Host private npm packages inside your network without publishing them publicly
  • Proxy and cache packages from npmjs.org, giving faster installs and failover if the upstream registry is down
  • Chain multiple upstream registries and fetch everything through one endpoint
  • Override public packages by publishing patched versions under their original names
  • Work with npm (7–11), Yarn Classic and Modern (1–4), and pnpm (9–11)
  • Manage users, tokens, and package-level access with pluggable authentication
  • Swap the default file storage for community plugins like Amazon S3 or Google Cloud Storage
  • Deploy via the official Docker image or a Helm chart on Kubernetes

Where does Verdaccio fall short?

  • It’s npm-only. Unlike JFrog Artifactory, which handles 20+ package formats (Maven, PyPI, Docker, NuGet and more), Verdaccio serves JavaScript packages and nothing else.
  • It’s built for small-to-mid-scale use. Teams report that scaling past ~50 developers or running true high availability takes extra work, and it lacks the enterprise analytics and governance an incumbent like Artifactory ships with.
  • The bundled storage is a simple local filesystem database; durable or shared storage means adding an S3/GCS plugin, and it doesn’t support running under PM2 cluster mode.

Is Verdaccio free?

Yes — Verdaccio is completely free and open source under the MIT license. There is no paid tier, no enterprise edition, and no per-seat or per-node licensing. Your only cost is the server or container you run it on. This is the main contrast with hosted alternatives, which meter storage, bandwidth, or users.

What does Verdaccio replace?

Verdaccio is a self-hosted alternative to hosted artifact and package services like JFrog Artifactory, GitHub Packages, and Azure Artifacts. For teams whose needs are npm-centric, it covers the private-registry-and-proxy job those products do, without their subscription or usage-based billing.

FAQ

Is Verdaccio open source? Yes. The code is released under the permissive MIT license (documentation and logos are Creative Commons 4.0), so you can use, modify, and self-host it freely.

Can I self-host Verdaccio for free? Yes — self-hosting is the intended use and there is no paid version. You only pay for the machine or container it runs on.

Is Verdaccio a good JFrog Artifactory alternative? For JavaScript-only teams, yes — it delivers a private npm registry and cache for free. If you need many package formats, enterprise HA, or built-in governance and analytics, Artifactory does more.

What do I need to run Verdaccio? A recent Node.js runtime (v24+ for the current release) or the official Docker image, plus modest disk and memory. No separate database is required to get started.