Ship packages on GitHub
GitHub Releases is a good public distribution layer for a small or medium package catalog. Attach every immutable .penpkg, its signature, and a registry index to a release.
Package and sign
pentool package init ./open-ui --name open-design/ui
pentool package pack ./open-ui --output open-ui-0.1.0.penpkg
pentool package verify open-ui-0.1.0.penpkg
pentool package keygen ./publisher
pentool package sign open-ui-0.1.0.penpkg --key publisher.key
Keep the private key outside Git. Commit the public key so consumers can verify publisher identity.
Publish a release
Create a tag such as packages/open-ui/v0.1.0. Upload the package and signature as release assets. Publish your generated registry index through GitHub Pages or an object-storage CDN.
Scale to many packages
Use one repository for the catalog and immutable release assets for blobs. A CI workflow should validate manifests, verify hashes, reject an existing name/version pair, regenerate the index, then publish. Teams install from a stable registry URL rather than hunting through release pages.