Host a company registry
A Pentool registry is static data. It does not require a special server: S3-compatible storage, a CDN, an internal web server, or a synchronized folder can all work.
Recommended layout
registry/
index.json
packages/open-design/ui/0.1.0/open-ui-0.1.0.penpkg
packages/open-design/ui/0.1.0/open-ui-0.1.0.penpkg.sig.json
keys/publisher.pub
Operational rules
- Treat package versions as immutable.
- Enable object versioning and keep registry index history.
- Put write credentials only in CI; consumers need read-only access.
- Require signature and hash verification before installation.
- Mirror critical packages for offline and disaster-recovery use.
Consumer workflow
pentool registry search https://design.example.com/registry open-design
pentool package install open-design/ui@0.1.0 \
--registry https://design.example.com/registry
pentool lock verify
pentool lock sync --offline
The generated pentool.lock gives each project a reproducible dependency graph. Commit it with the design project.