Verdaccio: a private npm registry and proxy that runs without a database
A lightweight Node.js private proxy registry
At a glance
- What is it?
- Verdaccio is a Node.js private registry that also proxies and caches npmjs.org. It starts with zero configuration and a local file-based store, which is why it is easy to adopt and worth understanding before you put it in front of a team.
- Who is it for?
- Adopt Verdaccio when you need a private registry, an npmjs.org cache or a single endpoint in front of several registries, and when a file-backed store plus community plugins is acceptable. Do not adopt it if you need a built-in database, an enterprise support contract or a paid security response: the README states there is no funding for contributions or security research.
- Can I use it commercially?
- Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
- Is it still maintained?
- Yes. The repository last received commits 1 day ago.
- What is it written in?
- Mainly TypeScript, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 30, 2026, and from our analysis. They are not legal advice.
Editorial analysis
What Verdaccio is for, and who ends up running it
The README describes Verdaccio as a simple, zero-config-required local private npm registry. It exists so a company can use the npm package system internally without sending all code to the public registry, and so private packages install as easily as public ones. The same server can sit in front of npmjs.org and cache downloaded modules along the way, which the README frames as latency reduction and limited failover: if npmjs.org is unreachable, previously cached packages may still be installable.
The project also covers two cases that are easy to miss. An uplinks configuration lets one endpoint chain several registries, so a project that depends on packages from more than one source fetches them from a single URL. And because Verdaccio can proxy a public registry, it can serve a modified version of a third-party package to your own consumers instead of the published one.
The audience is therefore not only platform teams. A single developer who wants to test publishing without touching the public registry, an air-gapped build environment, and a monorepo that needs internal packages all fit the same tool. The README does not describe a hosted or managed offering, so the operational work of running the server stays with whoever installs it.
Storage, uplinks and plugins: the mechanism behind the zero-config claim
Verdaccio ships with its own tiny database, which is what makes the zero-configuration start possible. There is no external service to provision before the first publish. For storage beyond the default, the README states that Verdaccio supports various community-made plugins that hook into services such as Amazon S3 or Google Cloud Storage, and that you can write your own.
The proxy behaviour is the second half of the mechanism. When a package is requested and is not in the local store, Verdaccio fetches it from an upstream registry and caches it, so the next request for that package and version is served locally. The README describes the benefit as presumably connecting to a slow npmjs.org only once per package and version, and as limited failover rather than high availability. That distinction matters: a cache is not a mirror of everything, and it only helps for what has already been requested.
Uplinks chain registries, which is how one Verdaccio instance becomes the single endpoint for several sources. The repository layout shows the server is a TypeScript monorepo under packages/, with a Vite library config, Cypress and Vitest configuration, and a docker-examples directory. None of that changes how the server behaves at runtime, but it does mean the project is built and released as a workspace rather than a single package.
Installing Verdaccio and publishing your first private package
The README lists four installation routes. The npm, Yarn and pnpm commands all target the next-9 tag, which the README says requires Node.js v24 or higher. The master branch carries the same requirement, while version 6 requires Node.js 22 or higher and is maintained in the 6.x branch. Pick the branch first, because the Node.js floor follows it.
npm install -g verdaccio@next-9After the global install, the verdaccio binary starts the server with the bundled default configuration. The Dockerfile sets VERDACCIO_PORT to 4873 and exposes it, so that is the port to expect when you run the container rather than the CLI.
docker pull verdaccio/verdaccio:nightly-masterThe Docker image runs the server with a config file at /verdaccio/conf/config.yaml and keeps its data in a volume mounted at /verdaccio/storage. The repository's docker-compose.yaml wires the same pieces and passes VERDACCIO_PORT through from the environment, so the host port and the container port stay in sync.
services:
verdaccio:
build: .
container_name: verdaccio
environment:
- VERDACCIO_PORT
ports:
- $VERDACCIO_PORT:$VERDACCIO_PORT
volumes:
- verdaccio-storage:/verdaccio/storageFor Kubernetes, the README points at the official Helm chart. The commands below add the chart repository, refresh it and install the chart under its default name.
helm repo add verdaccio https://charts.verdaccio.org
helm repo update
helm install verdaccio/verdaccioA first real use is publishing something internal. With the server running, point npm at it, log in, and publish a package. The login command prompts for credentials and writes a token to your npm configuration; the publish command uploads the package to the registry you just pointed at. The README does not print a full publish walkthrough, so treat the exact prompts as something you will see rather than something documented here. The important part is that after publishing, a colleague who installs from the same registry URL gets your package without any access to the public registry.
Where Verdaccio is the wrong tool
The README is direct about the project's resourcing: Verdaccio is run by volunteers, nobody works on it full-time, and there is currently no funding available for contributions or security research. That sentence should shape how you classify the tool. A private registry that every build depends on is production infrastructure, and a volunteer-run project with no funded security research is a different risk profile from a commercially supported artifact repository.
The second limitation is the storage model. The default tiny database is what makes the first run trivial, but the README's answer to larger storage needs is community plugins for S3, Google Cloud Storage or your own implementation. If you need a registry backed by a database you already operate, with replication and failover handled for you, Verdaccio's default is not that, and the plugin route means you own the plugin's behaviour.
The third is the failover claim itself. The README describes caching npmjs.org as providing limited failover, and limited is the operative word. A package that was never requested through Verdaccio is not in the cache, so an npmjs.org outage can still break a fresh install. Teams that read the proxy feature as a full mirror will be disappointed at the worst moment.
Finally, the version split is a real operational constraint. The master branch requires Node.js 24 or higher, version 6 requires Node.js 22 or higher, and the README notes that contributing guidelines might differ by branch. If your build images are pinned to an older Node.js line, the current branch is not available to you until you upgrade.
How Verdaccio differs from a hosted artifact repository
The obvious alternative is a hosted artifact repository such as JFrog Artifactory or Sonatype Nexus, or a managed registry service. The difference in approach is where the state lives and who operates it. A hosted repository is a product you run on infrastructure you already have, usually against a database you already back up, with a vendor behind it. Verdaccio is a Node.js process that starts with its own tiny database and a config file, and you are the operator.
That trade is not automatically in Verdaccio's favour. A hosted repository typically brings retention policies, replication, and a support contract; Verdaccio brings a single command to a working registry and a plugin interface when you outgrow the default store. The README's own framing leans on the small scale: no need for an entire database just to get started. If your requirement is a registry that a large organisation depends on with contractual guarantees, the volunteer-run model is the deciding factor against it.
There is a narrower comparison worth making. If all you need is to cache npmjs.org for faster installs, a plain npm or pnpm cache, or a CI-level cache, may be enough, and it avoids running a server at all. Verdaccio earns its place when you also need private packages, access control, or one endpoint chaining several registries. Those are the features a package manager cache does not give you.
For teams already on Kubernetes, the official Helm chart lowers the adoption cost, but it does not change the operating model: you still own the storage volume, the configuration and the upgrades.
Maintenance, upgrades and what the MIT licence leaves to you
The repository is not archived, and the last push was on 2026-09-21. The recent releases list shows v6.10.4 on 2026-09-20, v6.10.3 on 2026-09-05, and a v7.0.0-next prerelease on 2026-09-04. The master branch is labelled Version Next in the README, so the stable line and the development line move separately, and the release notes in RELEASES.md describe how releases are versioned, approved and published across branches.
Upgrade cost has two parts. The first is the Node.js floor: version 6 needs Node.js 22 or higher and the next line needs Node.js 24 or higher, so a major upgrade can force a runtime upgrade across your build images. The second is the storage and configuration you carry. The Docker image mounts /verdaccio/storage as a volume and reads /verdaccio/conf/config.yaml, and neither the README nor the Dockerfile describes an automated migration or rollback path between major versions. Plan to snapshot that volume before upgrading, because the documentation does not promise you can go back.
On licensing, Verdaccio is MIT. That is permissive and places few obligations on how you use or redistribute it, but it also means no warranty and no support commitment from the maintainers. The README's funding section reinforces the practical side of that: donations start from one dollar a month, contributors get their logo in the README, and there is no funding for security research. If your organisation depends on the registry for every build, the MIT licence tells you what you may do with the code, not who answers when it breaks. That is a decision for your own risk process, and it is worth making explicitly rather than by default.
Editorial conclusion
Adopt Verdaccio when you need a private registry, an npmjs.org cache or a single endpoint in front of several registries, and when a file-backed store plus community plugins is acceptable. Do not adopt it if you need a built-in database, an enterprise support contract or a paid security response: the README states there is no funding for contributions or security research. Verify first that your Node.js version matches the branch you install, that your CI package manager appears in the e2e matrix, and that you have a backup plan for /verdaccio/storage, because the README does not document rollback or migration between major versions.
Frequently asked questions
How do I install Verdaccio?
The README gives four routes: npm install -g verdaccio@next-9, yarn global add verdaccio@next-9, pnpm i -g verdaccio@next-9, or the Docker image verdaccio/verdaccio:nightly-master. There is also an official Helm chart for Kubernetes. The next-9 tag requires Node.js v24 or higher.
How do I set up Verdaccio for a team?
The npm, Yarn and pnpm installs start a working registry with the bundled configuration and its own tiny database, so no external database is needed to begin. For shared use, the Docker image keeps data in a volume at /verdaccio/storage and reads its config from /verdaccio/conf/config.yaml, and the repository's docker-compose.yaml wires those together with VERDACCIO_PORT.
What is Verdaccio npm?
Verdaccio is a lightweight Node.js private proxy registry. It serves private packages and proxies other registries such as npmjs.org, caching downloaded modules along the way, and it can chain multiple registries through uplinks so projects fetch from a single endpoint.
Is Verdaccio open source and free?
Yes. The repository is licensed MIT and the README describes the project as run by volunteers, with donations starting from one dollar a month on Open Collective. The README also notes there is currently no funding available for contributions or security research.
How do I use Verdaccio?
Start the server after installing it, point your package manager at the running registry, then publish internal packages or install through it. The same instance proxies npmjs.org and caches what it fetches, so later installs of those packages and versions can be served locally.
What does Verdaccio do?
It provides a private npm registry, proxies and caches other registries such as npmjs.org, chains multiple registries behind one endpoint through uplinks, and can serve a modified version of a public package to your own consumers.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/verdaccio-verdaccio)