<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
    <channel>
        <title>Artifact Registry Release Notes</title>
        <link>https://developer.harness.io/release-notes/artifact-registry</link>
        <description>Harness Release Notes</description>
        <lastBuildDate>Wed, 12 Aug 2026 23:34:48 GMT</lastBuildDate>
        <docs>https://validator.w3.org/feed/docs/rss2.html</docs>
        <generator>https://github.com/jpmonette/feed</generator>
        <copyright>Harness Inc.</copyright>
        <item>
            <title><![CDATA[Artifact Registry Release Notes]]></title>
            <link>https://developer.harness.io/release-notes/artifact-registry</link>
            <guid>https://developer.harness.io/release-notes/artifact-registry</guid>
            <pubDate>Mon, 20 Jul 2026 12:00:00 GMT</pubDate>
            <description><![CDATA[The release notes describe recent changes to Harness Artifact Registry.]]></description>
            <content:encoded><![CDATA[<header><h1>Artifact Registry Release Notes</h1><hr class="docItemHeaderDivider_VNQW"></header><a href="https://developer.harness.io/release-notes/artifact-registry/rss.xml" target="_blank" rel="noopener noreferrer" class="link"><button class="doc-button small">Subscribe via RSS<i class="fa-solid fa-square-rss custom-icon"></i></button></a>
<p>The release notes describe recent changes to Harness Artifact Registry.</p>
<div class="searchContainer_fEoh"><div class="searchBox_oC5u"><svg class="searchIcon_QrdY" width="20" height="20" viewBox="0 0 20 20" fill="none" xmlns="http://www.w3.org/2000/svg"><path d="M9 17A8 8 0 1 0 9 1a8 8 0 0 0 0 16zM19 19l-4.35-4.35" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round"></path></svg><input type="text" class="searchInput_xoDK" placeholder="Search releases on this page..." aria-label="Search release notes" value=""></div></div>
<div class="theme-admonition theme-admonition-info admonition_xJq3 alert alert--info"><div class="admonitionHeading_Gvgb"><span class="admonitionIcon_Rf37"><svg viewBox="0 0 14 16"><path fill-rule="evenodd" d="M7 2.3c3.14 0 5.7 2.56 5.7 5.7s-2.56 5.7-5.7 5.7A5.71 5.71 0 0 1 1.3 8c0-3.14 2.56-5.7 5.7-5.7zM7 1C3.14 1 0 4.14 0 8s3.14 7 7 7 7-3.14 7-7-3.14-7-7-7zm1 3H6v5h2V4zm0 6H6v2h2v-2z"></path></svg></span>About Harness Release Notes</div><div class="admonitionContent_BuS1"><ul>
<li class=""><strong>Security advisories:</strong> Harness publishes security advisories for every release. Go to the <a href="https://trust.harness.io/?itemUid=c41ff7d5-98e7-4d79-9594-fd8ef93a2838&amp;source=documents_card" target="_blank" rel="noopener noreferrer" class="">Harness Trust Center</a> to request access to the security advisories.</li>
<li class=""><strong>More release notes:</strong> Go to <a class="" href="/release-notes">Harness Release Notes</a> to explore all Harness release notes, including module, delegate, and Self-Managed Enterprise Edition release notes.</li>
</ul></div></div>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="-release-deployment-status-by-cluster">📌 Release Deployment Status by Cluster<a href="#-release-deployment-status-by-cluster" class="hash-link" aria-label="Direct link to 📌 Release Deployment Status by Cluster" title="Direct link to 📌 Release Deployment Status by Cluster" translate="no">​</a></h2>
<p><strong>Progressive deployment:</strong> Harness deploys changes to Harness SaaS clusters on a progressive basis. This means that the features described in these release notes may not be immediately available in your cluster. To identify the cluster that hosts your account, go to your <strong>Account Overview</strong> page in Harness. In the new UI, go to <strong>Account Settings</strong>, <strong>Account Details</strong>, <strong>General</strong>, <strong>Account Details</strong>, and then <strong>Platform Service Versions</strong>.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="july-2026">July 2026<a href="#july-2026" class="hash-link" aria-label="Direct link to July 2026" title="Direct link to July 2026" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="20267v2">2026.7.v2<a href="#20267v2" class="hash-link" aria-label="Direct link to 2026.7.v2" title="Direct link to 2026.7.v2" translate="no">​</a></h3>
<h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="new-features">New Features<a href="#new-features" class="hash-link" aria-label="Direct link to New Features" title="Direct link to New Features" translate="no">​</a></h4>
<p><strong>Debian Registry Support</strong></p>
<p>Harness Artifact Registry now supports <strong>Debian packages</strong> for Debian and Ubuntu systems. Host private <code>.deb</code> packages, configure upstream proxies against external Debian mirrors, and install packages with standard APT workflows.</p>
<p>Go to the <a class="" href="/docs/artifact-registry/content/supported-formats/debian-quickstart">Debian quickstart</a> to create a Debian registry and publish your first package.</p>
<p><strong>Raw File artifacts for WinRM CD deployments</strong></p>
<p>Harness Continuous Delivery now supports <strong>Raw File</strong> artifacts from Harness Artifact Registry as a service artifact source for <strong>WinRM</strong> deployments. Deploy <code>.zip</code> packages and other files stored in a Raw File registry to Windows targets without a third-party artifact connector.</p>
<p>Go to <a class="" href="/docs/continuous-delivery/x-platform-cd-features/services/artifact-sources#harness-artifact-registry">Use artifacts from Harness Artifact Registry</a> to configure a Raw File artifact source, or go to the <a class="" href="/docs/continuous-delivery/deploy-srv-diff-platforms/traditional/win-rm-tutorial">WinRM tutorial</a> for a full deployment walkthrough.</p>
<h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="enhancements--fixes">Enhancements &amp; Fixes<a href="#enhancements--fixes" class="hash-link" aria-label="Direct link to Enhancements &amp; Fixes" title="Direct link to Enhancements &amp; Fixes" translate="no">​</a></h4>
<p><strong>Dependency Firewall audit from manifest files</strong></p>
<p>The Harness CLI <code>hc registry fw audit</code> command now supports auditing dependencies from <code>package.json</code> without a lock file in source control. Pass <code>package.json</code> to evaluate direct dependencies only, or generate a lock file in CI for a full transitive audit with <code>package-lock.json</code>, <code>yarn.lock</code>, or <code>pnpm-lock.yaml</code>.</p>
<p>Go to <a class="" href="/docs/artifact-registry/artifact-registry-cli/manage-artifacts-registries#audit-dependencies-with-dependency-firewall">Audit dependencies with Dependency Firewall</a> for input file scope and examples.</p>
<p><strong>Webhooks for RPM registries</strong></p>
<p>Artifact Creation and Artifact Deletion webhook events now fire for <strong>RPM</strong> registries. Webhooks are supported for all Artifact Registry package types other than <strong>Raw</strong>.</p>
<p>Go to <a class="" href="/docs/artifact-registry/manage-registries/ar-webhooks">Webhooks</a> to configure triggers.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="20267v1">2026.7.v1<a href="#20267v1" class="hash-link" aria-label="Direct link to 2026.7.v1" title="Direct link to 2026.7.v1" translate="no">​</a></h3>
<h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="new-features-1">New Features<a href="#new-features-1" class="hash-link" aria-label="Direct link to New Features" title="Direct link to New Features" translate="no">​</a></h4>
<p><strong>Helm HTTP registry type</strong></p>
<p>Host and consume Helm charts with the classic <code>helm repo add</code> / <code>helm pull</code> workflow with a new <strong>Helm HTTP</strong> registry type. Unlike the existing Helm OCI registry, Helm HTTP uses the HTTP-based Helm chart repository protocol (<code>index.yaml</code> + <code>.tgz</code> archives) and supports upstream proxy pull-through for public Helm repositories.</p>
<p>Go to <a class="" href="/docs/artifact-registry/content/supported-formats/helm-http-quickstart">Helm HTTP quickstart</a> to create your first Helm HTTP registry.</p>
<p><strong>Native Harness Artifact Registry for CD Run steps in Containerized Step Groups</strong></p>
<p>CD Run steps inside a Step Group with <strong>container based execution</strong> enabled can now reference container images from Harness Artifact Registry natively, without a Docker connector. In the Run step, set <strong>Registry Type</strong> to <strong>Artifact Registry</strong>, select your registry in <strong>Container Registry</strong>, and enter the image reference in <strong>Image</strong>. To pull from an external Docker registry through a Harness Docker connector instead, choose <strong>Third-Party Artifact Registry</strong>.</p>
<p>Go to <a class="" href="/docs/artifact-registry/platform-integrations/cd-ar-integrations#add-a-run-step-inside-a-containerized-step-group">Add a Run step inside a Containerized Step Group</a> to walk through the setup.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="june-2026">June 2026<a href="#june-2026" class="hash-link" aria-label="Direct link to June 2026" title="Direct link to June 2026" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="20266v1">2026.6.v1<a href="#20266v1" class="hash-link" aria-label="Direct link to 2026.6.v1" title="Direct link to 2026.6.v1" translate="no">​</a></h3>
<h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="new-features-2">New Features<a href="#new-features-2" class="hash-link" aria-label="Direct link to New Features" title="Direct link to New Features" translate="no">​</a></h4>
<p><strong>Lifecycle Rules (Cleanup and Retention)</strong></p>
<div class="theme-admonition theme-admonition-info admonition_xJq3 alert alert--info"><div class="admonitionHeading_Gvgb"><span class="admonitionIcon_Rf37"><svg viewBox="0 0 14 16"><path fill-rule="evenodd" d="M7 2.3c3.14 0 5.7 2.56 5.7 5.7s-2.56 5.7-5.7 5.7A5.71 5.71 0 0 1 1.3 8c0-3.14 2.56-5.7 5.7-5.7zM7 1C3.14 1 0 4.14 0 8s3.14 7 7 7 7-3.14 7-7-3.14-7-7-7zm1 3H6v5h2V4zm0 6H6v2h2v-2z"></path></svg></span>Feature flag</div><div class="admonitionContent_BuS1"><p>This feature is behind the feature flag <code>HAR_ARTIFACT_LIFECYCLE_POLICY</code>. Contact <a href="mailto:support@harness.io" target="_blank" rel="noopener noreferrer" class="">Harness Support</a> to enable it.</p></div></div>
<p>Lifecycle rules bring policy-based artifact management to Harness Artifact Registry. Define rules that automatically identify and soft-delete stale artifact versions on a recurring schedule, so your registries stay lean without manual cleanup.</p>
<img class="DocImageWithBorder_Xort" src="/assets/images/june-2026-lifecycle-rules-e36fe413335f4fbcf9b86d86ac1dbf2a.png" width="100%" alt="Lifecycle Rules list view showing cleanup and retention rules with status, scope, and attached registries" title="Lifecycle Rules: manage cleanup and retention policies from a single view">
<p><strong>Key capabilities:</strong></p>
<ul>
<li class=""><strong>Cleanup rules:</strong> Soft-delete versions that match your criteria (age, version count, or name pattern). Deleted artifacts remain recoverable during the configured recovery period.</li>
<li class=""><strong>Retention rules:</strong> Protect matching artifacts from all deletion, including cleanup rules, manual soft delete, and manual hard delete. Retention rules are always evaluated first, overriding any deletion attempt.</li>
<li class=""><strong>Hierarchical scoping:</strong> Create rules at the account, organization, or project level and attach them to one or more registries.</li>
<li class=""><strong>Dry-run mode:</strong> Preview which versions a rule would affect before you enable it, so you can validate criteria safely.</li>
<li class=""><strong>Execution history:</strong> Track every run with detailed logs showing which versions were deleted and which were retained.</li>
<li class=""><strong>Notification integration:</strong> Fire centralised notification events when a cleanup rule or dry run finishes executing.</li>
</ul>
<p>Go to <a class="" href="/docs/artifact-registry/lifecycle-rules/overview">Lifecycle Rules</a> to understand how rules work. To start creating rules, go to <a class="" href="/docs/artifact-registry/lifecycle-rules/create-cleanup-rule">Create a cleanup rule</a> or <a class="" href="/docs/artifact-registry/lifecycle-rules/create-retention-rule">Create a retention rule</a>.</p>
<p><strong>Centralised Notifications for Artifact Registry</strong></p>
<p>Centralised Notifications now support Artifact Registry events. Configure notification rules at the organization level that apply to every project under the organizations you select, with no per-registry setup required.</p>
<p>Available events: Dependency Firewall Exemption Requested, Dependency Firewall Exemption Status Changed, Lifecycle Policy Execution Completed, and Lifecycle Policy Dry Run Execution Completed.</p>
<p>Go to <a class="" href="/docs/platform/notifications/centralised-notification#artifact-registry-notifications">Centralised Notification</a> to configure notification rules for Artifact Registry events.</p>
<p><strong>Puppet Registry Support</strong></p>
<p>Harness Artifact Registry now supports <strong>Puppet modules</strong> with full Puppet Forge compatibility. Publish with the Puppet CLI or <code>r10k</code>, host private modules inside your Harness account, and cache modules from external Puppet Forge sources through an upstream proxy.</p>
<p>Go to the <a class="" href="/docs/artifact-registry/get-started/quickstart#puppet">Puppet Registry Quickstart</a> to set up a Puppet registry and publish your first module.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="may-2026">May 2026<a href="#may-2026" class="hash-link" aria-label="Direct link to May 2026" title="Direct link to May 2026" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="20265v1">2026.5.v1<a href="#20265v1" class="hash-link" aria-label="Direct link to 2026.5.v1" title="Direct link to 2026.5.v1" translate="no">​</a></h3>
<h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="new-features-3">New Features<a href="#new-features-3" class="hash-link" aria-label="Direct link to New Features" title="Direct link to New Features" translate="no">​</a></h4>
<p><strong>Dependency Firewall Exemptions</strong></p>
<p>Request temporary access to blocked package versions through an approval workflow. A developer files a request with a business justification, an approver reviews it, and on approval the version becomes usable for a fixed duration. After expiry, the original policy verdict applies again. Centralized notification rules are available for exemption events.</p>
<p>Go to <a class="" href="/docs/artifact-registry/dependency-firewall/exemptions">Dependency Exemptions</a> to set up the workflow.</p>
<p><strong>Quarantine artifacts on Warning verdict</strong></p>
<p>A new checkbox on the upstream proxy configuration quarantines artifacts whose policy verdict is Warning (in addition to Blocked). Warning artifacts are cached but blocked until an administrator releases them from quarantine using the quarantine management UI. Exemptions do not apply to quarantined packages.</p>
<p>Go to <a class="" href="/docs/artifact-registry/manage-registries/configure-registry#enable-dependency-firewall">Enable Dependency Firewall</a> to configure this option.</p>
<p><strong>OSS Risk Level and Malicious Package policy templates</strong></p>
<p>Two new built-in Dependency Firewall policy templates:</p>
<ul>
<li class=""><strong>OSS Risk Level:</strong> Blocks artifacts that exceed a configured open-source risk threshold, factoring in maintenance status, known vulnerabilities, and community health.</li>
<li class=""><strong>Malicious Package:</strong> Blocks any artifact version flagged as malicious in threat intelligence databases.</li>
</ul>
<p>These join the existing CVSS Threshold, License Policy, and Package Age templates. Go to <a class="" href="/docs/artifact-registry/dependency-firewall/configure-policies">Configure Policies and Policy Sets</a> to use them.</p>
<h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="enhancements--fixes-1">Enhancements &amp; Fixes<a href="#enhancements--fixes-1" class="hash-link" aria-label="Direct link to Enhancements &amp; Fixes" title="Direct link to Enhancements &amp; Fixes" translate="no">​</a></h4>
<p><strong>CLI bulk artifact deletion</strong></p>
<p>The Harness CLI now supports bulk deletion with wildcard patterns (for example, <code>1.0.*</code>) and dry-run preview. Supported for Generic, Maven, npm, Python, NuGet, Go, Conda, Composer, Swift, and Dart registries. Go to <a class="" href="/docs/artifact-registry/artifact-registry-cli/manage-artifacts-registries#delete-artifacts">Delete Artifacts</a> to use bulk delete.</p>
<p><strong>Webhooks for upstream proxy registries</strong></p>
<p>Artifact Creation and Artifact Deletion webhook events now fire for upstream proxy registries. When a package is cached from an external source, the creation event fires. Supported for Docker, Maven, npm, Python, and NuGet upstream proxies. Cosign signature (<code>.sig</code>) and attestation (<code>.att</code>) artifacts are automatically filtered out. <em>[AH-3516, AH-3943]</em></p>
<p>Go to <a class="" href="/docs/artifact-registry/manage-registries/ar-webhooks">Webhooks</a> to configure triggers.</p>
<hr>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="april-2026">April 2026<a href="#april-2026" class="hash-link" aria-label="Direct link to April 2026" title="Direct link to April 2026" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="20264v1">2026.4.v1<a href="#20264v1" class="hash-link" aria-label="Direct link to 2026.4.v1" title="Direct link to 2026.4.v1" translate="no">​</a></h3>
<h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="new-features-4">New Features<a href="#new-features-4" class="hash-link" aria-label="Direct link to New Features" title="Direct link to New Features" translate="no">​</a></h4>
<p><strong>Swift Registry Support</strong></p>
<p>Harness Artifact Registry now supports <strong>Swift packages</strong> with full Swift Package Manager (SwiftPM) compatibility. Use the registry URL with <code>swift package-registry</code> for authentication, publishing, and dependency resolution. Your existing SwiftPM workflows keep working with Harness as the source of truth.</p>
<p><strong>Key benefits:</strong></p>
<ul>
<li class=""><strong>Native SwiftPM workflow:</strong> Compatible with <code>swift package-registry</code> commands (login, publish, resolve) on Swift 5.9 or later.</li>
<li class=""><strong>Private package hosting:</strong> Host proprietary Swift packages securely inside your Harness account.</li>
<li class=""><strong>Upstream proxy support:</strong> Cache packages from external Swift sources to accelerate builds and reduce external dependencies.</li>
</ul>
<p>Go to the <a class="" href="/docs/artifact-registry/get-started/quickstart#swift">Swift Registry Quickstart</a> to set up a Swift registry and publish your first package.</p>
<p><strong>Raw File Registry Support</strong></p>
<p>The new <strong>Raw File registry</strong> lets you store and retrieve arbitrary files by path: archives, reports, configuration files, or anything else that does not belong to a package manager ecosystem. You upload, download, inspect, and delete files using HTTP requests and <code>curl</code>, with no specialized client required.</p>
<p><strong>Key benefits:</strong></p>
<ul>
<li class=""><strong>Path-based storage:</strong> Address files directly by their path, ideal for build artifacts, reports, and shared configs.</li>
<li class=""><strong>HTTP-native workflow:</strong> Push and pull files with <code>curl</code> or any HTTP client; no custom CLI plugin required.</li>
<li class=""><strong>Upstream proxy support:</strong> Optionally cache files from an external HTTP source through Harness.</li>
</ul>
<p>Go to the <a class="" href="/docs/artifact-registry/get-started/quickstart#raw-file">Raw File Registry Quickstart</a> to create a Raw File registry and upload your first file.</p>
<p><strong>Copy Version between Registries</strong></p>
<p>You can now copy a specific package version from one Harness registry to another directly from the UI, with no need to re-push from your machine when promoting a version into another project or organization.</p>
<img class="DocImageWithBorder_Xort" src="/assets/images/april-2026-copy-version-f0b291b1a42f37632d6667e0496ec73b.png" width="80%" alt="npm package Versions tab with the row menu open showing Copy Version among the actions" title="Versions tab: use the row menu and select Copy Version">
<p>Open the package, switch to the <strong>Versions</strong> tab, open the row menu (<strong>⋮</strong>) on the version you want, and select <strong>Copy Version</strong>. Pick the target organization, project, and registry in the dialog, then run the copy. Permissions: read on the source registry, write on the target. The same operation is available from the CLI for automation.</p>
<p>Go to <a class="" href="/docs/artifact-registry/manage-artifacts/artifact-management#copy-a-version">Copy a version</a> to use the UI flow, or <a class="" href="/docs/artifact-registry/artifact-registry-cli/manage-artifacts-registries#copy-artifacts">Copy artifacts in the Harness CLI</a> to run the same operation from the command line.</p>
<p><strong>Soft Delete for Artifacts and Versions</strong></p>
<div class="theme-admonition theme-admonition-info admonition_xJq3 alert alert--info"><div class="admonitionHeading_Gvgb"><span class="admonitionIcon_Rf37"><svg viewBox="0 0 14 16"><path fill-rule="evenodd" d="M7 2.3c3.14 0 5.7 2.56 5.7 5.7s-2.56 5.7-5.7 5.7A5.71 5.71 0 0 1 1.3 8c0-3.14 2.56-5.7 5.7-5.7zM7 1C3.14 1 0 4.14 0 8s3.14 7 7 7 7-3.14 7-7-3.14-7-7-7zm1 3H6v5h2V4zm0 6H6v2h2v-2z"></path></svg></span>Feature flag</div><div class="admonitionContent_BuS1"><p>This feature is behind the feature flag <code>HAR_SOFT_DELETE_SUPPORT</code>. Contact <a href="mailto:support@harness.io" target="_blank" rel="noopener noreferrer" class="">Harness Support</a> to enable it.</p></div></div>
<p>Deleting a package or a version is now <strong>soft by default</strong>. Deleted items move to a <strong>Deleted</strong> view where they remain recoverable until the retention window allows them to be purged. You can also opt in to a permanent delete from the same dialog when that is what you intend.</p>
<img class="DocImageWithBorder_Xort" src="/assets/images/april-2026-soft-delete-deleted-tab-aab73ec256e6525a7b1a06015b43dbbc.png" width="100%" alt="Artifacts page Deleted tab listing soft-deleted packages, versions, and related rows" title="Artifacts → Deleted tab: soft-deleted items remain recoverable">
<p><strong>Key capabilities:</strong></p>
<ul>
<li class=""><strong>Recoverable deletes:</strong> Restore a package or version from the <strong>Deleted</strong> tab or the row menu, including content from a soft-deleted registry.</li>
<li class=""><strong>Cascade on registry delete:</strong> Soft-deleting a registry soft-deletes all packages, images, and versions inside it; restoring a child can restore the parent registry.</li>
<li class=""><strong>Configurable retention:</strong> Account administrators set the retention window in <strong>Default Settings → Artifact Registry</strong>; the value applies across the account, organization, or project.</li>
<li class=""><strong>Permanent delete still available:</strong> Select <strong>Permanently delete</strong> in the confirmation dialog when you want immediate, non-recoverable removal.</li>
</ul>
<p>Go to <a class="" href="/docs/artifact-registry/manage-artifacts/soft-delete">Delete Artifacts</a> to learn the soft-delete and restore flow, and <a class="" href="/docs/artifact-registry/manage-registries/delete-registry">Delete a Registry</a> to understand the cascade behavior.</p>
<p><strong>Artifact Registry Audit Dashboard</strong></p>
<p>The new <strong>Artifact Registry Audit Dashboard</strong> is an out-of-the-box dashboard in Harness Dashboards that records every artifact <strong>upload</strong> and <strong>download</strong> across your Harness Artifact Registries. It is provisioned and maintained by Harness, so it appears automatically for accounts that have Artifact Registry enabled — no setup, no widgets to build.</p>
<img class="DocImageWithBorder_Xort" src="/assets/images/april-2026-audit-dashboard-413e3c59bb00f80492976514903e6729.png" width="100%" alt="Artifact Registry Audit Dashboard with Time Range and identifier filters at the top, two event tables for downloads and uploads, an upload-and-download activity line chart, and an Upload/Download Aggregation donut" title="Artifact Registry Audit Dashboard">
<p><strong>Key capabilities:</strong></p>
<ul>
<li class=""><strong>Built for security and compliance:</strong> Identify which users or service accounts pulled a specific package version after a CVE or zero-day disclosure, and audit upload activity on a registry over a chosen time window.</li>
<li class=""><strong>Filter by scope and artifact:</strong> Narrow results by <strong>Time Range</strong>, <strong>Organization Identifier</strong>, <strong>Project Identifier</strong>, <strong>Registry Name</strong>, <strong>Package Name</strong>, and <strong>Version Name</strong>. Every widget on the page reacts to the filter set.</li>
<li class=""><strong>Four widgets out of the box:</strong> <strong>Download Artifact Data</strong> and <strong>Upload Artifact Data</strong> event tables (Action, Registry, Package, Version, Username, Client IP, Timestamp Hour), an <strong>Upload And Download Activity</strong> time series, and an <strong>Upload/Download Aggregation</strong> donut.</li>
<li class=""><strong>Read-only and clone-friendly:</strong> The original is owned by Harness and stays read-only so it keeps receiving updates. To customize widgets or filters, open the row menu and choose <strong>Clone</strong>; the clone belongs to your account and is fully editable.</li>
</ul>
<p>Go to <a class="" href="/docs/artifact-registry/manage-artifacts/audit-dashboard">Artifact Registry audit dashboard</a> to open the dashboard and walk through the upload-and-download workflows.</p>
<h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="enhancements--fixes-2">Enhancements &amp; Fixes<a href="#enhancements--fixes-2" class="hash-link" aria-label="Direct link to Enhancements &amp; Fixes" title="Direct link to Enhancements &amp; Fixes" translate="no">​</a></h4>
<p><strong>Webhook support extended to Python, Maven, and NuGet</strong></p>
<p>Artifact Registry <strong>webhooks</strong> now cover additional package types so more teams can drive CI/CD, security, and notification workflows from artifact events. The supported list now includes <strong>Maven, NuGet, and Python (PyPI)</strong>.</p>
<p>Go to <a class="" href="/docs/artifact-registry/manage-registries/ar-webhooks">Webhooks</a> to view the full support table and to wire webhooks to triggers.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="march-2026">March 2026<a href="#march-2026" class="hash-link" aria-label="Direct link to March 2026" title="Direct link to March 2026" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="20263v1">2026.3.v1<a href="#20263v1" class="hash-link" aria-label="Direct link to 2026.3.v1" title="Direct link to 2026.3.v1" translate="no">​</a></h3>
<h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="new-features-5">New Features<a href="#new-features-5" class="hash-link" aria-label="Direct link to New Features" title="Direct link to New Features" translate="no">​</a></h4>
<p><strong>Maven plugin for Artifact Registry</strong></p>
<p>The <strong>Harness Maven plugin</strong> (<code>io.harness.maven:harness-maven-plugin</code>) lets you publish JARs, WARs, POMs, and related artifacts from your Maven build—no one-off scripts or manual uploads. It fits the standard Maven lifecycle, supports <strong>parallel-friendly deployments</strong> for multi-module projects, and can <strong>enforce dependency resolution through Harness upstream proxies</strong> so builds pull through the registries you govern.</p>
<ul>
<li class=""><strong>Deploy from Maven</strong>: Bind the <code>deploy</code> goal and push artifacts to Harness using the same coordinates and repositories your teams already use.</li>
<li class=""><strong>Credentials via environment variables</strong>: Keep tokens out of <code>pom.xml</code> by configuring Harness registry URL and identity token through environment variables in CI and local workflows.</li>
</ul>
<p>Learn more in the <a class="" href="/docs/artifact-registry/build-plugins/overview">Build plugins overview</a>; open the <strong>Maven Plugin</strong> tab there for installation and configuration.</p>
<p><strong>Gradle plugin for Artifact Registry</strong></p>
<p>The <strong>Harness Gradle plugin</strong> (<code>io.harness.gradle</code>) hooks into <code>./gradlew publish</code>: Harness uploads artifacts to Artifact Registry in <strong>parallel</strong> for faster multi-module builds and reads <strong>registry URL and credentials from environment variables</strong> so secrets stay out of Gradle scripts and source control.</p>
<ul>
<li class=""><strong>Drop-in Gradle workflow</strong>: Apply the plugin in the root or subprojects and keep using your existing publish tasks.</li>
<li class=""><strong>Built for CI</strong>: Matches how Gradle projects already inject registry configuration in pipelines.</li>
</ul>
<p>Learn more in the <a class="" href="/docs/artifact-registry/build-plugins/overview">Build plugins overview</a>; open the <strong>Gradle Plugin</strong> tab there for installation and configuration.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="february-2026">February 2026<a href="#february-2026" class="hash-link" aria-label="Direct link to February 2026" title="Direct link to February 2026" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="20262v1">2026.2.v1<a href="#20262v1" class="hash-link" aria-label="Direct link to 2026.2.v1" title="Direct link to 2026.2.v1" translate="no">​</a></h3>
<h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="new-features-6">New Features<a href="#new-features-6" class="hash-link" aria-label="Direct link to New Features" title="Direct link to New Features" translate="no">​</a></h4>
<p><strong>Dependency Firewall</strong></p>
<p>We're excited to ship <strong>Dependency Firewall</strong> in Harness Artifact Registry—a major step forward for software supply chain security. Until now, risky or non-compliant packages could flow into your organization through upstream proxies with little gatekeeping at the registry boundary. Dependency Firewall changes that: it evaluates <strong>every</strong> artifact version pulled from an external source <strong>before</strong> it is cached in your upstream proxy registry, using the same <a class="" href="/docs/platform/governance/policy-as-code/harness-governance-overview">Policy as Code</a> and OPA-style policies you already trust elsewhere in Harness.</p>
<ul>
<li class=""><strong>Policy at the front door:</strong> CVSS thresholds, license rules, package age, and custom Rego policies can allow, warn on, or block versions automatically—so violations are caught when dependencies are first fetched, not after they have spread across builds.</li>
<li class=""><strong>Clear outcomes:</strong> Each evaluation is <strong>Passed</strong>, <strong>Warning</strong>, or <strong>Blocked</strong>. In <strong>Block</strong> mode, non-compliant versions are never cached and cannot be downloaded or used; <strong>Warn</strong> mode helps you roll out policies safely while you refine rules.</li>
<li class=""><strong>Built for operators:</strong> Enable the firewall on your upstream proxy, attach policy sets, pick <strong>Block</strong> or <strong>Warn</strong>, and track everything from the <strong>Dependency Firewall</strong> tab—no separate toolchain required.</li>
</ul>
<p><img decoding="async" loading="lazy" alt="Dependency Firewall tab: dashboard summaries and evaluated package list" src="/assets/images/february-2026-dependency-firewall-dashboard-72afce37c3694f0252a0edb3106cba4d.png" width="3452" height="1920" class="img_ev3q"></p>
<div class="theme-admonition theme-admonition-note admonition_xJq3 alert alert--secondary"><div class="admonitionHeading_Gvgb"><span class="admonitionIcon_Rf37"><svg viewBox="0 0 14 16"><path fill-rule="evenodd" d="M6.3 5.69a.942.942 0 0 1-.28-.7c0-.28.09-.52.28-.7.19-.18.42-.28.7-.28.28 0 .52.09.7.28.18.19.28.42.28.7 0 .28-.09.52-.28.7a1 1 0 0 1-.7.3c-.28 0-.52-.11-.7-.3zM8 7.99c-.02-.25-.11-.48-.31-.69-.2-.19-.42-.3-.69-.31H6c-.27.02-.48.13-.69.31-.2.2-.3.44-.31.69h1v3c.02.27.11.5.31.69.2.2.42.31.69.31h1c.27 0 .48-.11.69-.31.2-.19.3-.42.31-.69H8V7.98v.01zM7 2.3c-3.14 0-5.7 2.54-5.7 5.68 0 3.14 2.56 5.7 5.7 5.7s5.7-2.55 5.7-5.7c0-3.15-2.56-5.69-5.7-5.69v.01zM7 .98c3.86 0 7 3.14 7 7s-3.14 7-7 7-7-3.12-7-7 3.14-7 7-7z"></path></svg></span>Feature flag</div><div class="admonitionContent_BuS1"><p>Dependency Firewall is behind the feature flag <code>HAR_DEPENDENCY_FIREWALL</code>. Contact <a href="mailto:support@harness.io" target="_blank" rel="noopener noreferrer" class="">Harness Support</a> to enable it.</p></div></div>
<p>Learn more in the <a class="" href="/docs/artifact-registry/dependency-firewall/overview">Dependency Firewall overview</a>, <a class="" href="/docs/artifact-registry/manage-registries/configure-registry#enable-dependency-firewall">enable Dependency Firewall</a> in registry configuration, <a class="" href="/docs/artifact-registry/dependency-firewall/configure-policies">configure policies and policy sets</a>, and the tutorial <a class="" href="/docs/artifact-registry/tutorials/dependency-firewall-opa-policies">Implement Dependency Firewall with OPA policies</a>.</p>
<p><strong>Python registry: Poetry and uv</strong></p>
<p>Harness Python registries now document first-class workflows for <strong><a href="https://python-poetry.org/" target="_blank" rel="noopener noreferrer" class="">Poetry</a></strong> and <strong><a href="https://docs.astral.sh/uv/" target="_blank" rel="noopener noreferrer" class="">uv</a></strong>—including publishing, installing, and authenticating with identity tokens—alongside existing <strong>pip</strong> instructions. Use the same <code>pkg.harness.io</code> endpoints and tokens as for pip; Poetry and uv integrate through explicit sources, <code>pyproject.toml</code>, and lockfiles your teams may already use.</p>
<p>Follow the <strong>poetry</strong> and <strong>uv</strong> tabs in the embedded guide on <a class="" href="/docs/artifact-registry/get-started/quickstart">Get started with Artifact Registry</a> (select <strong>Python</strong> in the format selector) for copy-ready commands.</p>
<h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="enhancements--fixes-3">Enhancements &amp; Fixes<a href="#enhancements--fixes-3" class="hash-link" aria-label="Direct link to Enhancements &amp; Fixes" title="Direct link to Enhancements &amp; Fixes" translate="no">​</a></h4>
<p><strong>Harness CLI: Dependency Firewall audit, explain, and npm client configuration</strong></p>
<p>The Harness CLI (<code>hc</code>) streamlines Artifact Registry operations for security and local client setup:</p>
<ul>
<li class=""><strong><code>hc registry fw audit</code></strong> (alias <code>hc registry firewall audit</code>): Parse lock and manifest files and evaluate dependencies in bulk against Dependency Firewall policies. Supported inputs include NPM, Java (Maven and Gradle), and <strong>Python</strong> files such as <code>requirements.txt</code>, <code>pyproject.toml</code>, <code>Pipfile.lock</code>, and <strong><code>poetry.lock</code></strong>.</li>
<li class=""><strong><code>hc registry fw explain</code></strong>: Return firewall scan status (<strong>Passed</strong>, <strong>BLOCKED</strong>, or <strong>WARN</strong>) and details for a specific package version already present in a registry.</li>
<li class=""><strong><code>hc registry configure npm</code></strong>: Write Harness registry URLs and authentication into <code>.npmrc</code> for default, scoped, global, or project-level npm configuration.</li>
</ul>
<p>Learn more in <a class="" href="/docs/artifact-registry/artifact-registry-cli/manage-artifacts-registries">Manage artifacts and registries with the CLI</a>: <a class="" href="/docs/artifact-registry/artifact-registry-cli/manage-artifacts-registries#audit-dependencies-from-lock-files">Audit dependencies from lock files</a>, <a class="" href="/docs/artifact-registry/artifact-registry-cli/manage-artifacts-registries#get-firewall-status-for-an-artifact-version">Get firewall status for an artifact version</a>, and <a class="" href="/docs/artifact-registry/artifact-registry-cli/manage-artifacts-registries#configure-npm-client">Configure npm client</a>.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="january-2026">January 2026<a href="#january-2026" class="hash-link" aria-label="Direct link to January 2026" title="Direct link to January 2026" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="20261v1">2026.1.v1<a href="#20261v1" class="hash-link" aria-label="Direct link to 2026.1.v1" title="Direct link to 2026.1.v1" translate="no">​</a></h3>
<h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="new-features-7">New Features<a href="#new-features-7" class="hash-link" aria-label="Direct link to New Features" title="Direct link to New Features" translate="no">​</a></h4>
<p><strong>Artifact Download from UI</strong></p>
<p>Harness Artifact Registry now supports downloading artifacts directly from the UI. You can download all versions of an artifact, specific versions, or individual files. The system prepares your download as a compressed archive and displays a status indicator at the bottom center of the page. Once ready, downloads remain available for 24 hours.</p>
<p><img decoding="async" loading="lazy" src="/assets/images/download-b6138c4751448f59e865e57dc7f13157.png" width="1467" height="552" class="img_ev3q"></p>
<p>This feature works seamlessly with Docker digests and all supported artifact types, making it easy to retrieve artifacts for offline use, backup, or distribution.</p>
<p>Learn more about <a class="" href="/docs/artifact-registry/manage-artifacts/artifact-management#download-an-artifact">downloading artifacts from the UI</a>.</p>
<p><strong>Native CI Integration for Artifact Upload</strong></p>
<p>We've introduced a new <strong>native Upload Artifact to Harness Artifact Registry step</strong> in Harness CI pipelines, making it easier than ever to publish build artifacts directly to Harness Artifact Registry without custom scripts or third-party plugins.</p>
<p><strong>What's new:</strong></p>
<ul>
<li class=""><strong>Built-in CI step</strong>: New "Upload Artifacts to Harness Artifact Registry" step available in all CI pipelines</li>
<li class=""><strong>Multi-format (non-OCI) support</strong>: Upload artifacts in formats such as Maven JARs, npm packages, Python wheels, Conda packages, Generic artifacts, and more</li>
</ul>
<p>This native integration streamlines your CI/CD workflows by eliminating the need for custom scripts and manual authentication setup. Simply add the step to your pipeline, configure your target registry, and let Harness handle the rest.</p>
<p>Learn more about the <a class="" href="/docs/artifact-registry/platform-integrations/ci-ar-integrations">native CI integration for Artifact Registry</a>.</p>
<h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="enhancements--fixes-4">Enhancements &amp; Fixes<a href="#enhancements--fixes-4" class="hash-link" aria-label="Direct link to Enhancements &amp; Fixes" title="Direct link to Enhancements &amp; Fixes" translate="no">​</a></h4>
<p><strong>Enhanced CLI Capabilities for Artifact Registry</strong></p>
<p>The Harness CLI (<code>hc</code>) now includes expanded functionality for managing artifacts and registries:</p>
<ul>
<li class="">
<p><strong>Metadata Management</strong>: Set, get, and delete custom metadata on registries, packages, and specific versions. Use metadata for tagging environments, tracking ownership, managing approval workflows, and maintaining compliance information.</p>
</li>
<li class="">
<p><strong>Artifact Copy</strong>: Copy specific versions of artifacts between registries within your Harness Artifact Registry, with support for artifact type specification (e.g., model, dataset).</p>
</li>
<li class="">
<p><strong>Artifact Version Delete</strong>: Delete specific versions of artifacts or all versions of an artifact. This provides granular control over artifact lifecycle management.</p>
</li>
<li class="">
<p><strong>Registry Delete</strong>: Remove entire registries from your projects through the CLI.</p>
</li>
<li class="">
<p><strong>Python and NuGet Support</strong>: Manage Python (PyPI) and NuGet packages directly from the command line.</p>
</li>
</ul>
<p>These enhancements provide a consistent CLI experience across all supported registry types, making it easier for development teams to integrate Harness Artifact Registry into their existing workflows and automation pipelines.</p>
<p>Learn more about <a class="" href="/docs/artifact-registry/artifact-registry-cli/manage-artifacts-registries">managing artifacts and registries with the CLI</a>.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="december-2025">December 2025<a href="#december-2025" class="hash-link" aria-label="Direct link to December 2025" title="Direct link to December 2025" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="202512v1">2025.12.v1<a href="#202512v1" class="hash-link" aria-label="Direct link to 2025.12.v1" title="Direct link to 2025.12.v1" translate="no">​</a></h3>
<h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="new-features-8">New Features<a href="#new-features-8" class="hash-link" aria-label="Direct link to New Features" title="Direct link to New Features" translate="no">​</a></h4>
<p><strong>PHP Composer Registry Support</strong></p>
<p>Harness Artifact Registry now supports PHP Composer packages, providing a secure, private registry for your PHP dependencies. You can store, manage, and distribute Composer packages directly within Harness with full compatibility with the Composer package manager.</p>
<p><strong>Key benefits:</strong></p>
<ul>
<li class=""><strong>Private package hosting</strong>: Host your proprietary PHP libraries and internal packages securely</li>
<li class=""><strong>Upstream proxy support</strong>: Cache packages from Packagist and other public repositories to accelerate builds and reduce external dependencies</li>
<li class=""><strong>Version management</strong>: Full support for semantic versioning and package constraints</li>
</ul>
<p>To learn more about how to use Harness Artifact Registry with PHP Composer, check out our <a class="" href="/docs/artifact-registry/get-started/quickstart/#composer">Composer Registry documentation</a>.</p>
<h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="enhancements--fixes-5">Enhancements &amp; Fixes<a href="#enhancements--fixes-5" class="hash-link" aria-label="Direct link to Enhancements &amp; Fixes" title="Direct link to Enhancements &amp; Fixes" translate="no">​</a></h4>
<p><strong>Python PyPI Upstream Proxy Enhancements</strong></p>
<p>Python PyPI upstream proxy configuration now supports specifying a custom registry suffix for non-standard PyPI endpoints. This allows platform teams to integrate private PyPI repositories and enterprise artifact managers such as Artifactory, Nexus, or self-hosted PyPI mirrors that do not expose packages under the default <code>/simple/</code> path.</p>
<p>You can configure a remote registry URL, optionally define a custom registry suffix, and choose the appropriate authentication method. Harness transparently proxies Python packages from these upstream registries while handling authentication and package resolution.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="november-2025">November 2025<a href="#november-2025" class="hash-link" aria-label="Direct link to November 2025" title="Direct link to November 2025" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="202511v2">2025.11.v2<a href="#202511v2" class="hash-link" aria-label="Direct link to 2025.11.v2" title="Direct link to 2025.11.v2" translate="no">​</a></h3>
<h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="new-features-9">New Features<a href="#new-features-9" class="hash-link" aria-label="Direct link to New Features" title="Direct link to New Features" translate="no">​</a></h4>
<p><strong>Metadata Support for Artifacts and Registries</strong></p>
<p>Now enhance your artifact management with custom metadata! You can now attach key-value pairs to registries, artifacts, and packages, enabling better organization, searchability, and governance across your artifact ecosystem.</p>
<p><strong>Key capabilities:</strong></p>
<ul>
<li class=""><strong>Multi-level metadata</strong>: Add metadata at registry, artifact, and package (version) levels</li>
<li class=""><strong>Flexible filtering</strong>: Search and filter artifacts using custom metadata attributes</li>
<li class=""><strong>Custom attributes</strong>: Track ownership, environment tags, build information, security classifications, and more</li>
<li class=""><strong>Enhanced governance</strong>: Maintain audit trails and compliance information with version-specific metadata</li>
</ul>
<div class="theme-admonition theme-admonition-note admonition_xJq3 alert alert--secondary"><div class="admonitionHeading_Gvgb"><span class="admonitionIcon_Rf37"><svg viewBox="0 0 14 16"><path fill-rule="evenodd" d="M6.3 5.69a.942.942 0 0 1-.28-.7c0-.28.09-.52.28-.7.19-.18.42-.28.7-.28.28 0 .52.09.7.28.18.19.28.42.28.7 0 .28-.09.52-.28.7a1 1 0 0 1-.7.3c-.28 0-.52-.11-.7-.3zM8 7.99c-.02-.25-.11-.48-.31-.69-.2-.19-.42-.3-.69-.31H6c-.27.02-.48.13-.69.31-.2.2-.3.44-.31.69h1v3c.02.27.11.5.31.69.2.2.42.31.69.31h1c.27 0 .48-.11.69-.31.2-.19.3-.42.31-.69H8V7.98v.01zM7 2.3c-3.14 0-5.7 2.54-5.7 5.68 0 3.14 2.56 5.7 5.7 5.7s5.7-2.55 5.7-5.7c0-3.15-2.56-5.69-5.7-5.69v.01zM7 .98c3.86 0 7 3.14 7 7s-3.14 7-7 7-7-3.12-7-7 3.14-7 7-7z"></path></svg></span>note</div><div class="admonitionContent_BuS1"><p>This feature is currently behind the feature flag <code>HAR_CUSTOM_METADATA_ENABLED</code>. Contact Harness Support to enable it.</p></div></div>
<p>To learn more about how to use Harness Artifact Registry to store and manage artifacts with custom metadata, check out our <a href="https://developer.harness.io/docs/artifact-registry/metadate-registry" target="_blank" rel="noopener noreferrer" class="">Metadata Support for Artifacts and Registries</a></p>
<p><strong>Dart Registry Support</strong></p>
<p>Harness Artifact Registry now supports Dart packages with full pub.dev compatibility. You can store, manage, and distribute Dart packages directly within Harness, with complete support for versions, metadata, and immutable release behaviour.</p>
<p><strong>Key benefits:</strong></p>
<ul>
<li class=""><strong>Secure, private Dart registry</strong>: Provides a dedicated, secure registry for all your teams' Dart packages</li>
<li class=""><strong>Immutable versions</strong>: Ensures immutable package versions matching pub.dev behaviour for safe, predictable builds</li>
<li class=""><strong>Accelerated CI/CD</strong>: Speeds up builds by caching remote dependencies via upstream proxy, reducing external dependencies and improving reliability</li>
</ul>
<p>To learn more about how to use Harness Artifact Registry to store and manage Dart packages, check out our <a href="https://developer.harness.io/docs/artifact-registry/get-started/quickstart/#dart" target="_blank" rel="noopener noreferrer" class="">Dart Registry Quickstart guide</a>.</p>
<h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="enhancements--fixes-6">Enhancements &amp; Fixes<a href="#enhancements--fixes-6" class="hash-link" aria-label="Direct link to Enhancements &amp; Fixes" title="Direct link to Enhancements &amp; Fixes" translate="no">​</a></h4>
<p><strong>Download Button for Non-OCI Artifacts</strong></p>
<p>You can now directly download any non-OCI artifact (Maven, npm, PyPI, Generic, Conda, Helm charts, etc.) from the Artifact Registry UI with a single click.
Until now, retrieving individual files or packages required using CLI commands or configuring a package manager client. For many workflows: debugging, validation, quick inspections, and offline analysis, users simply want to grab the file instantly.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="202511v1">2025.11.v1<a href="#202511v1" class="hash-link" aria-label="Direct link to 2025.11.v1" title="Direct link to 2025.11.v1" translate="no">​</a></h3>
<h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="new-features-10">New Features<a href="#new-features-10" class="hash-link" aria-label="Direct link to New Features" title="Direct link to New Features" translate="no">​</a></h4>
<p><strong>Artifact Registry management via CLI</strong></p>
<p>We're thrilled to introduce comprehensive CLI support for Artifact Registry management through the new Harness CLI v1.0.0 (<code>hc</code>)! This powerful addition brings the full capabilities of Artifact Registry directly to your terminal, enabling seamless automation and developer-friendly workflows.</p>
<img class="DocImageWithBorder_Xort" src="/assets/images/reg-list-a8e9ea9b463e687e946827fd62e8095d.png" width="80%" alt="Registry List" title="Click to view full size image">
<p><strong>What's new:</strong></p>
<ul>
<li class=""><strong>Registry Management</strong>: List, view, and manage your registries with intuitive commands like <code>hc registry list</code> and <code>hc registry get</code></li>
<li class=""><strong>Artifact Operations</strong>: Push, pull, and list artifacts across all your registries using <code>hc artifact</code> commands</li>
<li class=""><strong>Developer-Friendly Aliases</strong>: Save time with short commands - use <code>hc reg</code> instead of <code>hc registry</code> and <code>hc art</code> instead of <code>hc artifact</code></li>
<li class=""><strong>Flexible Output Formats</strong>: Get results in JSON, YAML, or table format for easy parsing in scripts and automation pipelines</li>
<li class=""><strong>Cross-Project Support</strong>: Work seamlessly across multiple projects with global flags like <code>--project</code> and <code>--org</code></li>
</ul>
<p>Install the new Harness CLI v1.0.0 (<code>hc</code>) and authenticate to your account to start managing your registries and artifacts from the command line. Check out our <a href="https://developer.harness.io/docs/artifact-registry/artifact-registry-cli/manage-artifacts-registries" target="_blank" rel="noopener noreferrer" class="">CLI documentation</a> for detailed examples and best practices.</p>
<p><strong>Conda Registry Support</strong></p>
<p>We have added a new registry type, Conda Registry support, for Python and R package management.</p>
<p><strong>Key capabilities:</strong></p>
<ul>
<li class=""><strong>Native Conda client support</strong>: Works with <code>conda</code> and <code>mamba</code> out of the box</li>
<li class=""><strong>Bioconda upstream proxy</strong>: Automatically configured to fall back to Bioconda's public repository, giving you access to thousands of packages</li>
<li class=""><strong>Hybrid package management</strong>: Host your private packages while proxying public ones from Bioconda</li>
<li class=""><strong>Channel organization</strong>: Organize packages into channels for better version control and distribution</li>
</ul>
<p>Configure your Conda client to point to your Harness registry, and you're ready to go - private packages are served directly while public packages are fetched from Bioconda automatically (If some custom source is not configured).</p>
<p>Do refer to <a href="https://developer.harness.io/docs/artifact-registry/get-started/quickstart#conda" target="_blank" rel="noopener noreferrer" class="">Conda Registry Quickstart</a> for more details.</p>
<h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="enhancements--fixes-7">Enhancements &amp; Fixes<a href="#enhancements--fixes-7" class="hash-link" aria-label="Direct link to Enhancements &amp; Fixes" title="Direct link to Enhancements &amp; Fixes" translate="no">​</a></h4>
<p><strong>Upstream Proxy to aggregate multiple Artifact Registries</strong></p>
<p>We have enhanced our Artifact Registry experience by allowing it to be configured as an upstream proxy, enabling you to aggregate multiple registries into a single, unified access point. Use any Harness Artifact Registry as an upstream proxy for their respective registry.</p>
<p>When adding an Artifact Registry as an upstream proxy, ensure that registry doesn't have its own upstream proxies configured to avoid circular dependencies.</p>
<div class="theme-admonition theme-admonition-note admonition_xJq3 alert alert--secondary"><div class="admonitionHeading_Gvgb"><span class="admonitionIcon_Rf37"><svg viewBox="0 0 14 16"><path fill-rule="evenodd" d="M6.3 5.69a.942.942 0 0 1-.28-.7c0-.28.09-.52.28-.7.19-.18.42-.28.7-.28.28 0 .52.09.7.28.18.19.28.42.28.7 0 .28-.09.52-.28.7a1 1 0 0 1-.7.3c-.28 0-.52-.11-.7-.3zM8 7.99c-.02-.25-.11-.48-.31-.69-.2-.19-.42-.3-.69-.31H6c-.27.02-.48.13-.69.31-.2.2-.3.44-.31.69h1v3c.02.27.11.5.31.69.2.2.42.31.69.31h1c.27 0 .48-.11.69-.31.2-.19.3-.42.31-.69H8V7.98v.01zM7 2.3c-3.14 0-5.7 2.54-5.7 5.68 0 3.14 2.56 5.7 5.7 5.7s5.7-2.55 5.7-5.7c0-3.15-2.56-5.69-5.7-5.69v.01zM7 .98c3.86 0 7 3.14 7 7s-3.14 7-7 7-7-3.12-7-7 3.14-7 7-7z"></path></svg></span>note</div><div class="admonitionContent_BuS1"><p>This feature is currently behind the feature flag <code>HAR_SUPPORT_LOCAL_REGISTRY_AS_UPSTREAM_PROXY</code>. Contact Harness Support to enable it.</p></div></div>
<p>To know more about <a class="" href="/docs/artifact-registry/manage-registries/configure-registry#set-proxy-for-registry">Set Proxy for Registry</a></p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="october-2025">October 2025<a href="#october-2025" class="hash-link" aria-label="Direct link to October 2025" title="Direct link to October 2025" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="202510v1">2025.10.v1<a href="#202510v1" class="hash-link" aria-label="Direct link to 2025.10.v1" title="Direct link to 2025.10.v1" translate="no">​</a></h3>
<h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="enhancements-and-fixes">Enhancements and Fixes<a href="#enhancements-and-fixes" class="hash-link" aria-label="Direct link to Enhancements and Fixes" title="Direct link to Enhancements and Fixes" translate="no">​</a></h4>
<p><strong>Public Registry</strong></p>
<p>Users can now define the visibility of an artifact registry as <strong>Private</strong> or <strong>Public</strong>. This enhancement allows better control over access to registry contents and image pulls.</p>
<blockquote>
<p>By default, all registries are created as <strong>Private</strong>.</p>
</blockquote>
<ul>
<li class=""><strong>Public registries</strong> make the registry contents and images accessible to all users external to your organization.</li>
<li class=""><strong>Private registries</strong> restrict both visibility and image pulls to authorized users or service accounts with valid permissions or tokens.</li>
</ul>
<div class="theme-admonition theme-admonition-note admonition_xJq3 alert alert--secondary"><div class="admonitionHeading_Gvgb"><span class="admonitionIcon_Rf37"><svg viewBox="0 0 14 16"><path fill-rule="evenodd" d="M6.3 5.69a.942.942 0 0 1-.28-.7c0-.28.09-.52.28-.7.19-.18.42-.28.7-.28.28 0 .52.09.7.28.18.19.28.42.28.7 0 .28-.09.52-.28.7a1 1 0 0 1-.7.3c-.28 0-.52-.11-.7-.3zM8 7.99c-.02-.25-.11-.48-.31-.69-.2-.19-.42-.3-.69-.31H6c-.27.02-.48.13-.69.31-.2.2-.3.44-.31.69h1v3c.02.27.11.5.31.69.2.2.42.31.69.31h1c.27 0 .48-.11.69-.31.2-.19.3-.42.31-.69H8V7.98v.01zM7 2.3c-3.14 0-5.7 2.54-5.7 5.68 0 3.14 2.56 5.7 5.7 5.7s5.7-2.55 5.7-5.7c0-3.15-2.56-5.69-5.7-5.69v.01zM7 .98c3.86 0 7 3.14 7 7s-3.14 7-7 7-7-3.12-7-7 3.14-7 7-7z"></path></svg></span>note</div><div class="admonitionContent_BuS1"><p>To enable public artifact registries, the feature flag <strong><code>PL_ALLOW_TO_SET_PUBLIC_ACCESS</code></strong> must be activated. Contact <strong>Harness Support</strong> to enable it. After activation, navigate to <strong>Account Settings &gt; Authentication</strong> and enable <strong>Allow public resources</strong> to make your registry publicly accessible.</p></div></div>
<img class="DocImageWithBorder_Xort" src="/assets/images/public-registry-6ab6304b00b3d7aea75488b10d50f00d.png" width="80%" alt="Public Registry" title="Click to view full size image">
<p>Check out our documentation to know more about <a href="https://developer.harness.io/docs/artifact-registry/manage-registries/create-registry" target="_blank" rel="noopener noreferrer" class="">Creating an Artifact Registry</a></p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="september-2025">September 2025<a href="#september-2025" class="hash-link" aria-label="Direct link to September 2025" title="Direct link to September 2025" translate="no">​</a></h2>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="202509v2">2025.09.v2<a href="#202509v2" class="hash-link" aria-label="Direct link to 2025.09.v2" title="Direct link to 2025.09.v2" translate="no">​</a></h3>
<h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="new-features-11">New Features<a href="#new-features-11" class="hash-link" aria-label="Direct link to New Features" title="Direct link to New Features" translate="no">​</a></h4>
<p><strong>Artifact Quarantine</strong></p>
<p>Protect your software supply chain with <strong>Artifact Quarantine</strong>! You can now quarantine artifacts to prevent them from being used in pipelines or pulled by users. This powerful security feature works hand-in-hand with built-in container scanning and policy enforcement.</p>
<img class="DocImageWithBorder_Xort" src="/assets/images/quarantine-59b1782b527655ea6e878a2342d67864.png" width="80%" alt="Artifact Quarantine" title="Click to view full size image">
<p><strong>Key Capabilities:</strong></p>
<ul>
<li class=""><strong>Manual Quarantine</strong>: Quarantine any artifact with a documented reason via the 3-dot menu</li>
<li class=""><strong>Automated Quarantine</strong>: When integrated with Harness Supply Chain Security, artifacts are automatically scanned using AquaTrivy, and Security Tests policy sets can automatically quarantine artifacts based on vulnerability severity</li>
<li class=""><strong>Easy Management</strong>: Remove artifacts from quarantine when they're safe to use again</li>
</ul>
<p>This feature is available for Docker and Helm registries and provides an essential layer of protection to ensure only secure, compliant artifacts make it into your production environments.</p>
<div class="theme-admonition theme-admonition-note admonition_xJq3 alert alert--secondary"><div class="admonitionHeading_Gvgb"><span class="admonitionIcon_Rf37"><svg viewBox="0 0 14 16"><path fill-rule="evenodd" d="M6.3 5.69a.942.942 0 0 1-.28-.7c0-.28.09-.52.28-.7.19-.18.42-.28.7-.28.28 0 .52.09.7.28.18.19.28.42.28.7 0 .28-.09.52-.28.7a1 1 0 0 1-.7.3c-.28 0-.52-.11-.7-.3zM8 7.99c-.02-.25-.11-.48-.31-.69-.2-.19-.42-.3-.69-.31H6c-.27.02-.48.13-.69.31-.2.2-.3.44-.31.69h1v3c.02.27.11.5.31.69.2.2.42.31.69.31h1c.27 0 .48-.11.69-.31.2-.19.3-.42.31-.69H8V7.98v.01zM7 2.3c-3.14 0-5.7 2.54-5.7 5.68 0 3.14 2.56 5.7 5.7 5.7s5.7-2.55 5.7-5.7c0-3.15-2.56-5.69-5.7-5.69v.01zM7 .98c3.86 0 7 3.14 7 7s-3.14 7-7 7-7-3.12-7-7 3.14-7 7-7z"></path></svg></span>note</div><div class="admonitionContent_BuS1"><p>This feature requires the feature flag <strong><code>HAR_ARTIFACT_QUARANTINE_ENABLED</code></strong>. Contact Harness Support to enable it.</p></div></div>
<p>Learn more: <a href="https://developer.harness.io/docs/artifact-registry/manage-artifacts/artifact-management#quarantine-an-artifact" target="_blank" rel="noopener noreferrer" class="">Artifact Quarantine</a></p>
<p><strong>Digest Viewing / Image Referencing</strong></p>
<p>Harness Artifact Registry now provides complete visibility into all your container images with <strong>digest-based viewing</strong> and flexible <strong>tag selection</strong>, giving you more control over how you reference and manage images.</p>
<img class="DocImageWithBorder_Xort" src="/assets/images/untagged-242fb34dce30e597ba32fd27ae32aef8.png" width="80%" alt="Untagged Images" title="Click to view full size image">
<p><strong>Untagged Images Made Visible</strong>:
Images without tags now appear clearly in the UI with an <strong>“N/A”</strong> label next to their digest. They remain fully pullable via their digest, so even untagged or cleaned-up images are easy to track and verify. Multi-architecture Docker and OCI images are also grouped neatly by platform, making navigation effortless.</p>
<p><strong>Flexible Tag and Digest Selection</strong>:
You can now select a <strong>tag or version</strong> for all artifact types directly from the header selector. For Docker and OCI images, you can also select by <strong>digest</strong> to reference an immutable version.</p>
<ul>
<li class=""><strong>Use Tags</strong> to browse familiar labels such as <code>latest</code> or <code>1.25.2</code>.</li>
<li class=""><strong>Use Digests</strong> to pinpoint a specific, unchanging image for verification or debugging.</li>
</ul>
<blockquote>
<p>Deployment details appear only when a tag is selected.</p>
</blockquote>
<p>This enhancement offers a clearer, more dependable way to browse, reference, and inspect your images—whether tagged, untagged, or multi-architecture.</p>
<p>Learn more: <a href="https://developer.harness.io/docs/artifact-registry/manage-artifacts/artifact-details#selecting-by-tag" target="_blank" rel="noopener noreferrer" class="">Selecting by Tag</a> | <a href="https://developer.harness.io/docs/artifact-registry/manage-artifacts/find-artifacts#image-referencing" target="_blank" rel="noopener noreferrer" class="">Image Referencing</a></p>
<h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="enhancements-and-fixes-1">Enhancements and Fixes<a href="#enhancements-and-fixes-1" class="hash-link" aria-label="Direct link to Enhancements and Fixes" title="Direct link to Enhancements and Fixes" translate="no">​</a></h4>
<p><strong>NuGet Visual Studio Integration</strong></p>
<p>We're excited to provide <strong>Visual Studio integration</strong> for NuGet package management! .NET developers can now configure Harness Artifact Registry as a package source directly within Visual Studio, enabling native IDE integration with secure token-based authentication.</p>
<p>Configure your registry in Visual Studio and start pulling packages from Harness registries with ease.</p>
<p>Learn more: <a href="https://developer.harness.io/docs/artifact-registry/get-started/quickstart/#nuget--install-and-use-nuget-packages" target="_blank" rel="noopener noreferrer" class="">Install and Use NuGet Packages</a></p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="202509v1">2025.09.v1<a href="#202509v1" class="hash-link" aria-label="Direct link to 2025.09.v1" title="Direct link to 2025.09.v1" translate="no">​</a></h3>
<h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="enhancements-and-fixes-2">Enhancements and Fixes<a href="#enhancements-and-fixes-2" class="hash-link" aria-label="Direct link to Enhancements and Fixes" title="Direct link to Enhancements and Fixes" translate="no">​</a></h4>
<ul>
<li class="">
<p><strong>Delete Version API</strong>: Improved error handling for invalid non-OCI versions. Instead of returning a confusing <strong>500 Internal Server Error</strong>, the API now responds with a clear <strong>404 Not Found</strong>. This makes debugging easier and ensures a more consistent developer experience. <em>[AH-1302]</em></p>
</li>
<li class="">
<p><strong>List Versions API</strong>: Fixed an issue where requests for unavailable images incorrectly triggered a <strong>500 Internal Server Error</strong>. The API now returns a proper <strong>404 Not Found</strong>, giving developers accurate feedback and reducing troubleshooting time. <em>[AH-1829]</em></p>
</li>
</ul>]]></content:encoded>
        </item>
    </channel>
</rss>