Catalyst Package Manager - Version 2.0 Release notes
Building on the UI-driven sign-up flow introduced in the previous release, CPM now enables users to publish and manage public packages directly through the UI. Users can manage their published packages in a dedicated My Packages section and explore all public packages in the Marketplace, with clear visibility into package details, versions, and available actions. This unified experience allows users to efficiently manage, share, and monitor their software artifacts.
What’s new
-
My Packages – – In addition to the existing Marketplace, My Packages provides a personal workspace where users can view and manage all packages they have published. This section serves as the central hub for a user’s package lifecycle, giving quick access to management actions such as viewing package metadata, creating new versions, or removing packages. The Marketplace remains a comprehensive catalog of all published public packages, allowing users to explore packages shared by other users or teams, search, filter by type or status, sort, and download public packages, with full visibility into package details and versioning, giving users confidence in selecting and using the right packages for their needs.
-
Publish New Public Package - Users can now create and publish new public packages through the CPM UI, an improvement over the previous CLI-only workflow. Users are guided to provide all required information, including application name, description, version, type, and Artifactory links. This workflow ensures packages are consistently documented, discoverable, and ready for distribution in the Marketplace.
-
Publish New Public Package Guide: See here
-
-
Public Package Management – A set of actions for managing existing packages, including editing package details, downloading packages, or removing them from My Packages and, by extension, the Marketplace. This functionality gives users control over package content, access, and lifecycle while maintaining a clear and auditable record of all changes.
-
Public Package Management Guide: See here
-
-
Package Versioning – The ability to create new versions of existing packages while keeping previous versions intact and accessible. Users can update package content, metadata, and links for new releases without affecting older versions, ensuring continuity and traceability across the lifecycle of the package.
-
Package Versioning Management Guide: See here
-
-
Package Version History – A dedicated view that lists all versions of a package, showing details such as version number, type, and associated metadata. Users can review previous versions, manage version-level actions (edit, download, delete), and maintain a clear history of package evolution. This view supports governance, auditing, and informed decision-making when updating or using packages.
-
Package Version History Guide: See here
-
Coming soon
The CPM 2.1 release will introduce several key enhancements aimed at increasing control, governance, and flexibility for users managing software packages. This release will bring support for private packages with full access management, enhanced package auditing capabilities, and the option to host DAR files directly within CPM or via external links. These features give users more control over package distribution, secure access, and compliance while streamlining workflows for both publishers and consumers.
-
Private Packages & Access Management – Users will be able to publish packages privately, restricting visibility and download access to authorized individuals. The system will provide a dedicated workflow for managing access, allowing package owners to review incoming access requests, approve or deny requests, and maintain a clear record of who has access. This will ensure that sensitive or internal packages are securely managed while still enabling controlled collaboration.
-
Requesting Access – For packages marked as private, users without access will be able to submit a request for approval through the Marketplace. The request will be sent to the package publisher, who can review the requester’s Party ID and grant or deny access. This process will ensure that private packages remain secure while providing a clear and auditable mechanism for users to request access.
-
Auditing – Users will be able to request an audit of their packages to ensure compliance, correctness, or verification of package contents. Designated auditors will be able to perform the review, and the results will be linked to the package and made visible in CPM. This feature will support governance, accountability, and traceability, allowing teams to maintain confidence in the quality and compliance of published packages.
-
DAR Files Artifactory Hosting – CPM 2.1 will provide flexibility in how DAR files are stored and distributed. Users will have an option of choosing to host the file directly within CPM, ensuring it is fully managed and secured by the platform, or provide an artifactory hosting link if preferred. This option will allow teams to maintain existing infrastructure practices while benefiting from CPM’s management and distribution features.