nuget.org
nuget.org, also known as the "Gallery", is the de facto feed for public .NET packages. Publish the packages of your open-source projects there.
The Gallery is battle-tested and proven to scale well. You can host your own instance by following the Gallery's wiki. Its code is spread across several repositories:
- NuGet/NuGetGallery: the nuget.org website and v2 APIs
- NuGet/NuGet.Jobs: background jobs for things like validation and package statistics
- NuGet/NuGet.Services.Metadata: NuGet's v3 implementation
- NuGet/ServerCommon: libraries shared across NuGet's services
As you can tell, nuget.org is a complex system. Hosting your own instance of the Gallery is not for the faint of heart.
PaGetto vs nuget.org​
PaGetto mainly competes with nuget.org's v3 implementation (NuGet/NuGet.Services.Metadata).
| PaGetto | nuget.org | |
|---|---|---|
| Audience | Private and internal packages | Public, open-source packages |
| Hosting your own | A single service: Docker, Kubernetes (Helm), IIS, any ASP.NET Core 10 host | Many services and jobs, tied to Windows and Azure |
| v3 implementation | Dynamic: each request is answered by querying a database | Static: JSON files generated by jobs (feed2catalog, catalog2registration, catalog2dnx, catalog2lucene), stored in Azure Blob Storage and served through a CDN |
| Platforms | Cross-platform (Linux, Windows, macOS; amd64 and arm64 images) | Windows |
| Read scaling | Limited by the database and the number of replicas | Scales reads to near infinity through the CDN |
| Write latency | A pushed package is available right away | A pushed package goes through validation and jobs before it is listed |
| Package validation | Basic checks on push | Signing, malware scanning, reserved ID prefixes and more |
| Access control | Private feeds with per-feed pull, push and delete permissions | Public reads, owner-based pushes |
| Several feeds | Yes | No |
| Mirroring | Can mirror nuget.org into a local feed | Not applicable |
| Adding features | Easy: one codebase, one process | Hard: changes span several services |
Which one to pick​
- Publish open-source packages to nuget.org.
- Use PaGetto for internal packages, and as a mirror of nuget.org so restores stay fast and keep working when nuget.org is unreachable. See Import nuget.org packages.