generated: '2026-09-04' method: searched source: >- https://github.com/artifacthub/hub (docs/cli.md, charts/artifact-hub, widget/), https://artifacthub.github.io/helm-charts/index.yaml, https://proxy.golang.org/github.com/artifacthub/hub/@latest, https://raw.githubusercontent.com/artifacthub/homebrew-cmd/master/ah.rb, https://raw.githubusercontent.com/artifacthub/scoop-cmd/master/ah.json, https://hub.docker.com/v2/repositories/artifacthub/{hub,ah}/tags provider: Artifact Hub providerId: artifact-hub description: >- First-party distribution artifacts published by the Artifact Hub project. NOTE THE SHAPE OF THIS SURFACE: Artifact Hub publishes NO client SDK for its REST API in any language registry — no npm, PyPI, Maven, NuGet, RubyGems, Packagist or crates.io package wraps https://artifacthub.io/api/v1. Everything below distributes the SERVER (a self-hostable Helm chart and container images), the first-party `ah` CLI, or the embeddable web widget. Consumers of the hosted API call it directly over HTTP. Registries were queried unauthenticated on 2026-09-04 and the version/published values are read from that metadata. sdk_summary: first_party_api_client_sdks: 0 first_party_distribution_packages: 6 note: >- Searched npm (registry.npmjs.org), PyPI, pkg.go.dev/proxy.golang.org, RubyGems, crates.io, NuGet, Maven Central and the provider docs for an Artifact Hub REST API client library. The repository's own package.json files (web/, widget/) are marked "private": true and are not published. No first-party client SDK exists. packages: - name: artifact-hub registry: helm official: true kind: server-chart url: https://artifacthub.io/packages/helm/artifact-hub/artifact-hub repository: https://artifacthub.github.io/helm-charts install: helm repo add artifact-hub https://artifacthub.github.io/helm-charts && helm install artifact-hub artifact-hub/artifact-hub version: 1.23.0 published: '2026-07-07' app_version: 1.23.0 note: >- Official Helm chart for self-hosting Artifact Hub. Read from the provider's own chart index (https://artifacthub.github.io/helm-charts/index.yaml, entry created 2026-07-07T14:55:48Z). This is also the project's declared distribution point in SECURITY-INSIGHTS.yml. - name: github.com/artifacthub/hub registry: go official: true kind: source-module url: https://pkg.go.dev/github.com/artifacthub/hub install: go install github.com/artifacthub/hub/cmd/ah@latest version: v1.23.0 published: '2026-07-07' note: >- Go module for the whole project (hub, ah, scanner, tracker commands). Version read from https://proxy.golang.org/github.com/artifacthub/hub/@latest (tag refs/tags/v1.23.0, 2026-07-07T13:29:15Z). It is the server/CLI source, not an API client library. - name: ah registry: homebrew official: true kind: cli url: https://github.com/artifacthub/homebrew-cmd install: brew install artifacthub/cmd/ah version: 1.22.0 published: '2025-10-21' note: >- STALE RELATIVE TO THE PROJECT. The Homebrew tap formula (generated by GoReleaser) still pins 1.22.0 while the project, the Helm chart, the Scoop manifest and the container images are all at 1.23.0 (2026-07-07). macOS users installing via brew get a CLI one minor release behind. published is the 1.22.0 release date. - name: ah registry: scoop official: true kind: cli url: https://github.com/artifacthub/scoop-cmd install: scoop bucket add artifacthub https://github.com/artifacthub/scoop-cmd.git && scoop install artifacthub/ah version: 1.23.0 published: '2026-07-07' note: Windows manifest, current with the 1.23.0 release. - name: artifacthub/ah registry: dockerhub official: true kind: cli-image url: https://hub.docker.com/r/artifacthub/ah/tags install: docker run --rm -i artifacthub/ah:v1.23.0 version: v1.23.0 published: '2026-07-07' note: Container distribution of the ah CLI. Tag v1.23.0 pushed 2026-07-07T14:53:56Z. - name: artifacthub/hub registry: dockerhub official: true kind: server-image url: https://hub.docker.com/r/artifacthub/hub/tags version: v1.23.0 published: '2026-07-07' note: Container image for the hub server component. Tag v1.23.0 pushed 2026-07-07T14:52:43Z. - name: artifacthub-widget.js registry: cdn official: true kind: browser-widget url: https://artifacthub.io/artifacthub-widget.js version: null published: null note: >- UNPINNED DISTRIBUTION. The embed code the provider publishes (docs/embedding_artifacts.md) loads the widget from a bare, unversioned URL (