content-addressed SCM

Browse every mirrored repo, by content.

Depot is a read-only window on truss — the content-addressed SCM the rest of the platform builds on. Every mirrored repo, ref, commit, tree, and blob is named by its content hash, so the history you're looking at can't be quietly rewritten underneath you.

available
Mirrored repos, branches/tags, history, file treesEvery object named by its BLAKE3 content hashMirror-sync activity, liveFour read-only agent tools over the depotA window on the platform's SCM substrate — never a write path
content-addressed
every object by its hash
BLAKE3, deduped
read-only
a window, not a write path
the platform's SCM substrate
4
agent-callable tools
list_repos · list_refs · log · browse
mirrored
every forge repo, one depot
refs/mirror/<host>/<org>/<repo>
why it's different

The same substrate the platform builds on.

Depot doesn't wrap a forge API — it reads truss, the content-addressed depot that mirrors every repo and that code search and the rest of the platform already run on.

In truss, every entity — a chunk, an object, a tree, a commit — is named by the digest of its content (BLAKE3, so identical content is stored once). A commit is its hash; a tree's digest is a function of its sorted entries. That makes history tamper-evident: you can't rewrite the past without changing every digest that points at it. Depot is the human window on that — it dials trussd read-only and composes the views you expect: repositories, refs, first-parent history, and file trees. It owns no data and degrades to empty panels if the depot is unreachable.

Every commit, tree, and blob is named by its content hash. History you can't quietly rewrite.

plugin-depot · truss is content-addressed, day one
the console

Every mirrored repo, in one depot.

The Repositories panel groups the depot's refs/mirror/* refs back into repos — with branch and tag counts and the tip commit. Values illustrative.

Repositories
depot.v1.DepotExplorer · ListRepos
orgrepositorybranchestagstip
tomato-bazel truss 2 1 a1b2c3d4e5f6
tomato-bazel rules_lora 3 4 9f8e7d6c5b4a
fastverk botnoc 8 12 0123456789ab
row → : Branches & tags · Files · Historyshort sha: first 12 hex of the BLAKE3 digest
how it's addressed

Commits, trees, and blobs — by digest.

Truss's content-addressed model is what makes the history trustworthy. Depot surfaces it directly.

truss object model
content-addressed · BLAKE3
objectaddressed bynote
commit Digest(BLAKE3) tree + parents + a jj ChangeId (durable identity)
tree Digest(BLAKE3) sorted entries → one canonical digest
object / blob Digest(BLAKE3) content-defined chunks, deduped across repos
ref → commit Digest refs/mirror/<host>/<org>/<repo>/<kind>/<name>
interop: SHA-256 for migration; BLAKE3 by default
the mirror

Watch the depot fill.

The Sync activity panel shows recent events from the mirror receiver — which ref moved, whether it succeeded, and how many objects transferred. Values illustrative.

Sync activity
depot.v1.DepotExplorer · ListSyncActivity
repositoryrefeventresultobjects
tomato-bazel/truss refs/heads/main PUSH OK 142
fastverk/botnoc refs/tags/v0.9.3 CREATE OK 6
tomato-bazel/rules_lora refs/heads/main PUSH SKIPPED 0
source: the truss mirror-serve receiver
the payoff

Why the depot is content-addressed.

Not a detail — the reason the platform trusts what it builds from.

Four properties, for free

  • Tamper-evident history: a commit is its own hash, so the past can't be rewritten without changing every digest that references it.
  • Deduplication by construction: identical content is stored once via content-defined chunking — across every mirrored repo.
  • One substrate: the same depot backs forge-wide code search and the rest of the platform; depot is just the human window on it.
  • Read-only by design: depot reads a shared internal depot — there's no token to forward and nothing it can mutate.

Depot is a read-only window. It shows you the depot the platform already runs on — it never changes it.

plugin-depot · owns no data

source · github.com/fastverk/plugin-depot · tools: list_repos, list_refs, log, browse

Prove it's safe to merge.

depot is one of 14 plugins in the fastverk console — hosted, or in your own cloud.