Browse every mirrored repo, by content.
Depot is a read-only window on truss — the content-addressed SCM the rest of the platform builds on. Every mirrored repo, ref, commit, tree, and blob is named by its content hash, so the history you're looking at can't be quietly rewritten underneath you.
The same substrate the platform builds on.
Depot doesn't wrap a forge API — it reads truss, the content-addressed depot that mirrors every repo and that code search and the rest of the platform already run on.
In truss, every entity — a chunk, an object, a tree, a commit — is named by the digest of its content (BLAKE3, so identical content is stored once). A commit is its hash; a tree's digest is a function of its sorted entries. That makes history tamper-evident: you can't rewrite the past without changing every digest that points at it. Depot is the human window on that — it dials trussd read-only and composes the views you expect: repositories, refs, first-parent history, and file trees. It owns no data and degrades to empty panels if the depot is unreachable.
Every commit, tree, and blob is named by its content hash. History you can't quietly rewrite.
Every mirrored repo, in one depot.
The Repositories panel groups the depot's refs/mirror/* refs back into repos — with branch and tag counts and the tip commit. Values illustrative.
| org | repository | branches | tags | tip |
|---|---|---|---|---|
| tomato-bazel | truss | 2 | 1 | a1b2c3d4e5f6 |
| tomato-bazel | rules_lora | 3 | 4 | 9f8e7d6c5b4a |
| fastverk | botnoc | 8 | 12 | 0123456789ab |
Commits, trees, and blobs — by digest.
Truss's content-addressed model is what makes the history trustworthy. Depot surfaces it directly.
| object | addressed by | note |
|---|---|---|
| commit | Digest(BLAKE3) | tree + parents + a jj ChangeId (durable identity) |
| tree | Digest(BLAKE3) | sorted entries → one canonical digest |
| object / blob | Digest(BLAKE3) | content-defined chunks, deduped across repos |
| ref | → commit Digest | refs/mirror/<host>/<org>/<repo>/<kind>/<name> |
Watch the depot fill.
The Sync activity panel shows recent events from the mirror receiver — which ref moved, whether it succeeded, and how many objects transferred. Values illustrative.
| repository | ref | event | result | objects |
|---|---|---|---|---|
| tomato-bazel/truss | refs/heads/main | PUSH | OK | 142 |
| fastverk/botnoc | refs/tags/v0.9.3 | CREATE | OK | 6 |
| tomato-bazel/rules_lora | refs/heads/main | PUSH | SKIPPED | 0 |
Why the depot is content-addressed.
Not a detail — the reason the platform trusts what it builds from.
Four properties, for free
- Tamper-evident history: a commit is its own hash, so the past can't be rewritten without changing every digest that references it.
- Deduplication by construction: identical content is stored once via content-defined chunking — across every mirrored repo.
- One substrate: the same depot backs forge-wide code search and the rest of the platform; depot is just the human window on it.
- Read-only by design: depot reads a shared internal depot — there's no token to forward and nothing it can mutate.
Depot is a read-only window. It shows you the depot the platform already runs on — it never changes it.
source · github.com/fastverk/plugin-depot · tools: list_repos, list_refs, log, browse
Prove it's safe to merge.
depot is one of 14 plugins in the fastverk console — hosted, or in your own cloud.