[Danny Berger](https://dpb587.me/ "Home")

# Metalink

CLI tools and library for using the XML-based specification for assets.

I created this after researching ways to record checksums and mirrors of files and finding an RFC about it. I used this in several private projects, and it also ended up being adopted by the [Cloud Foundry BOSH website](https://bosh.io/) for its `git`-backed database of [releases](https://github.com/bosh-io/releases-index) and [stemcells](https://github.com/bosh-io/stemcells-core-index). I also ended up creating a Concourse resource type for it.

# 2019

- [**Metalink Repositories: Stability Channels** Consistently representing both internal and external dependencies.](https://dpb587.me/entries/metalink-repositories-separation-of-concerns-20190123)

# 2018

- [**Metalink Repositories: Mirroring Third-Party Dependencies** Using metalink repositories to track upstream artifacts.](https://dpb587.me/entries/metalink-repositories-mirroring-third-party-dependencies-20181230)
- [**Metalink Repositories: Background and Motivation** Some "whys" of this alternative way to track artifacts.](https://dpb587.me/entries/metalink-repositories-background-and-motivation-20181228)
- [**Watching Upstream Binaries with Concourse** Unifying how pipelines monitor third-party assets and versions.](https://dpb587.me/entries/watching-upstream-binaries-with-concourse-20181202)

# 2017

- [**Documenting Blobs with Metalink Files** A general format for documenting checksums, signatures, and origins of blobs.](https://dpb587.me/entries/documenting-blobs-with-metalink-files-20171009)

## Related

Topics

[bosh](https://dpb587.me/topics/bosh/) · [Go](https://dpb587.me/topics/golang/) · [xml](https://dpb587.me/topics/xml/)

Copyright © 2026 // [dpb587.me](https://dpb587.me/) is a [personal](https://dpb587.me/projects/website), [open source](https://github.com/dpb587/dpb587.me/blob/main/content/topic/metalink/_index.md) site.
