# Best practices for archival of external packages

**URL:** <https://community.sonatype.com/t/best-practices-for-archival-of-external-packages/2704>\
**Category:** Best Practices\
**Created:** [October 16, 2019, 3:39pm UTC](https://community.sonatype.com/t/best-practices-for-archival-of-external-packages/2704 "2019-10-16T15:39:09Z")\
**Posts on this page:** 1\
**Showing post:** 1

<div class="post-metadata">

**Author:** ![joja.public](https://avatars.discourse-cdn.com/v4/letter/j/87869e/32.png) [@joja.public](https://community.sonatype.com/u/joja.public)\
**Post date:** [October 16, 2019, 3:39pm UTC](https://community.sonatype.com/t/best-practices-for-archival-of-external-packages/2704/1 "2019-10-16T15:39:09Z")

</div>

Hello,  
I need to ensure that I have always access to packages@version that are used in product releases. As far as I can see I have two options:

1. proxy the public repo  
pros: simple to setup, updates automatically as soon as fetching some public package  
cons: accumulation of packages that have not really been used, maybe only in test and studies, impossible to clean them up separately from the ones that I need to preserve (for eternity)

2. duplicate public packges in private repo  
pros: be sure to only have the packges that are really used in production releases  
cons: a tedious job to do keep up to date (at least manually), possible duplicate packages in private and proxy repo

How others are handling this? Are there some best practices?

Thanks for any advice.

Joja

---

_[View the full topic](https://community.sonatype.com/t/best-practices-for-archival-of-external-packages/2704)._
