The official discovery directory for software sold straight from the source. Every listing is a signed manifest, checked against the official Ed25519 key — what you see is exactly what the developer shipped.
/ discovery
Developers opt in by shipping a manifest. We crawl, verify and list — the seller's own storefront always closes the sale.
/ trust
Listing CI verifies every PR fail-closed — schema, repository identity, release, signature, license, the live /sell page, the seller Payment Link, discovery pricing, duplicates and security.
Fail closed
Anything invalid blocks the PR. Nothing is "approved by hand".
$ listing-ci verify # 12/12 or BLOCKEDSeller link verified-only
The listing checks the seller's Payment Link. It never creates or touches it.
verify /sell → match or BLOCKEDImmutable records
Old discovery links stay valid forever. History is verifiable.
v1.0 → link A foreverTwo transactions
Discovery pays reposell. Software pays the seller. Never mixed.
discovery ≠ purchase/ sellers
If your repository already has a /sell endpoint, listing is one command and one PR.
step 1 — from your repo
$ reposell listing publish v1.2.0Builds the PR payload, health-checks your live /sell, writes .reposell/listing-pr.json.
step 2 — open the PR
listing PR → CI verify → mergeCI re-verifies everything independently. PASS merges; BLOCKED explains why.