Inventory.
One inventory across your Windows package managers.
Currently in development — early-access slots available.
What's broken without it.
Today, asking "what is installed across our fleet?" requires reconciling outputs from winget, Chocolatey, Scoop, npm, pip, .NET tools, PSGallery, and the registry. Each tool has its own version conventions, identity model, and gaps. Inventory drift goes unnoticed for months, and the picture you give the auditor is always at least 24 hours stale.
The approach.
Attestree Inventory brings your Windows package managers into a single inventory — winget and Chocolatey managed today, Scoop inventoried (its deployment stays off until an operator populates the trusted-bucket allowlist), with npm, pip, .NET, and PSGallery on the roadmap. Software that arrived outside any package manager shows up too, from the uninstall entries the endpoint reports. Per-user installs are attributed to the user who has them — with last-seen staleness — instead of dissolving into a machine-level row. The fleet view is live in the console; an inventory export is not built yet. Beyond inventory, Chocolatey is now managed the way you already manage winget — subscribe, ring-deploy, converge — while rollback and uninstall for Chocolatey are still being finished, and detonation-backed attestation for choco packages is the next slice.
Roadmap, in three moves.
Canonical artifact IDs
Stable identity across winget, Choco, Scoop, npm, pip — no more reconciliation joins.
Live fleet query
GraphQL-style API for "show me every machine running X version Y or older."
Drift alarms
Automatic alerts when a fleet diverges from its declared desired-state manifest.
Ready for inventory on your fleet?
Early-access slots are open through GA. Tell us about your fleet.