OCI Distribution registry resolver, including self-hosted Forgejo registries.
Sites use {:oci, "forgejo.example.com/<owner>[/<path>]"}. HTTPS is the
default; an explicit http:// prefix supports local development registries.
Basic and same-origin Bearer token authentication are supported. Project
credentials come from NBPR_REGISTRY_USERNAME and NBPR_REGISTRY_TOKEN.