Welcome to the Inedo Forums! Check out the Forums Guide for help getting started.

If you are experiencing any issues with the forum software, please visit the Contact Form on our website and let us know!

  • Request new API

    2
    2 Posts
    2 Views
    stevedennisS
    Hi @bobmaurer , Thanks for the inquiry! Hope you don't mind a little push back on this -- but we'd encourage your security team to read our Vulnerability Management Done Right with ProGet. While we understand where they're coming from, the "weekly download" report is an anti-pattern these days and will lower the organization's security posture... which probably goes against their mission The main reason is that it improperly treats vulnerabilities as security incidents while providing no realistic path to mitigate them. This is backed by a huge body of research, including our own State of Software Supply Chain Security and reports from industry analysts. For example, they see "Joe Developer downloaded JsonLib 3.4.1, which has PGV-12345" -- what exactly are they going to do with that information? Contact Joe and ask him how he used it? Do they expect Joe to trace through 1000's of transitive dependencies across dozens of projects to see if he even knows where it's used? Tell him to uninstall it? Try to figure out if he caused damage? Or what application it was added to? Obviously not, because there will be so many packages with vulnerabilities that no one knows where they came from. The "best case" is to get aggregate data -- and ProGet already provides that, but by application/deployment state (which is what really matters). Anyway -- the best way to handle this is by implementing Software Composition Analysis in ProGet - we have all the tools to help Prepare for a Category 5 Vulnerability Thanks, Steve
  • Bug: RPM packages list wrong "latest" version

    1
    1
    1 Posts
    3 Views
    No one has replied
  • 5 Posts
    10 Views
    stevedennisS
    Hi @brandon_owensby_2976 , This is a generic forums system that we're using for public-facing support of a niche software product, so most of the features like voting/reputation don't really apply. Honestly I didn't even know those were features.... we recently upgraded the software, so maybe these were added? Anyway I just disabled them since we don't use them :) We have internal tracking for everything - either as a scheduled YouTrack ticket (which we link to) or a roadmap item (internal project tracking) that we periodically review and schedule as tickets. Thanks, Steve
  • Python packages; cannot determine Publish Date.

    1
    2
    1 Posts
    8 Views
    No one has replied
  • ProGet on Windows ignores intermediate CA certificate in PFX file

    4
    4 Posts
    10 Views
    stevedennisS
    Hi @clsa, If you're talking about the certificate errors under Admin > HTTPS, I wouldn't worry about those. An application does not need to validate its own certificate; it's only used to encrypt/decrypt the traffic. The server transmits a copy of the certificate (without the private key), and the client validates the certificate before transmitting data. Without getting into too many technical details, the only thing that really matters is if clients can connect to the application (ProGet) using HTTPS or not. There are a lot of reasons that may prevent the application from self-validation and it's not really worth trying to fix, since it's only used on that page to help catch basic errors. Thanks, Steve
  • How can i exclude npm packages from pgutil

    2
    2 Posts
    8 Views
    rhessingerR
    Hi @Valentijn, It looks like when we migrated pgscan in to pgutil, the functionality for this was removed. We will add a new flag to pgutil builds scan called --do-not-scan-npm that will ignore scanning for npm packages. I should have this released later this week or early next week. I will let you know as soon as we push the change. Thanks, Rich
  • 6 Posts
    19 Views
    rhessingerR
    Hi @carl.westman_8110, Always happy to help! I have actually already made the fix internally. If you would like, I can provide a pre-release build of ProGet 2026.13 that includes the fix. Thanks, Rich
  • 11 Posts
    27 Views
    B
    @stevedennis Thank you, I look forward to hearing back.
  • Using npm:Install with Image-based Services doesn't work

    3
    3 Posts
    4 Views
    B
    Thank you!!!
  • Feature Request: Allow IBS for DotNet::Test

    3
    3 Posts
    6 Views
    B
    Thank you!!
  • ProGet: Delete Asset History Files

    5
    5 Posts
    15 Views
    A
    Thanks @rhessinger!
  • 5 Posts
    28 Views
    I
    Hi @Nils-Nilsson, we were facing similar issue maybe 2 years ago (I am not even sure if pgutil was available at that time). There may be other approaches besides pgutil. ProGet exposes native APIs, but not all features are enabled by default; some aspects can be modified directly in the database. The native API is visible at: https://<ProgetServer>:<port>/reference/api FeedGroups APIs [image: 1791188466717-48fdf5f8-ccce-44da-b858-e625d4494986-image.jpeg] The Enabled features can be checked in the following table (we are using an MS SQL database): __StoredProcInfo Internal_Indicator shows what is exposed and can be used. We set Internal_Indicator = 'N' for the APIs (stored procedures) that we want to use for our automation purposes. Kind regards Ivan
  • 3 Posts
    29 Views
    N
    Hello @gdivis I've tested the new release and can verify that it now works as intended :) Best regards Nils Nilsson
  • Proget Installation as container with external Postgres

    proget-installa
    4
    1
    4 Posts
    26 Views
    rhessingerR
    Hi @hardik.turakhia, Using nginx as a reverse-proxy in front of ProGet is definitely the easiest way. I'm guessing you already took a look at our example nginx config file. When it comes to certificates, I find that it's easiest to use .pem files on Linux. There are a lot of guides out there on how to convert certificates to .pem files and configure them in nginx. The best source is to check with your SSL provider on how to create a fullchain (includes the intermediate certificates) .pem file. We do have some notes in the HTTPS on Windows guide in the update config section that has some commands on how to convert a .pfx file to .pem, which includes some crossover with converting .crt files to .pem files. If you are planning to use a dynamic SSL provider like Let's Encrypt, certbot has an extension called certbot-nginx on most distros or via snap on ubuntu/debian distros. That will configure nginx for you. Thanks, Rich
  • 14 Posts
    30 Views
    rhessingerR
    Hi @sai.pabbareddy, If you could pull a full LDAP trace/packate capture that would be great. I also setup a single-domain/single-dc. I can even share my setup as I used a VM and docker to set it up. My VM is a base alpine install with docker, docker-compose, and nano installed. Here is my the compose file I tested with. NOTE: my container uses the host network mode because that was the only way I could get it to bind the port in Samba. This is probably not needed if ProGet sat in the same Docker network as the Samba container. version: '3.8' services: samba-test-ad: image: diegogslomp/samba-ad-dc:latest container_name: samba_test_ad hostname: DC1 privileged: true network_mode: host environment: - REALM=PLANETEXPRESS.COM - DOMAIN=PLANETEXPRESS - ADMIN_PASS=GoodNewsEveryone123! - DNS_FORWARDER=8.8.8.8 # NOTE: "ports" was removed because network_mode: host opens the container ports on the host natively samba-provisioner: image: alpine:latest container_name: samba_provisioner depends_on: - samba-test-ad # Shares host network context to communicate with the main container smoothly network_mode: host volumes: - /var/run/docker.sock:/var/run/docker.sock entrypoint: - /bin/sh - -c - | apk add --no-cache docker-cli echo "🚀 Monitoring Active Directory operational readiness..." while true; do if docker exec samba_test_ad /usr/local/samba/bin/samba-tool user list >/dev/null 2>&1; then break fi echo "⏳ Samba is compiling directory tree schema... checking back in 3s" sleep 3 done echo "🔌 Active Directory Engine Online and Accepting Modifications!" echo "--- Creating Test Groups ---" docker exec samba_test_ad /usr/local/samba/bin/samba-tool group add ship_crew || true docker exec samba_test_ad /usr/local/samba/bin/samba-tool group add admin_staff || true echo "--- Creating Pre-populated Test Users ---" docker exec samba_test_ad /usr/local/samba/bin/samba-tool user create fry FryPassword123! --given-name='Philip' --surname='Fry' --mail-address='fry@planetexpress.com' || true docker exec samba_test_ad /usr/local/samba/bin/samba-tool user create leela LeelaPassword123! --given-name='Turanga' --surname='Leela' --mail-address='leela@planetexpress.com' || true docker exec samba_test_ad /usr/local/samba/bin/samba-tool user create professor ProfPassword123! --given-name='Hubert' --surname='Farnsworth' --mail-address='professor@planetexpress.com' || true echo "--- Assigning Group Members ---" docker exec samba_test_ad /usr/local/samba/bin/samba-tool group addmembers ship_crew fry,leela || true docker exec samba_test_ad /usr/local/samba/bin/samba-tool group addmembers admin_staff professor || true echo "✅ Active Directory data successfully populated! Setup complete." Then for my ProGet configuration, I created a new V5: Active Directory and here were the settings: General Name: V5: Samba 4 Domain: planetexpress.com User name: Administrator Password: GoodNewsEveryone123! Connection Domain Controller Host: <IP Address of my VM> LDAP Connection: Use LDAP Then I tested using Load user by username for the user fry in the group ship_crew. For recursive groups I used the user Administrator and the Group Denied RODC Password Replication Group. Then I added ship_crew to the Administer task and I logged in using fry/FryPassword123!. Thanks, Rich
  • [ProGet] Docker Feeds Self Connector & Caching

    3
    1
    3 Posts
    13 Views
    F
    @atripp Hi Alana, Thanks for the clarification!
  • [ProGet] Incorrect package publish date affecting policies

    15
    15 Posts
    70 Views
    atrippA
    Hi @amy.j , Without a reliable publish date, there's no reasonable way to rely on an automated compliance rule that relies on the publish date. I would recommend developing a Maven-specific approach, since this feed type is so limited. You've probably noticed it already, but license detection is also not very reliable. But, I wouldn't worry too much about it. Keep in mind: the Java ecosystem seems to publish much less frequently than JavaScript there are fewer transient dependencies in Java version ranges tend to be less popular and much more conservative Also there seems to be an issue with pulling in certain jar files, eg, when org.springframework:spring-webflux 6.2.19 is promoted no jar file is listed - so cannot be consumed. This has happened for a few packages. This is probably related to that unreliable Maven Index file. The Maven API does not support "file listing", so there's no automated way to know what artifacts are contained within a particular release. You just "kinda know" by reading the project's release notes, etc. Early on, we just "assumed" there would always a .jar file, but I guess that's not the case because there are .war and .ear files too. We also considered parsing the web-based file listing page (e.g. spring-webflux/6.2.19, but a lot of repositories don't provide a listing. We're open to ideas, but it's just an unfortunately limited ecosystem. Thanks, Alana
  • 2 Posts
    10 Views
    atrippA
    Hi @sai.pabbareddy , Those are both "packages" that contain the same kind of license (ProGet Enterprise). A single ProGet Enterprise license will allow you to configure a ProGet instance as a HA/cluster. "Enterprise Essentials" contains ONE license of ProGet Enterprise and no services "Enterprise Complete" contains TWO licenses of ProGet Enterprise plus services Organizations will often get two licenses of ProGet Enterprise to create two different environments (one Production, one DR/Testing/Training). Hope that helps clarify :) Thanks, Alana
  • 4 Posts
    32 Views
    gdivisG
    We've scheduled PG-3386 to resolve the slow multi-build analysis on Postgres. It will be included in ProGet 2026.12, which is scheduled for release on Oct 2.
  • ProGet issue with metadata API for PyPi packages

    7
    7 Posts
    31 Views
    atrippA
    Hi @amy.j , This package is a bit weird in that (1) it uses a file-embedded licenses, (2) there are 172 contained files, and (3) some of those files don't follow standard naming conventions. When those things happen, I think we get results like this. The easiest way to work-around this is to just assign a license directly to the package using the Purl (i.e. pkg:pypi/charset_normalizer@3.5.1). You can do that by editing the MIT license type. Thanks, Alana
Inedo Website Home • Support Home • Code of Conduct • Forums Guide • Documentation