Welcome to the Inedo Forums! Check out the Forums Guide for help getting started.

If you are experiencing any issues with the forum software, please visit the Contact Form on our website and let us know!

  • 0 Votes
    4 Posts
    13 Views
    apxltdA
    Hi @fabrice-mejean , Thanks so much for the detailed information and offer to connect further! Very interested in that and I will definitely take you up on that :) Please give me a little time for that; I've got some travel coming up and then a bunch of other things... so I'd like to connect when I can really focus on some of these future things. . Cheers, Alex
  • 0 Votes
    8 Posts
    75 Views
    stevedennisS
    @Nils-Nilsson excellent, let us know as you have other feedback too! This is definitely an area we intend to keep improving in throughout ProGet 2026+
  • 0 Votes
    4 Posts
    17 Views
    stevedennisS
    Hi @carl-westman_8110 , Thanks for sharing that. This isn't a symptom of "server overload" that we've seen before. The error you shared is occurring on Feeds_GetFeeds, which is definitely not an intensive query, and I would not expect that to be timing out at all. It's just SELECT * FROM [Feeds]. However, that's a similar symptom to the "AzureSQL resource throttling" that we've seen on other users: another query is being throttled (for example, something that joins on [Feeds]), and that is causing a cascading impact on other queries. We don't have enough information to say that's the case here. But, an easy way to test would be to up your DTUs substantially. Otherwise, the next troubleshooting step is to try to identify the cause of the timeouts, which involves looking at HTTP Access logs and jobs occurring around the same time under Admin > Scheduled Jobs. Thanks, Steve
  • API request to get latest image or chart?

    Support
    2
    0 Votes
    2 Posts
    10 Views
    atrippA
    Hi @jeff-miles_5073 , You can get information about images and tags using the Docker API; we do not provide documentation on how to use that (see our caveat on Feed Endpoints). And unfortunately the Docker API is a bit awkward, but with enough ChatGPT you should be able to figure it out :) You could also query the database directly, perhaps building some kind of data export tool so that you can sync it with your dashboard. Hope that helps, Alana
  • 0 Votes
    4 Posts
    21 Views
    rhessingerR
    Hi @joris-guex, Thanks for sending an example over. It looks like this is related to an issue in the libssh2-sys's manifest. I have created a ticket, PG-3321, to handle these issues better. We are expecting to have a fix out within the couple of maintenance releases of ProGet 2026. Thanks, Rich
  • ProGet pnpm audit reports no vulnerabilities

    Support
    4
    0 Votes
    4 Posts
    27 Views
    stevedennisS
    Hi @Ashley , Amazing, thanks for this investigation! This is very helpful. You've also captured the exact issue we have with a lot of these APIs; no real specs (or worse... wrong specs), which involves a reverse engineering effort. This quote is wonderful: In summary, due to the lack of an official JSON schema and potential changes between npm versions, it's crucial to treat the npm audit --json output structure as subject to change. Relying solely on the npm CLI source code for the most accurate and up-to-date information is recommended, along with implementing robust version checks and testing in your development processes. Wouldn't it be nice if we could build our products like that! Anyway, I was curious and I asked internally, and the original engineer is almost certain that npmjs used to have the CVE number there, which we also used to emit until changing to PGVD number in ProGet 2023. But that is consistent with their position of "we don't do specs, just read the latest commit to figure it out. But it doesn't really matter, that's what we have now... To ensure consistency with the public npm registry, would it be possible to change ProGet to use a number for the id field on the audit response? If you discovered this in ProGet 2025, we'd just change it in ProGet 2026 and not worry about it. But we need to be super-careful making API changes in a maintenance release. We can't quite get away with Microsoft/GitHub levels of quality :) Seemingly harmless changes lead to broken builds, which are really painful to debug; for example, we recently added upload-time to PyPI API. That caused older versions of the pip client to break due to a bug in how they parsed dates. There are probably too many client/versions to answer the question "what is this field even used for and what are the consequences of changing it?" Perhaps an easier route is to just get pnmp to change to a string, like the rest of them? Or, just ignore it and "let it be"? Over time, if you follow our recommend best practices, these audits will show fewer and fewer vulnerabilities. We plan to continuously refine the PVRS algorithm to better combat both "vulnslop" (i.e. AI-discovered and AI-generated vulnerabilities that cannot be exploited in any real-world scenario nor would cause any real-world harm if so) and misreporting. Thanks, Steve
  • Block recently published - Metadata filter ?

    Support
    4
    1 Votes
    4 Posts
    28 Views
    apxltdA
    @jens-viebig_4541 ooh good catch! That guidance is outdated as of ProGet 2026, where we no longer recommend/default to blocking Noncompliant packages. We should rewrite/republish the article to be more focused on guidance, update the screenshots, etc. I'll add that to the list.
  • 0 Votes
    2 Posts
    7 Views
    stevedennisS
    Hi @svc-4x9p2a_6341 , This is known issue and will be addressed via PG-3309 in the next maintenance release. You can just ignore the messages for the time being, it only happens like once a week or so.... I wouldn't modify the database either. Thanks, Steve
  • 0 Votes
    4 Posts
    15 Views
    stevedennisS
    Hi @mhelp_5176, Connecting to the embedded database requires local access to the ProGet server. Once an attacker has that, then they already have full access to the database, as it's stored as files on disk... basically it's the equivalent of storing the safe key inside of the safe :) As such. it doesn't make sense for us to add complexity to the product to support changing a password that's already secured. Thanks, Steve
  • User gets 500 error if you delete a logged in user

    Locked Support
    4
    0 Votes
    4 Posts
    16 Views
    stevedennisS
    Hello, Thanks for reporting this; this behavior is by design. ProGet uses authentication tickets (i.e. encrypted cookies). If the username on a valid ticket cannot be located in the user directory, then a "user not found" error will occur, as it did here. This errant behavior is generally desired for troubleshooting cases where users are intermittently not available from a user directory. Otherwise it's very difficult to troubleshoot, since it will just appear as a random log-out. Thanks, Steve
  • PostgreSQL DB Location

    Support
    5
    0 Votes
    5 Posts
    26 Views
    atrippA
    Hi @mhelp_5176, Not at this time; this would add complexity to the software and installation, so we're hesitant to give an option to configure this path without a compelling technical benefit. Given your requirements, perhaps they should just configure the %ProgramData% folder to be on a different drive? Many Windows programs use that location for data like this. Or perhaps configure a junction (soft link). Thanks, Alana
  • Add Documentation for Chocolatey Proxy feeds

    Support
    11
    0 Votes
    11 Posts
    33 Views
    apxltdA
    Hi @imm0rtalsupp0rt , We've published a version of the article now: https://docs.inedo.com/docs/proget/feeds/chocolatey/howto-chocolatey-proxyccr Let us know your thoughts or freel free to submit a PR should have have any suggestions! Thanks, Alex
  • 1 Votes
    6 Posts
    20 Views
    stevedennisS
    @sigurd-hansen_7559 wow very cool! We didn't anticipate anyone would customize these templates beyond adding a variable or two, so it it didn't seem to make a lot of sense to invest in a proper editor (like we have in the other products) Anyway, it'd be interesting to see what kind of templates you develop.
  • Support for Azure Key Vault references in Connector credentials

    Support
    2
    0 Votes
    2 Posts
    4 Views
    stevedennisS
    Hi @alkhleif_2585 , There isn't much demand for this kind of feature (I think we've only seen one or two requests for this over very many years) so it's not on our roadmap. And it's unlikely we will add it to the roadmap considering that it would be quite costly to build, support, and maintain. Especially considering that we'd need to support all of the major "vaults" out there as well. It doesn't seem to add much value to ProGet as these types of read-only credentials can be very long living (several years) without any security risk, and take just a few minutes to rotate when needed. That being said, you could probably write a "sync script" pretty easily that continuously updates the connector credentials by connecting to the vault and then updating it via the API. Cheers, Steve
  • Cargo feed returning 500 Internal Server Error

    Support cargo error 500 proget
    3
    0 Votes
    3 Posts
    19 Views
    J
    Hi @atripp, We have now updated to ProGet 2026.3 and can confirm this is now working as expected. Thank you for your prompt help.
  • 0 Votes
    2 Posts
    11 Views
    stevedennisS
    Hi @vdubrovskyi_1854 , Without knowing which specific package you're referring to, it's hard to give a more specific example. Historically, Packagist was effectively a database of "GitHub Repository pointers" and Composer was effectively just a wrapper around the Git client. They can both still operate in that mode, and needs to for older, non-standard packages. I suspect that's the type of package you're referring to here. ProGet's Composer feeds work with "packages" (i.e. not the GitHub pointers), which account for nearly all of the modern packages on Packagist.org. For the small number of packages that don't follow the standard (mostly older, legacy packages), you'll need to download them, properly package them, and then upload them to follow the standard. Unfortunately there's no technically feasible/sensible way to solve this problem - since it would require ProGet to serve as a GitHub pointer database, which just doesn't make sense. Cheers, Steve
  • Unable to login with Active Directory with Proget 2026.1

    Support
    7
    0 Votes
    7 Posts
    44 Views
    aristo_4359A
    @pg_user_8607 Given the fix is about searching in AD I think the pull request is indeed related, as there is no other error I can find other than unable to find the user(s) in the User Directories Test.
  • After upgrading to 2026 https no longer works

    Support
    5
    1 Votes
    5 Posts
    48 Views
    ValentijnV
    Hi, I was on a short vacation but today I upgraded to 2026.3 (build 14) without any problems. This probably fixed it: PG-3299 2026.3 FIX: Hostname based binding fails when hosting on Windows with HTTP.SYS Kind regards, Valentijn
  • Scheduled Task is failing due to invalid script identifier

    Support
    3
    2
    0 Votes
    3 Posts
    24 Views
    B
    Hi Alana, Just wanted to let you know that restarting the service did fix the issue. Thank you for the suggestion. Brandon
  • 0 Votes
    3 Posts
    18 Views
    A
    Hi @gdivis , thanks for the quick turnaround. Everything is working as expected with the new version. Cheers