<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Automatic Assesment not working?]]></title><description><![CDATA[<p dir="auto">We have a Proget Enterprise trial instance and are soon buying a license (ProGet Version 2025.23 (Build 11) (Docker/ Linux))</p>
<p dir="auto">I wanted to test/evaluate the "Automatic Assessment" functionality<br />
There seems to be a missing link in my setup and the documentation<br />
I have the default assessment types which specifies and automatic assessment rule of setting vulnerabilities with score 9.0 -&gt; 10.0 as Blocked</p>
<p dir="auto">Now i have setup a maven feed, and downloaded log4j-core 2.14.1 which has a known vulnerability with score 10.0<br />
I would have expected proget to set the assessment automatically to "Blocked" and block the download but it is shown as Unassessed and can be downloaded!</p>
<p dir="auto">What am I missing ?</p>
<p dir="auto"><a href="/assets/uploads/files/1776778047621-screenshot-2026-04-21-145157.png">Screenshot 2026-04-21 145157.png</a> <img src="/assets/uploads/files/1776778047596-screenshot-2026-04-21-145114.png" alt="Screenshot 2026-04-21 145114.png" class="img-responsive img-markdown" /> <img src="/assets/uploads/files/1776778047545-screenshot-2026-04-21-145042.png" alt="Screenshot 2026-04-21 145042.png" class="img-responsive img-markdown" /> <img src="/assets/uploads/files/1776778047568-screenshot-2026-04-21-145000.png" alt="Screenshot 2026-04-21 145000.png" class="img-responsive img-markdown" /></p>
]]></description><link>https://forums.inedo.com/topic/5730/automatic-assesment-not-working</link><generator>RSS for Node</generator><lastBuildDate>Tue, 28 Apr 2026 13:14:15 GMT</lastBuildDate><atom:link href="https://forums.inedo.com/topic/5730.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 21 Apr 2026 13:27:51 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Automatic Assesment not working? on Tue, 21 Apr 2026 13:27:51 GMT]]></title><description><![CDATA[<p dir="auto">We have a Proget Enterprise trial instance and are soon buying a license (ProGet Version 2025.23 (Build 11) (Docker/ Linux))</p>
<p dir="auto">I wanted to test/evaluate the "Automatic Assessment" functionality<br />
There seems to be a missing link in my setup and the documentation<br />
I have the default assessment types which specifies and automatic assessment rule of setting vulnerabilities with score 9.0 -&gt; 10.0 as Blocked</p>
<p dir="auto">Now i have setup a maven feed, and downloaded log4j-core 2.14.1 which has a known vulnerability with score 10.0<br />
I would have expected proget to set the assessment automatically to "Blocked" and block the download but it is shown as Unassessed and can be downloaded!</p>
<p dir="auto">What am I missing ?</p>
<p dir="auto"><a href="/assets/uploads/files/1776778047621-screenshot-2026-04-21-145157.png">Screenshot 2026-04-21 145157.png</a> <img src="/assets/uploads/files/1776778047596-screenshot-2026-04-21-145114.png" alt="Screenshot 2026-04-21 145114.png" class="img-responsive img-markdown" /> <img src="/assets/uploads/files/1776778047545-screenshot-2026-04-21-145042.png" alt="Screenshot 2026-04-21 145042.png" class="img-responsive img-markdown" /> <img src="/assets/uploads/files/1776778047568-screenshot-2026-04-21-145000.png" alt="Screenshot 2026-04-21 145000.png" class="img-responsive img-markdown" /></p>
]]></description><link>https://forums.inedo.com/post/19584</link><guid isPermaLink="true">https://forums.inedo.com/post/19584</guid><dc:creator><![CDATA[jens.viebig_4541]]></dc:creator><pubDate>Tue, 21 Apr 2026 13:27:51 GMT</pubDate></item><item><title><![CDATA[Reply to Automatic Assesment not working? on Tue, 21 Apr 2026 21:29:05 GMT]]></title><description><![CDATA[<p dir="auto">Hi <a class="plugin-mentions-user plugin-mentions-a" href="https://forums.inedo.com/uid/3906">@jens-viebig_4541</a>,</p>
<p dir="auto">This is because you have not downloaded any versions of log4j-core as of yet.  Once at least one version is downloaded, it will become auto-assessed after the next vulnerability database update.  This situation is something that is being addressed with the upcoming release of ProGet 2026.</p>
<p dir="auto">Thanks,<br />
Dan</p>
]]></description><link>https://forums.inedo.com/post/19588</link><guid isPermaLink="true">https://forums.inedo.com/post/19588</guid><dc:creator><![CDATA[Dan_Woolf]]></dc:creator><pubDate>Tue, 21 Apr 2026 21:29:05 GMT</pubDate></item><item><title><![CDATA[Reply to Automatic Assesment not working? on Wed, 22 Apr 2026 06:51:01 GMT]]></title><description><![CDATA[<p dir="auto">Hi,<br />
i had already downloaded log4j-core with the "bad" version. I would have expected this to be an immediate action but as you described it is tied to a scheduled job triggered by vulnerability update.</p>
<p dir="auto">Looking at the feed and packages today shows me that the auto assessment of all the downloaded packages was done overnight.</p>
<p dir="auto">But does this mean the auto-blocking will never work the first time a package is downloaded? The auto blocking will always only kick in after the next vulnerability update ??</p>
<p dir="auto">I hope that logic does not apply to the malicious package blocking as well... <img src="https://forums.inedo.com/plugins/nodebb-plugin-emoji/emoji/android/1f628.png?v=n37j1a7b7c4" class="not-responsive emoji emoji-android emoji--fearful" title=":fearful:" alt="😨" /></p>
]]></description><link>https://forums.inedo.com/post/19589</link><guid isPermaLink="true">https://forums.inedo.com/post/19589</guid><dc:creator><![CDATA[jens.viebig_4541]]></dc:creator><pubDate>Wed, 22 Apr 2026 06:51:01 GMT</pubDate></item></channel></rss>