<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Dependency Confusion in ProGet]]></title><description><![CDATA[<p dir="auto">Hello,</p>
<p dir="auto">We currently have a pipeline dedicated to detecting dependency confusion, but it takes around six hours to scan all artifacts. Does Inedo provide a native API or built-in capability to perform the same kind of analysis?<br />
Regards</p>
]]></description><link>https://forums.inedo.com/topic/5739/dependency-confusion-in-proget</link><generator>RSS for Node</generator><lastBuildDate>Fri, 01 May 2026 12:25:25 GMT</lastBuildDate><atom:link href="https://forums.inedo.com/topic/5739.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 01 May 2026 09:28:14 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Dependency Confusion in ProGet on Fri, 01 May 2026 09:28:14 GMT]]></title><description><![CDATA[<p dir="auto">Hello,</p>
<p dir="auto">We currently have a pipeline dedicated to detecting dependency confusion, but it takes around six hours to scan all artifacts. Does Inedo provide a native API or built-in capability to perform the same kind of analysis?<br />
Regards</p>
]]></description><link>https://forums.inedo.com/post/19616</link><guid isPermaLink="true">https://forums.inedo.com/post/19616</guid><dc:creator><![CDATA[certificatemanager_4002]]></dc:creator><pubDate>Fri, 01 May 2026 09:28:14 GMT</pubDate></item><item><title><![CDATA[Reply to Dependency Confusion in ProGet on Fri, 01 May 2026 12:17:30 GMT]]></title><description><![CDATA[<p dir="auto">Hi <a class="plugin-mentions-user plugin-mentions-a" href="https://forums.inedo.com/uid/3205">@certificatemanager_4002</a> ,</p>
<p dir="auto">This is really easy to do in ProGet and no need for a "scan". I can't even imagine how such a "scan" could work.</p>
<p dir="auto">Anyway, you just simply need to add a connector filter that prefixes your internal packages. For example, our filter for NuGet packages would look like <code>Inedo*</code> - which prevents any package named that coming through a connector.</p>
<p dir="auto">Check out this article to get some more details:<br />
<a href="https://blog.inedo.com/software-supply-chain-security/three-things" rel="nofollow">https://blog.inedo.com/software-supply-chain-security/three-things</a></p>
<p dir="auto">Thanks,<br />
Steve</p>
]]></description><link>https://forums.inedo.com/post/19618</link><guid isPermaLink="true">https://forums.inedo.com/post/19618</guid><dc:creator><![CDATA[stevedennis]]></dc:creator><pubDate>Fri, 01 May 2026 12:17:30 GMT</pubDate></item></channel></rss>