Welcome to the Inedo Forums! Check out the Forums Guide for help getting started.
If you are experiencing any issues with the forum software, please visit the Contact Form on our website and let us know!
Dependency Confusion in ProGet
-
Hello,
We currently have a pipeline dedicated to detecting dependency confusion, but it takes around six hours to scan all artifacts. Does Inedo provide a native API or built-in capability to perform the same kind of analysis?
Regards -
This is really easy to do in ProGet and no need for a "scan". I can't even imagine how such a "scan" could work.
Anyway, you just simply need to add a connector filter that prefixes your internal packages. For example, our filter for NuGet packages would look like
Inedo*- which prevents any package named that coming through a connector.Check out this article to get some more details:
https://blog.inedo.com/software-supply-chain-security/three-thingsThanks,
Steve
Hello! It looks like you're interested in this conversation, but you don't have an account yet.
Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.
With your input, this post could be even better 💗
Register Login