<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Request new API]]></title><description><![CDATA[<p dir="auto">Hello.</p>
<p dir="auto">We are new to using ProGet, and so far it is great.  But, our security team would like a weekly  report showing all the packages with vulnerabilities, how many times they were downloaded, and who downloaded those packages.  There doesn't seem to be a native report that shows that, so I created one using the API.  I can get all the data except who downloaded the vulnerable package.  I know the data is in the database, because I can see it on the Usage &amp; Statistics page.</p>
<p dir="auto">It would be great if you developed a report or created a new API, or enhanced an exiting one, to let me get the usage &amp; statistic data for a package.</p>
]]></description><link>https://forums.inedo.com/topic/5856/request-new-api</link><generator>RSS for Node</generator><lastBuildDate>Fri, 09 Oct 2026 23:07:32 GMT</lastBuildDate><atom:link href="https://forums.inedo.com/topic/5856.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 09 Oct 2026 16:03:35 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Request new API on Fri, 09 Oct 2026 20:40:27 GMT]]></title><description><![CDATA[<p dir="auto">Hi <a class="plugin-mentions-user plugin-mentions-a" href="/user/bobmaurer" aria-label="Profile: bobmaurer">@<bdi>bobmaurer</bdi></a> ,</p>
<p dir="auto">Thanks for the inquiry! Hope you don't mind a little push back on this -- but we'd encourage your security team to read our <a href="https://guides.inedo.com/vulnerability-management/" rel="nofollow ugc">Vulnerability Management Done Right with ProGet</a>.</p>
<p dir="auto">While we understand where they're coming from, the "weekly download" report is an anti-pattern these days and will lower the organization's security posture... which <em>probably</em> goes against their mission <img src="https://forums.inedo.com/assets/plugins/nodebb-plugin-emoji/emoji/android/1f609.png?v=5cc69d9e2fd" class="not-responsive emoji emoji-android emoji--wink" style="height:23px;width:auto;vertical-align:middle" title=":wink:" alt="😉" /></p>
<p dir="auto">The main reason is that it improperly treats vulnerabilities as security incidents while providing no realistic path to mitigate them. This is backed by a huge body of research, including our own <a href="https://inedo.com/2026-software-supply-chain-security-report" rel="nofollow ugc">State of Software Supply Chain Security</a> and reports from industry analysts.</p>
<p dir="auto">For example, they see "Joe Developer downloaded JsonLib 3.4.1, which has PGV-12345" -- what exactly are they going to do with that information? Contact Joe and ask him how he used it? Do they expect Joe to trace through 1000's of transitive dependencies across dozens of projects to see if he even knows where it's used? Tell him to uninstall it? Try to figure out if he caused damage?  Or what application it was added to?</p>
<p dir="auto">Obviously not, because there will be so many packages with vulnerabilities that no one knows where they came from. The "best case" is to get aggregate data -- and ProGet already provides that, but by application/deployment state (which is what really matters).</p>
<p dir="auto">Anyway -- the best way to handle this is by implementing <a href="https://docs.inedo.com/docs/proget/api/sca" rel="nofollow ugc">Software Composition Analysis</a> in ProGet - we have all the tools to help <a href="https://guides.inedo.com/vulnerability-management/category-5/" rel="nofollow ugc">Prepare for a Category 5 Vulnerability</a></p>
<p dir="auto">Thanks,<br />
Steve</p>
]]></description><link>https://forums.inedo.com/post/20136</link><guid isPermaLink="true">https://forums.inedo.com/post/20136</guid><dc:creator><![CDATA[stevedennis]]></dc:creator><pubDate>Fri, 09 Oct 2026 20:40:27 GMT</pubDate></item></channel></rss>