Inedo Community Forums Forums
    • Recent
    • Tags
    • Popular
    • Login
    1. Home
    2. caterina

    Welcome to the Inedo Forums! Check out the Forums Guide for help getting started.

    If you are experiencing any issues with the forum software, please visit the Contact Form on our website and let us know!

    C Offline
    • Profile
    • Following 0
    • Followers 0
    • Topics 27
    • Posts 77
    • Groups 0

    caterina

    @caterina

    2
    Reputation
    3
    Profile views
    77
    Posts
    0
    Followers
    0
    Following
    Joined
    Last Online

    caterina Unfollow Follow

    Best posts made by caterina

    • pgutil: Projects in .slnx are not found

      Hi all,

      we tested the .slnx support of pgutil and noticed that pgutil can only detect projects that are a direct child of the root element.
      If the .slnx structure is more complex, projects are not found.

      E.g:
      Both projects are detected by pgutil:
      0f2927c0-6de2-46a3-bc55-013c39489a7e-image.png

      No projects are being found:
      76eb97ea-f5c7-41bc-a3ff-42e24f7d49d1-image.png

      Since it was a quick fix, we created a pull request for it:
      https://github.com/Inedo/pgutil/pull/25

      Please have a look at it and let us know if you can confirm the behavior.

      Thanks
      Caterina

      posted in Support
      C
      caterina
    • RE: pgscan: lockfileVersion 3 for npm dependencies not supported

      Hi @atripp

      I think packages has to be iterated instead. I haven't seen dependencies beneath packages.
      Further, the "empty" Key has to be ignored as it stands for the root project:
      f22cf0f2-b7e6-4bc6-98cd-3c19e983f635-image.png

      Maybe a little bit parsing would be necessary.
      In lockfileVersion 2 a dependency was listed like this:
      dae966e2-b003-4624-a25e-2b0e06d24b77-image.png
      In lockfileVersion 3 it looks like this:
      5302a66c-d015-4f87-afb6-2ed097e30f52-image.png

      If desired, we can also upload package-lock.json files for testing via MyInedo.

      posted in Support
      C
      caterina

    Latest posts made by caterina

    • RE: [ProGet] Understanding Assessments

      Hi @stevedennis,

      thank you very much for your reply 😄

      Caterina

      posted in Support
      C
      caterina
    • RE: [ProGet] Understanding Assessments

      Maybe an example is helpful:
      3c4825a9-1387-44f7-8b35-42e88d66f2b9-image.jpeg
      This package has vulnerability PGV-265934T. It gets auto-assessed as "Monitor" in Category 1.
      But if (for whatever reason) we want to block all packages with this vulnerability by making them non-compliant (without changing the risk profile) I would go to the vulnerabilities page, search for this vulnerability and assess it manually. But this vulnerability can not be found on the vulnerabilities page.

      posted in Support
      C
      caterina
    • RE: [ProGet] Understanding Assessments

      Hi all,

      I have a followup question regarding the assessments.
      Am I only able to assess vulnerabilities that are already present in my products?
      What if a new vulnerability is found which does not affect any of my products yet but I want to avoid future products to use affected packages?

      In ProGet 2025 we were using a manual assessment called "Manually Blocked" which was assigned to a new vulnerability, made all packages noncompliant and blocked the download. This way we were able to prevent vulnerabilities in our products before they could happen.

      Thanks
      Caterina

      posted in Support
      C
      caterina
    • RE: [ProGet] Understanding Assessments

      Hi @stevedennis,

      no need to do such a deep dive 😄
      I was just curious about the new data structure and I noticed that the "old" table "PgvdAssessments" contained all assessments, also the auto-assessed ones. And the table "PgvdAssessments26" is empty.
      I just wanted to make sure that this is somehow intended and does not cause any further issues.
      As long as we still get all vulnerabilities for a project everything is ok 👍
      I will let you know if we encounter any problems.

      Thanks
      Caterina

      posted in Support
      C
      caterina
    • RE: [ProGet] Understanding Assessments

      Hi @stevedennis,

      so the package is coming from a connector but it has been retrieved via ProGet and is used in projects. I can also see it if I search for "Local and Cached" packages.
      Is that enough to be seen as "in" ProGet? Or what is the exact definition of being "in" ProGet? Maybe I have a different understanding of that.

      Because I ran the job again via Admin -> Vuln Types -> Reassess and it is still dotted.

      Thanks
      Caterina

      posted in Support
      C
      caterina
    • [ProGet] Understanding Assessments

      Hi all,

      I noticed that auto-assessed vulnerabilities are not stored in the Assessments table of ProGet.
      Further it also shows them as (unassessed) when i want to override the assessment:
      1a841ab3-a493-487b-aecc-412a98163e31-image.jpeg
      Only if I manually assess them they are stored in the database.
      Is this intended behavior? Just wanted to check in if that affects the compliance analyzer or if anything is still working as planed.

      Thanks
      Caterina

      posted in Support
      C
      caterina
    • RE: ProGet - Unable to login with Active Directory

      Hi @dean-houston,

      but the output of /debug/integrated-auth is the same for our ProGet 2025 installation where it is working perfectly fine. Not sure how meaningful the output is.

      There is no reverse proxy or anything in front of ProGet.
      We used IIS to host older versions of ProGet, but with ProGet 2025 we switched to Integrated Web Server like it is written in your documentation. We deleted all IIS pages.

      Everything has been installed via InedoHub and we also use the InedoHub for upgrading/downgrading. WIA has been activated

      And just as I am writing this reply I was able to fix the problem 😅
      I wanted to double check our settings and noticed that the directory we have set up (many years ago) was V3. For testing I added a new V5 directory and now WIA is working again.
      Was updating the user directory part of an upgrade guide for ProGet? I can not remember reading it anywhere.

      Thanks
      Caterina

      posted in Support
      C
      caterina
    • RE: ProGet - Unable to login with Active Directory

      Hi all,

      thanks for your responses.
      This is the output of https://«PROGET_HOST»/debug/integrated-auth:
      b1e4334a-bf03-48cc-b969-00ee72eb40d3-image.jpeg
      But the same output is generated by ProGet 2025, where WIA is working.

      Also searching for the user using «NETBIOS_DOMAIN_NAME»\«USER_NAME» was successful.

      Rolling back to ProGet 2025 resolved the issue again.

      Since most of our used products are working with WIA and no one else is recommending moving away from it we want to keep working with it if we have the possibility. We already had that discussion in another post ;D

      What does "setting it up from scratch" include?
      Just disabling and enabling it again was not enough. We have a User directory/domain set up. Will it help to disable the existing one and create a new one?

      Thanks
      Caterina

      posted in Support
      C
      caterina
    • ProGet - Unable to login with Active Directory

      Hi,

      we tried upgrading to ProGet 2026 (from ProGet 2025.30). We are using Windows Integrated Authentication to be able to login with our AD users.
      Unfortunately, after upgrading to ProGet 2026 the windows authentication is no longer working. Everyone is recieving a error 500. (I tried all ProGet 2026 versions, none is working.)
      The status code 500 is returned immediately without trying to authenticate the user (no negotiate handshake).

      We upgraded using the Inedo Hub and we did not make changes to the settings.

      If we test the user directories for our domain under Adminstration -> Security the user is being found.

      In the Event Viewer we have this exception:

      Inedo.ProGet.Web.Security.UserNotFoundException: Exception of type 'Inedo.ProGet.Web.Security.UserNotFoundException' was thrown.
         at Inedo.ProGet.WebApplication.ProGetHttpModule.AuthorizeRequestAsync(AhHttpApplication app)
         at Inedo.Web.InedoHttpModule.Inedo.Web.IAhWebModule.AuthorizeRequestAsync(AhHttpApplication app)
         at Inedo.Web.AhWebMiddleware.InvokeAsync(HttpContext context)
         at Inedo.Web.AhWebMiddleware.InvokeAsync(HttpContext context)
         at Inedo.Web.AhWebMiddleware.InvokeAsync(HttpContext context)
         at Inedo.Web.AhWebHost.<>c.<<Configure>b__24_0>d.MoveNext()
      

      Maybe you can help us with that.

      Thanks
      Caterina

      posted in Support
      C
      caterina
    • RE: Moving from IIS to Integrated Web Server

      Hi @stevedennis ,

      using ?bypassIntegrated=false lets me download the package from the UI.
      Is this something you can fix?
      For now I can share this information with my colleagues.

      Offtopic (since we are already talking):
      We recieved your Inedo snackbox this week and we love it 😄

      Thanks,
      Caterina

      posted in Support
      C
      caterina