Inedo Community Forums Forums
    • Recent
    • Tags
    • Popular
    • Login
    1. Home
    2. MellowOak
    3. Posts

    Welcome to the Inedo Forums! Check out the Forums Guide for help getting started.

    If you are experiencing any issues with the forum software, please visit the Contact Form on our website and let us know!

    M Offline
    • Profile
    • Following 0
    • Followers 0
    • Topics 1
    • Posts 1
    • Groups 0

    Posts

    Recent Best Controversial
    • [ProGet] Malicious package blocking

      Can you please provide further details on the handling of malicious packages? The Inedo Security Labs site (https://security.inedo.com/vulnerability/malicious-packages) states:

      Our research team is constantly monitoring these threats and evolving our detection methods to stay ahead of these attacks. Below is a list of packages that we're aware of and actively blocking in ProGet.
      

      However I can't find the corresponding documentation for such a feature, only the following which covers vulnerable packages but does not mention malicious packages: https://docs.inedo.com/docs/proget/sca/vulnerabilities

      Specifically, I'd like to know:

      1. What version of ProGet is required to block malicious packages?
      2. What configuration settings are needed to block malicious packages?
      3. Can a block be overridden?
      4. Is the malicious package list retrieved periodically and stored locally on the ProGet instance? If so, how often is this done and is this configurable?
      5. What visibility do we get when a malicious package is blocked?
      posted in Support
      M
      MellowOak
    • 1 / 1