Navigation

    Inedo Community Forums

    Forums

    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Groups
    1. Home
    2. MellowOak
    3. Posts
    M
    • Profile
    • Following
    • Followers
    • Topics
    • Posts
    • Best
    • Groups

    Posts made by MellowOak

    • [ProGet] Malicious package blocking

      Can you please provide further details on the handling of malicious packages? The Inedo Security Labs site (https://security.inedo.com/vulnerability/malicious-packages) states:

      Our research team is constantly monitoring these threats and evolving our detection methods to stay ahead of these attacks. Below is a list of packages that we're aware of and actively blocking in ProGet.
      

      However I can't find the corresponding documentation for such a feature, only the following which covers vulnerable packages but does not mention malicious packages: https://docs.inedo.com/docs/proget/sca/vulnerabilities

      Specifically, I'd like to know:

      1. What version of ProGet is required to block malicious packages?
      2. What configuration settings are needed to block malicious packages?
      3. Can a block be overridden?
      4. Is the malicious package list retrieved periodically and stored locally on the ProGet instance? If so, how often is this done and is this configurable?
      5. What visibility do we get when a malicious package is blocked?
      posted in Support
      M
      MellowOak
    • 1 / 1