Rules and approvals
Auto approve
Let clean requests approve themselves, and keep anything risky for a person.
Every request is checked as soon as it arrives: its files are downloaded, which caches them, scanned for malware, and looked up in the advisory feeds. On Requests each one says what the check found, like "checked: malware scan clean, no advisories", so you can decide at a glance.
With Auto approve on, a request that passes is approved by itself. Switch it on or off on the Dashboard, under Auto approve. Only admins can change it, a reason is required, admins are emailed, and the change goes into the audit trail.
| The check finds | Auto approve does |
|---|---|
| Every file scans clean for malware, and the worst advisory is below High | Approves it, pinned to the exact versions checked. The files are already cached. |
| A High or Critical advisory | Leaves it in Requests for a person, naming the advisories. |
| No malware answer: scanning off, a scanner down, or a file too big to scan | Leaves it for a person, saying why. |
| A kill switch, a deny rule, a lookalike name, a reserved name, or a license held by the license rules | Leaves it for a person. |
| A version still cooling off, a scan still running, or the registry in degraded or lockdown mode | Waits, and looks again every 5 minutes. |
- A request that names versions is approved for exactly those. A request with no version, which is what a blocked install makes, is approved for the whole package when Scan before serving is on, because every later version is still scanned before it is served. With Scan before serving off, it is pinned to the newest version that finished cooling off.
- For an image, every platform image, config and layer is downloaded and scanned, and the packages inside are checked. When Only count what has a fix is on, only advisories that have a fix count toward High and Critical.
- Malware scanning must be on with a content scanner such as ClamAV. A hash blocklist alone is not a scan.
- On Requests, a request auto approve would not take says needs a person and why, like "high advisories (CVE-2021-23337)". Approved rules say "auto approved" in their note, and the audit trail records request.approve.auto.
- While auto approve is on, an install refused for want of a rule tells the developer it is being checked and to try again in up to 10 minutes, or 30 for an image.
Careful
Auto approve takes a person out of the loop for clean packages. Keep Cooling off on, so a brand new malicious release is not approved in its first hours, before scanners and advisory feeds know about it.