Images and publishing
CocoaPods CDNs
Mirror the CocoaPods CDN for pod install. The code of each pod is fetched and scanned by this box.
- Settings, Registries: switch on CocoaPods CDN.
- Add a CocoaPods registry. For the public pods use
https://cdn.cocoapods.org. - Write pod rules: pattern
AlamofireorFirebase*, versions5.9.1or~> 5.9. - Developers add the source line to their Podfile. See Set up CocoaPods.
- The CDN only describes a pod. Its code is a git tag, usually on GitHub. ForgeRepo™ fetches the tag archive itself, keeps and scans it, and the podspec it hands out points pod at that copy.
- A pod whose code cannot be fetched as a fixed archive is refused: a git branch or commit, git submodules, svn, or a download that does not match the checksum in its podspec. Sources on an internal address are never fetched.
- The version lists hold only allowed pods and versions, so a pod nobody approved is not found. Only a download of an unapproved version opens a request.
- OSV has no CocoaPods feed, so pods get no advisories. Malware scanning, licenses, the kill switch, auto approve and Cache now all work.
- A podspec can hold a
prepare_command, a shell command pod runs on the developer's machine. Approving a pod approves that too.