Images and publishing
NuGet feeds
Mirror nuget.org or a private feed for dotnet and Visual Studio, with the same checks as npm and PyPI.
- Settings, Registries: switch on NuGet feed.
- Add a NuGet registry. For nuget.org use
https://api.nuget.org/v3/index.json. For Azure Artifacts or GitHub Packages use the feed'sindex.jsonaddress and a token written asusername:personal-access-token. - Write NuGet rules: pattern
Newtonsoft.JsonorMicrosoft.Extensions.*, versions13.0.3,[13.0,14.0),13.*, or nothing for any version. - Developers add https://packages.example.com/nuget/v3/index.json to their
nuget.config. See Set up dotnet.
- A package id is one package in any case. Rules and kills match
newtonsoft.jsonandNewtonsoft.Jsonalike, and the box keeps the spelling the feed uses, which the advisory feed needs. - A bare version in a rule is that exact version. NuGet itself reads
13.0as "13.0 or newer", so write[13.0,)for that. - dotnet shows why a package was refused. The reason goes out in the
X-NuGet-Warningheader, and dotnet prints it as a warning. - Every package is scanned for malware, checked against the OSV advisories, has its SPDX license read, and waits out cooling off, the same as npm and PyPI. Auto approve and Cache now work for NuGet rules too.
- The feed offers the package list and downloads. Search and
dotnet nuget pushare not offered yet.