How it works
How ForgeRepo™ works
One registry for npm, PyPI and container images that checks every download against your rules and your security settings.
ForgeRepo™ answers npm, pip and docker at packages.example.com. It fetches packages and images from the public registries, keeps a copy, and serves them only when every check agrees. Nothing is installed straight from the internet.
- Kill switch. Beats everything, including allow rules and audit mode.
- Rules. Whitelist or blacklist, scoped by the token's application and environment.
- Lookalike names. Warns or blocks names that imitate popular packages.
- Fetch. Reserved names are never fetched from outside. Degraded and lockdown modes limit what is fetched.
- Holds and policies. Quarantine holds, safe version resolution for known vulnerabilities, cooling off for brand new releases, and license rules.
- Last checks on the file. A kill by file hash, and an optional malware or image scan before the file is served.
Two ways a version is left out
- In metadata. When npm or pip asks which versions exist, blocked versions are removed and
latestmoves to the newest allowed version. The client picks an allowed version on its own. - On download. A lock file asks for an exact file. That request runs every check again and gets a 403 with the reason.
Note
Checks run on the server for every request. Hiding a button in the portal is only tidiness. Roles are enforced by the API.
See also: Writing rules, Applications, environments and token scope, Registry modes: degraded and lockdown