Rules and approvals
Whitelist, blacklist and audit mode
Choose whether unknown packages are blocked or allowed, and how to switch safely.
12
- Whitelist or blacklist
- Serve everything and record what would be blocked
| Mode | No rule matches | Best for |
|---|---|---|
| whitelist | Blocked | The strongest protection. Every package needs an allow rule. |
| blacklist | Allowed | Getting started. Only deny rules and the security checks stop anything. |
Audit only (learning mode)
With Audit only on, everything the rules would block is served anyway and recorded as "would have blocked". A request is opened for each package with the exact versions used. The kill switch still blocks in audit mode. Safe resolution, cooling off, license holds and lookalike blocking do not.
- Turn on Audit only in whitelist mode and point your pipelines at packages.example.com.
- Let a few weeks of normal builds run.
- On Requests, approve what your teams really use. Tick several and use Approve selected.
- Check Traffic with Show: would have blocked until it is quiet.
- Turn Audit only off.
Tip
Use Dry run before a big rule change to see who would be affected. See Dry run.