Security protections
Quarantine and integrity alerts
Files held for review, and files whose contents changed after they were first seen.
A file is held when malware scanning, provenance, license rules, an integrity alert, a person, or a new publish says it needs a look. Quarantine (Settings, Policy) decides what developers get meanwhile:
| Mode | Held files |
|---|---|
| permissive (default) | Still served, with a QUARANTINE warning printed by npm. |
| strict | Refused with a 403 and left out of metadata. |
| any mode | Rejected files are always refused. |
release serves the file normally. reject refuses it for good. Holds belong to the file itself, so purging and downloading it again does not escape one.
Integrity alerts
The first copy of a file wins. If npm or PyPI later publish a different hash for the same version, or a download returns different bytes, ForgeRepo™ raises an integrity alert, holds the file and keeps serving the original bytes. On Integrity alerts, accept takes the new file and keep original dismisses the alert.
Careful
A changed file for a version that was already published is a classic sign of a compromised registry account. Check before you accept.