Rules and approvals
Writing rules
Patterns, version ranges, priority and scope, and how the winning rule is chosen.
- Higher priority wins first
- Scope a rule to the tokens of one application or environment
| Field | Notes |
|---|---|
| Pattern | A name or a pattern where * matches anything, including the / in a scope. Up to 5 wildcards. |
| Kind | allow or deny. A deny with a version range only blocks those versions, the rest of the package still comes through. |
| Version range | Empty means every version. See the table below. |
| Priority | -1000 to 1000, default 0. Compared first. |
| Only for application / Only in environment | Limits the rule to tokens in that scope. |
| Note | Why the rule exists. Shown to approvers, and worth writing. |
| Type | Version range examples |
|---|---|
| npm | 4.21.2, 1.2.*, ^4.0.0, ~1.2.0, >=4.17.21, 1.2.3 || 1.4.5 |
| PyPI | ==2.31.*, ~=2.31.0, >=2.31,<3, >=2.31,!=2.32.1 |
| images | latest, 1.27.*, stable-alpine, sha256:..., joined with || |
- npm deny rules match names in any letter case. Allow rules match the exact case.
- An allow covers a prerelease like
2.0.0-beta.1only when its range names a prerelease. An allow with no range never covers prereleases. - Paste a list adds up to 2000 names at once.
- Tick rules to flip, enable, disable or delete them together.
Caching approved versions ahead of time
Tick allow rules and click Cache now to download them before anyone needs them, up to 2000 files. A rule that pins exact versions caches those. A rule for any version caches the current release, and a range like ^4.0.0 caches the newest version it allows, without changing the rule. An image rule with a tag pattern like 1.27.* is skipped. Saving an allow rule for every version also caches the current version in the background when Cache the current version of any-version rules is on.
Note
For an image, Cached counts a tag only when every image in its list, and the config and every layer of each, is on disk. Walking an image's dependency tree or pulling one platform learns part of it, so the cell says how far along it is, like "26.04: 12 of 30 files downloaded". Cache now downloads the rest.