Security protections
Vulnerabilities and safe version resolution
Keep known vulnerable versions out of installs automatically.
ForgeRepo™ checks cached and approved versions against osv.dev on a schedule (Hours between scans of the allow list, default 24), and checks a new version when it is first downloaded. CISA KEV and FIRST EPSS add whether an advisory is exploited in the wild and how likely it is to be.
Telling developers
- Answer npm audit:
npm auditgets its answer from these findings. The dependency tree never leaves the box. - Warn during the install: npm prints the advisory as the package installs.
- Record who downloaded what: every download of a vulnerable version is logged with the token and application.
Safe version resolution
Nothing on the Vulnerabilities page blocks by itself. Turn on Safe version resolution (Settings, Policy) and pick Leave out advisories from (default HIGH). Versions at or above that severity are then left out of metadata, so npm and pip pick the newest safe version within the range, and an exact download of one is refused with the advisory named.
Note
Advisories with an unknown severity are never left out. A waiver for the exact advisories lets a version back in. The Resolutions page shows what was left out and what the client picked instead.