Product

Overview

How it works Watch it work All 35 features Screenshots How ForgeRepo™ is secured

Keep bad packages out

Malware scanning Typosquat detection Dependency confusion protection Cooling off new releases Allow lists and block lists

When something goes wrong

Kill switch Who has it Lockdown and degraded modes Vulnerability monitoring

Developers and approvals

Requests and auto approve Check, walk and review Waivers Dry run
Formats

Languages

Private npm registry PyPI proxy and private index Private NuGet feed and proxy Maven repository proxy RubyGems mirror Composer and Packagist proxy

Apple, containers and Linux

CocoaPods CDN mirror Swift package registry Docker registry mirror RPM mirror for dnf and yum APT mirror for Debian and Ubuntu

Use it as

An npm firewall Artifacts, SBOMs and lifecycle More than one node SSO, roles and allow lists
Learn

Guides

Learn secure development Secure coding Secure pipelines Unsafe vs safe Security and development

Supply chain

Supply chain attacks, 2016 to 2026 Software supply chain security
Compare Side by side, all four ForgeRepo™ vs JFrog ForgeRepo™ vs Sonatype ForgeRepo™ vs Cloudsmith
Docs

Start

Getting started Download All documentation Questions

For developers

npm setup pip setup docker login Push a Docker image CI basics

For administrators

First setup Rules and their order Six incidents, walked through Backup and upgrade
Pricing Install it

Blocked packages and requests

When something is blocked

Read the reason, then ask for the package or pick a different version.

A blocked install fails with a 403 error. The message says what was refused and why.

npm

What a blocked package looks like
$ npm install left-pad
npm error code E403
npm error 403 403 Forbidden - GET https://packages.example.com/left-pad - left-pad is not approved on this registry. Reason: not on the whitelist. Ask for it at https://packages.example.com/_admin. It is being scanned and checked now, and approved by itself if it comes back clean. Try again in up to 10 minutes.
npm error 403 In most cases, you or one of your dependencies are requesting
npm error 403 a package version that is forbidden by your security policy, or
npm error 403 on a server you do not have access to.
npm error A complete log of this run can be found in: /root/.npm/_logs/2026-09-18T19_26_46_722Z-debug-0.log

Captured by running these commands against a real ForgeRepo™.

docker

What a blocked image looks like
$ docker pull packages.example.com/redis:latest
Error response from daemon: pull access denied for packages.example.com/redis, repository does not exist or may require 'docker login': denied: redis:latest is not approved on this registry. Reason: not on the whitelist. Ask for it at https://packages.example.com/_admin. It is being scanned and checked now, and approved by itself if it comes back clean. Try again in up to 30 minutes.

Captured by running these commands against a real ForgeRepo™.

pip

pip hides the reason and only says "No matching distribution found". Ask packages.example.com directly to see it:

What a blocked project looks like in pip
$ . .venv/bin/activate && pip install numpy
Looking in indexes: https://__token__:****@packages.example.com/pypi/simple/
ERROR: Could not find a version that satisfies the requirement numpy (from versions: none)
ERROR: No matching distribution found for numpy
$ curl -s -u "__token__:$REPO_TOKEN" https://packages.example.com/pypi/simple/numpy/
numpy is not approved on this registry. Reason: not on the whitelist. Ask for it at https://packages.example.com/_admin. It is being scanned and checked now, and approved by itself if it comes back clean. Try again in up to 10 minutes.

Captured by running these commands against a real ForgeRepo™.

mvn

mvn prints the reason in the error line, after the status code:

What a blocked Maven package looks like
$ mvn -B -q package
...
[ERROR] Failed to read artifact descriptor for org.yaml:snakeyaml:jar:2.2
[ERROR] 	Caused by: The following artifacts could not be resolved: org.yaml:snakeyaml:pom:2.2 (absent): Could not transfer artifact org.yaml:snakeyaml:pom:2.2 from/to company (https://packages.example.com/maven/): status code: 403, reason phrase: org.yaml:snakeyaml 2.2 is not approved on this registry. Reason: not on the whitelist. Ask for it at https://packages.example.com/_admin. It is being scanned and checked now, and approved by itself if it comes back clean. Try again in up to 10 minutes. (403)

Captured by running these commands against a real ForgeRepo™.

dotnet

dotnet prints the reason as a warn line, then fails with "There are no versions available for the package":

What a blocked NuGet package looks like
$ dotnet add package Dapper
...
warn : Dapper is not approved on this registry. Reason: not on the whitelist. Ask for it at https://packages.example.com/_admin. It is being scanned and checked now, and approved by itself if it comes back clean. Try again in up to 10 minutes.
info :   NotFound https://packages.example.com/nuget/v3/registration/dapper/index.json 265ms
info :   GET https://packages.example.com/nuget/v3/registration/dapper/index.json
warn : Dapper is not approved on this registry. Reason: not on the whitelist. Ask for it at https://packages.example.com/_admin. It is being scanned and checked now, and approved by itself if it comes back clean. Try again in up to 10 minutes.
info :   NotFound https://packages.example.com/nuget/v3/registration/dapper/index.json 9ms
error: There are no versions available for the package 'Dapper'.

Captured by running these commands against a real ForgeRepo™.

Common reasons

The reason saysWhat it meansWhat to do
not on the whitelistNobody has approved this package yet.Ask for it. It may already be waiting.
blocked by ruleSomeone decided this package or version must not be used.Pick another package or version. Ask an approver why if it is not clear.
on the kill switchThe version was found to be malicious or compromised. The text after it says why.Stop using it now. Move to a version that is not killed.
advisory ... safe resolution leaves outThe version has known vulnerabilities at or above the level your company refuses.Upgrade to a fixed version, or ask for a waiver.
held in quarantineThe file is being checked, for example by a malware scan, or failed a check.Try again later, or use the version before it.
new versions wait ... hoursThe version is very new. New releases wait a while in case they turn out to be malicious. The message says when it will be served.Use the previous version for now, or ask for a cooling off waiver.
a possible typosquatThe name looks like a popular package with a letter changed.Check the spelling. You probably meant the package it names.

See also: Ask for a package or image, Check before you install