Blocked packages and requests
When something is blocked
Read the reason, then ask for the package or pick a different version.
A blocked install fails with a 403 error. The message says what was refused and why.
npm
$ npm install left-pad npm error code E403 npm error 403 403 Forbidden - GET https://packages.example.com/left-pad - left-pad is not approved on this registry. Reason: not on the whitelist. Ask for it at https://packages.example.com/_admin. It is being scanned and checked now, and approved by itself if it comes back clean. Try again in up to 10 minutes. npm error 403 In most cases, you or one of your dependencies are requesting npm error 403 a package version that is forbidden by your security policy, or npm error 403 on a server you do not have access to. npm error A complete log of this run can be found in: /root/.npm/_logs/2026-09-18T19_26_46_722Z-debug-0.log
Captured by running these commands against a real ForgeRepo™.
docker
$ docker pull packages.example.com/redis:latest Error response from daemon: pull access denied for packages.example.com/redis, repository does not exist or may require 'docker login': denied: redis:latest is not approved on this registry. Reason: not on the whitelist. Ask for it at https://packages.example.com/_admin. It is being scanned and checked now, and approved by itself if it comes back clean. Try again in up to 30 minutes.
Captured by running these commands against a real ForgeRepo™.
pip
pip hides the reason and only says "No matching distribution found". Ask packages.example.com directly to see it:
$ . .venv/bin/activate && pip install numpy Looking in indexes: https://__token__:****@packages.example.com/pypi/simple/ ERROR: Could not find a version that satisfies the requirement numpy (from versions: none) ERROR: No matching distribution found for numpy $ curl -s -u "__token__:$REPO_TOKEN" https://packages.example.com/pypi/simple/numpy/ numpy is not approved on this registry. Reason: not on the whitelist. Ask for it at https://packages.example.com/_admin. It is being scanned and checked now, and approved by itself if it comes back clean. Try again in up to 10 minutes.
Captured by running these commands against a real ForgeRepo™.
mvn
mvn prints the reason in the error line, after the status code:
$ mvn -B -q package ... [ERROR] Failed to read artifact descriptor for org.yaml:snakeyaml:jar:2.2 [ERROR] Caused by: The following artifacts could not be resolved: org.yaml:snakeyaml:pom:2.2 (absent): Could not transfer artifact org.yaml:snakeyaml:pom:2.2 from/to company (https://packages.example.com/maven/): status code: 403, reason phrase: org.yaml:snakeyaml 2.2 is not approved on this registry. Reason: not on the whitelist. Ask for it at https://packages.example.com/_admin. It is being scanned and checked now, and approved by itself if it comes back clean. Try again in up to 10 minutes. (403)
Captured by running these commands against a real ForgeRepo™.
dotnet
dotnet prints the reason as a warn line, then fails with "There are no versions available for the package":
$ dotnet add package Dapper ... warn : Dapper is not approved on this registry. Reason: not on the whitelist. Ask for it at https://packages.example.com/_admin. It is being scanned and checked now, and approved by itself if it comes back clean. Try again in up to 10 minutes. info : NotFound https://packages.example.com/nuget/v3/registration/dapper/index.json 265ms info : GET https://packages.example.com/nuget/v3/registration/dapper/index.json warn : Dapper is not approved on this registry. Reason: not on the whitelist. Ask for it at https://packages.example.com/_admin. It is being scanned and checked now, and approved by itself if it comes back clean. Try again in up to 10 minutes. info : NotFound https://packages.example.com/nuget/v3/registration/dapper/index.json 9ms error: There are no versions available for the package 'Dapper'.
Captured by running these commands against a real ForgeRepo™.
Common reasons
| The reason says | What it means | What to do |
|---|---|---|
| not on the whitelist | Nobody has approved this package yet. | Ask for it. It may already be waiting. |
| blocked by rule | Someone decided this package or version must not be used. | Pick another package or version. Ask an approver why if it is not clear. |
| on the kill switch | The version was found to be malicious or compromised. The text after it says why. | Stop using it now. Move to a version that is not killed. |
| advisory ... safe resolution leaves out | The version has known vulnerabilities at or above the level your company refuses. | Upgrade to a fixed version, or ask for a waiver. |
| held in quarantine | The file is being checked, for example by a malware scan, or failed a check. | Try again later, or use the version before it. |
| new versions wait ... hours | The version is very new. New releases wait a while in case they turn out to be malicious. The message says when it will be served. | Use the previous version for now, or ask for a cooling off waiver. |
| a possible typosquat | The name looks like a popular package with a letter changed. | Check the spelling. You probably meant the package it names. |
See also: Ask for a package or image, Check before you install