Blocked packages and requests
Review a whole lock file
Upload a lock file, an SBOM or a software inventory and see what the rules make of every package, of every type.
On Check a package, scroll to Review a file. Pick your lock file and click Review it. The file is read in memory and is not kept.
- Pick your lockfile, then review it
Each row says whether the version is allowed, blocked or needs a decision, and lists known advisories. Tick the rows that need a decision to ask for all of them at once.
Every package is judged by the rules of its own type. A NuGet package is judged by the NuGet rules, never by an npm rule with the same name. The type shows next to each name.
- SBOMs: CycloneDX (JSON or XML) and SPDX. The package url says the type, like pkg:nuget/Serilog@2.12.0. When a tool leaves the purl out, the bom-ref is read instead.
- Inventories: a CSV or JSON export from another tool, one package per row. An ecosystem column (nuget, pypi, maven, gem, cocoapods, swift, npm) or a purl column says the type. Without one, every row is read as npm.
- Repeats: a package listed once per repository is read once.
- Left out: repositories, applications and types this registry has no rules for, like golang or cargo. The notes count them.
Note
A type that is switched off on this box is left out, and the notes say so. An admin can switch it on under Settings.