Keep bad packages out
Cooling off period for new package releases
Hijacked and malicious releases usually get noticed and pulled within a few days. Cooling off, in hours keeps brand new versions away from your builds for that long. 72 is a sensible start.
A version published more recently than the cooling off period is left out of the metadata the client reads, so a range like ^1.2.0 or >=1.2 quietly settles on the newest version that is old enough, and latest moves back with it. Asking for the young version by name, the way a lockfile does, gets a 403 that says when it will be served.
The publish time comes from the registry: npm's time field, and for PyPI the first upload of the release. A late wheel added to an old release does not make it young again. NuGet, Maven (for the newest few versions of a package), RubyGems, Composer and RPM give publish times too. CocoaPods, Swift and APT give none, so for those the A version with no publish time setting decides, and it lets them through unless you change it. The same setting covers a private registry that gives no times. Container images are not cooled off: a tag has no publish time to trust.
Your own builds are not held up. Never cooled off takes names and patterns like @yourcompany/*, and an allow rule pinned to one exact version skips the wait, since somebody already looked at it. A cooling off waiver can be granted for one package, scoped to one application or environment, with an end date.
This is not unique to ForgeRepo™, and we will not pretend otherwise: JFrog Curation, Sonatype Firewall and Cloudsmith all offer a package age policy in their paid tiers. Here it is simply on the Settings page of the free one.
In short
- Measured from the registry's own publish time, not when the box first saw it
- Applies to every package type that has a publish time, images excepted
- Ranges step back to the newest version that is old enough
- Lockfiles asking for a young version get a 403 that says when
- Exemptions for your own packages, and pinned allow rules skip the wait
- Every left out version is logged under Resolutions
In the documentation
- Cooling off new releases Administrator Guide
- Ask for a waiver Developer Guide
Goes well with
- Safe version resolution Versions with serious advisories are left out, so a range quietly settles on the newest safe one.
- Malware scanning ClamAV, a hash blocklist, your own scanner and the OpenSSF known malicious feed, on every cached file. Optionally before the first download.
- Waivers A written down, time boxed yes for one finding on one package, scoped to an app or environment.
One container, about two minutes
A Linux box with Docker, or one without it, and a reverse proxy for TLS. The installer does the rest and it is safe to run twice. Free, MIT licensed, nothing to sign up for.