Developers and approvals
Package requests, approvals and auto approve
A developer who hits a block sees the reason and a link. The request is already waiting for an approver, and it is already checked.
Blocked installs open a request on their own, for npm, pip, docker, dotnet, mvn, Bundler, pod, SwiftPM, Composer, dnf and apt alike, so approvers see what people are actually reaching for. Developers can also ask in the portal with a reason, or tick everything a reviewed lockfile needs and ask for it in one go. Repeats fold into one row.
Every request is checked the moment it arrives: its files are downloaded (which caches them), scanned for malware, and looked up in the advisory feeds. Each row says what was found, like "checked: malware scan clean, no advisories", so the decision takes a glance.
The four things you can do are on the row: approve writes the allow rule, block writes a deny rule at priority 1000, clear removes it without writing anything, and check deps walks the dependency tree first. Approving can also approve the request's clean dependencies, each pinned to the version the walk resolved.
Auto approve
With auto approve on, a request of any type whose every file scans clean and whose worst advisory is below High approves itself, pinned to the versions checked. A High or Critical advisory, no malware answer, a kill, a deny rule, a lookalike, a reserved name or a held license leaves it for a person, and the row says why. Cooling off and running scans make it wait and look again. Only admins can switch it, with a reason, and it is audited.
Developers get an hourly digest, never one mail per request, about what happened to theirs.
In short
- Blocked installs open requests automatically
- Scanned and advisory checked on arrival
- Approve, block, clear or check deps on the row
- Auto approve for clean requests, a person for risky ones
- Digests instead of a mail per event
In the documentation
- Deciding requests Administrator Guide
- Auto approve Administrator Guide
- Decide on requests Developer Guide
- Ask for a package or image Developer Guide
Goes well with
- Check, walk and review See what the rules say before you install. Walk a dependency tree. Review a lockfile or an SBOM.
- Allow lists and block lists Whitelist or blacklist by name, scope, wildcard or version range, for every type. A blocked version is not even listed to the client.
- Waivers A written down, time boxed yes for one finding on one package, scoped to an app or environment.
One container, about two minutes
A Linux box with Docker, or one without it, and a reverse proxy for TLS. The installer does the rest and it is safe to run twice. Free, MIT licensed, nothing to sign up for.