Keep bad packages out
Safe version resolution
npm and pip pick a version themselves from the list the registry hands them. Safe version resolution changes the list, so they pick a safe one without anybody editing a lockfile.
With it on, any version with a known advisory at or above the chosen severity (HIGH by default) is left out of the npm packument, the PyPI project page and the JSON API, and the version lists of every other type with an OSV feed: NuGet, Maven, RubyGems, Swift, Composer, RPM and APT. It is refused with a 403 when something asks for it directly. The client then picks normally from what is left. CocoaPods has no advisory feed, so nothing is left out there.
Nothing outside the range the developer asked for is ever swapped in. If every version inside ^4.17.0 is excluded, the install fails and says so, rather than quietly getting something else. That is the right way round: a surprise major version is its own kind of outage.
Every answer that left something out is logged under Activity, Resolutions: the package, the token's application and environment, how many versions were offered, what was excluded and why, and the version the client then downloaded.
For container images, an image with serious advisories that an upgrade fixes is refused, naming the advisories. Only count what has a fix keeps unfixable operating system CVEs from blocking everything.
A team that needs a vulnerable version for a while asks for a waiver: it names the advisory ids, so a new advisory published later is never covered by an old waiver.
In short
- Pick the lowest severity that gets a version left out
- Metadata is trimmed, so ranges resolve to the newest safe version
- Exact downloads of an excluded version get a 403 with the advisory
- Never swaps in a version outside the requested range
- Every exclusion logged with the version that was chosen instead
In the documentation
- Vulnerabilities and safe version resolution Administrator Guide
- See known vulnerabilities Developer Guide
Goes well with
- Vulnerability monitoring OSV, CISA KEV and FIRST EPSS against everything allowed and cached. npm audit answered locally.
- Waivers A written down, time boxed yes for one finding on one package, scoped to an app or environment.
- Cooling off new releases Brand new versions wait a few days before your builds see them, which is when hijacks get caught.
One container, about two minutes
A Linux box with Docker, or one without it, and a reverse proxy for TLS. The installer does the rest and it is safe to run twice. Free, MIT licensed, nothing to sign up for.