Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
122 commits
Select commit Hold shift + click to select a range
643f699
experimental filtering pills
kokes Sep 4, 2026
94c11b4
align data in the dashboard table more nicely (#318)
kokes Sep 6, 2026
7e4b13c
Bump zizmorcore/zizmor-action from 0.6.2 to 0.6.3 (#333)
dependabot[bot] Sep 10, 2026
f0580d9
Bump docker/setup-qemu-action from 4.2.0 to 4.3.0 (#331)
dependabot[bot] Sep 10, 2026
8d3dacf
Bump azure/setup-helm from 4.3.1 to 5.0.1 (#332)
dependabot[bot] Sep 10, 2026
dc1ce8d
Bump modernc.org/sqlite from 1.57.0 to 1.58.0 (#337)
dependabot[bot] Sep 14, 2026
0935c15
Bump github.com/aws/aws-sdk-go-v2/config from 1.32.40 to 1.33.2 (#336)
dependabot[bot] Sep 14, 2026
66a6d81
Bump github.com/prometheus/client_model from 0.6.2 to 0.6.3 (#330)
dependabot[bot] Sep 14, 2026
83e7e80
Bump golang.org/x/sync from 0.22.0 to 0.23.0 (#335)
dependabot[bot] Sep 14, 2026
f29c916
Bump github.com/aws/aws-sdk-go-v2/service/ecr from 1.61.0 to 1.64.0 (…
dependabot[bot] Sep 14, 2026
8696a25
fix(handler): let the ProxyCached path request a per-call Accept-Enco…
pinguinfuss Sep 15, 2026
eb45cd5
Fix duplicate fetches and 502s on concurrent cache misses (#329)
montehurd Sep 15, 2026
4436130
Bump google.golang.org/grpc from 1.83.1 to 1.83.2 (#346)
dependabot[bot] Sep 15, 2026
0089917
Stop writing fileblob's .attrs sidecar (#328)
montehurd Sep 15, 2026
8a51d04
feat(debian): serve additional APT archives at /debian/{name}/
andrewmrich Sep 14, 2026
be2a1f0
fix(server): tune the shared upstream transport defaults (#351)
pinguinfuss Sep 16, 2026
3db2cd5
fix(database): set connection pool limits for Postgres (#350)
pinguinfuss Sep 16, 2026
ba45227
test(database): drop every schema table in the Postgres fixture (#349)
pinguinfuss Sep 16, 2026
7835f7a
Discard a stale cache entry under the coalescing key (#348)
montehurd Sep 16, 2026
0bab9bd
Separate OCI request timeout from readiness probes in loopback test (…
andrew Sep 16, 2026
c895e5b
Fix NuGet cooldown enforcement for listings and downloads (#340)
abhinavgautam01 Sep 16, 2026
2736fe0
Fall back to embedded build info for Version (#352)
andrew Sep 16, 2026
8805cd9
Merge branch 'git-pkgs:main' into arich/debian-repositories
andrewmrich Sep 16, 2026
46faf76
docs(debian): trim comments on the named-repositories change
andrewmrich Sep 16, 2026
658664a
docs(debian): drop a stray space in a test comment
andrewmrich Sep 16, 2026
2ae6213
Bump github.com/aws/aws-sdk-go-v2/service/ecr from 1.64.0 to 1.65.0 (…
dependabot[bot] Sep 17, 2026
2aad8bf
Bump github.com/git-pkgs/spdx from 0.3.1 to 0.3.2 (#355)
dependabot[bot] Sep 17, 2026
b83bc0e
Bump zizmorcore/zizmor-action from 0.6.3 to 0.6.4 (#354)
dependabot[bot] Sep 17, 2026
b2817dc
Bump github.com/aws/aws-sdk-go-v2/config from 1.33.2 to 1.33.4 (#356)
dependabot[bot] Sep 17, 2026
9788aa7
feat(debian): report a misspelled repository name
andrewmrich Sep 18, 2026
429e745
fix(helm): support OCI references in HTTP repository indexes
abhinavgautam01 Sep 19, 2026
548a50d
feat: add exact-version package denylist
abhinavgautam01 Sep 20, 2026
499033b
Exit non-zero when mirror denylist is invalid
andrew Sep 21, 2026
54cfb30
Merge pull request #360 from abhinavgautam01/feat/version-denylist-358
andrew Sep 21, 2026
1da2dc0
Merge pull request #359 from abhinavgautam01/fix/helm-oci-index-320
andrew Sep 21, 2026
8b1e7cb
Omit malformed Helm chart releases instead of failing the index
andrew Sep 21, 2026
e287457
Merge pull request #353 from andrewmrich/arich/debian-repositories
andrew Sep 21, 2026
1001cd7
End an eviction pass that cannot evict anything
montehurd Sep 21, 2026
8f09c1d
Fix the handler test build
montehurd Sep 21, 2026
ee60ab7
Merge pull request #362 from montehurd/fix-handler-test-build
andrew Sep 22, 2026
c753a74
docs: explain APT denylist limitations and version pinning
abhinavgautam01 Sep 22, 2026
e6271a8
Merge pull request #364 from abhinavgautam01/docs/apt-denylist-pinnin…
andrew Sep 22, 2026
73a9863
Assert omitted Helm releases are not downloadable
andrew Sep 22, 2026
f3445b5
Merge pull request #361 from git-pkgs/helm-skip-malformed-releases
andrew Sep 22, 2026
442b591
build(deps): bump go.opentelemetry.io/otel/sdk from 1.44.0 to 1.45.0
dependabot[bot] Sep 22, 2026
65f2bf5
Widen wall-clock bound in flaky probe timeout test
andrew Sep 22, 2026
e94805e
Merge pull request #365 from git-pkgs/dependabot/go_modules/go.opente…
andrew Sep 22, 2026
50e5cc3
Merge branch 'git-pkgs:main' into bound-eviction-pass
montehurd Sep 22, 2026
c1f420a
Add and align CI security and dependency automation
andrew Sep 23, 2026
a55f42e
fix(mirror): match cached artifacts by resolved filename
abhinavgautam01 Sep 23, 2026
00a49e2
Standardize the README license footer
andrew Sep 23, 2026
cd7d92e
Merge pull request #366 from abhinavgautam01/fix/mirror-cache-hit-342
andrew Sep 23, 2026
37ef25b
Merge pull request #363 from montehurd/bound-eviction-pass
andrew Sep 23, 2026
e635a62
Test that GCS Delete of a missing object returns nil
andrew Sep 23, 2026
4ce6c37
Give each fetch its own storage path
montehurd Sep 23, 2026
3724c93
build(deps): bump docker/setup-buildx-action from 4.3.0 to 4.4.1
dependabot[bot] Sep 24, 2026
15d5ac0
build(deps): bump docker/setup-qemu-action from 4.3.0 to 4.4.0
dependabot[bot] Sep 24, 2026
d14b240
build(deps): bump docker/build-push-action from 7.3.0 to 7.4.0
dependabot[bot] Sep 24, 2026
8bbe117
build(deps): bump github.com/aws/aws-sdk-go-v2/service/ecr
dependabot[bot] Sep 24, 2026
468e9e5
build(deps): bump golang.org/x/net from 0.58.0 to 0.59.0
dependabot[bot] Sep 24, 2026
ceee79f
build(deps): bump github.com/git-pkgs/registries from 0.9.1 to 0.9.2
dependabot[bot] Sep 24, 2026
2a35d3d
build(deps): bump github.com/git-pkgs/magic from 0.3.1 to 0.4.0
dependabot[bot] Sep 24, 2026
fbb89c9
build(deps): bump modernc.org/sqlite from 1.58.0 to 1.59.0
dependabot[bot] Sep 24, 2026
3611ff2
build(deps): bump github.com/git-pkgs/vers from 0.7.0 to 0.7.1
dependabot[bot] Sep 24, 2026
c3fc32b
Merge pull request #368 from git-pkgs/dependabot/github_actions/docke…
andrew Sep 24, 2026
a7cccff
Merge pull request #369 from git-pkgs/dependabot/github_actions/docke…
andrew Sep 24, 2026
e26c2d1
Merge pull request #370 from git-pkgs/dependabot/github_actions/docke…
andrew Sep 24, 2026
a4702d0
Merge pull request #371 from git-pkgs/dependabot/go_modules/github.co…
andrew Sep 24, 2026
e4682c8
Merge pull request #372 from git-pkgs/dependabot/go_modules/golang.or…
andrew Sep 24, 2026
4f80102
Merge pull request #373 from git-pkgs/dependabot/go_modules/github.co…
andrew Sep 24, 2026
43a91ec
Merge pull request #374 from git-pkgs/dependabot/go_modules/github.co…
andrew Sep 24, 2026
7379f47
Merge pull request #376 from git-pkgs/dependabot/go_modules/modernc.o…
andrew Sep 24, 2026
10ebb52
Merge pull request #377 from git-pkgs/dependabot/go_modules/github.co…
andrew Sep 24, 2026
ccc80f8
build(deps): bump github.com/aws/aws-sdk-go-v2/config
dependabot[bot] Sep 24, 2026
3655694
Merge pull request #378 from git-pkgs/dependabot/go_modules/github.co…
andrew Sep 24, 2026
eedc290
build(deps): bump github.com/git-pkgs/archives from 0.7.0 to 0.7.1
dependabot[bot] Sep 24, 2026
b5fcee5
Merge pull request #375 from git-pkgs/dependabot/go_modules/github.co…
andrew Sep 24, 2026
e40c78f
fix(conda): preserve gzip for large repodata indexes
abhinavgautam01 Sep 25, 2026
b00da65
Merge pull request #379 from abhinavgautam01/fix/conda-repodata-gzip-321
andrew Sep 26, 2026
ac261cc
fix: centralize pass-through response relaying
abhinavgautam01 Sep 26, 2026
436155e
Clear before deleting on eviction, and requeue failed reclaims
montehurd Sep 29, 2026
eb43505
Log and count requests aborted mid-relay
andrew Oct 1, 2026
6f2bc9a
Merge pull request #367 from montehurd/per-fetch-storage-path
andrew Oct 1, 2026
c3540fb
Merge pull request #380 from abhinavgautam01/fix/response-relay-326
andrew Oct 1, 2026
4827cb9
Batch cache hit writes
montehurd Oct 1, 2026
c4f34b0
fix pnpm audit
wickedOne Sep 30, 2026
d8a8111
apply review changes
wickedOne Oct 1, 2026
b6f11db
Merge pull request #382 from wickedOne/npm-audit
andrew Oct 1, 2026
fb04bb8
Name every mounted route in requestEcosystem
wickedOne Oct 1, 2026
e738a21
test(handler): stop asserting on an upstream connection the proxy aba…
wickedOne Oct 1, 2026
fb1630a
Merge pull request #395 from wickedOne/relay-test-flake
andrew Oct 1, 2026
4ebd805
Per-ecosystem cache and download statistics
wickedOne Oct 1, 2026
0501534
Add the /ui/analytics page
wickedOne Oct 1, 2026
4b8c5a8
Report the per-ecosystem breakdown from GET /stats
wickedOne Oct 1, 2026
36fe6ab
Add a Grafana dashboard
wickedOne Oct 1, 2026
3655000
Attribute requests to a caller and a client tool
wickedOne Oct 1, 2026
5f0f3b0
Update enrichment to v0.7.2 (#394)
andrew Oct 1, 2026
51caa17
Update git-pkgs dependencies (#396)
andrew Oct 1, 2026
55ed6b9
Keep hit timestamps from moving backwards
montehurd Oct 1, 2026
107301c
build(deps): bump alpine from 3.24.1 to 3.24.2 (#397)
dependabot[bot] Oct 1, 2026
76db945
Install development tools directly in CI (#398)
andrew Oct 1, 2026
b40a50a
Add storage.cache_artifacts to serve artifacts without storing them (…
DANIILSKRIPCHENKO Oct 2, 2026
2124e8c
Merge pull request #383 from montehurd/batch-hit-updates
andrew Oct 2, 2026
82f5e66
Merge pull request #388 from wickedOne/analytics-1-route-coverage
andrew Oct 2, 2026
9dff45d
Merge remote-tracking branch 'origin/main' into analytics-2-ecosystem…
andrew Oct 2, 2026
f40f839
Merge pull request #389 from wickedOne/analytics-2-ecosystem-stats
andrew Oct 2, 2026
31b7378
Merge pull request #390 from wickedOne/analytics-3-page
andrew Oct 2, 2026
7c129f9
Merge pull request #391 from wickedOne/analytics-4-stats-breakdown
andrew Oct 2, 2026
5fce187
Merge pull request #392 from wickedOne/analytics-5-grafana
andrew Oct 2, 2026
4261bcb
Show the by-client table regardless of ui_request_sources
andrew Oct 2, 2026
e7817dc
Merge pull request #393 from wickedOne/analytics-6-source-attribution
andrew Oct 2, 2026
739bba3
Drop unused registry from TestUpdateEcosystemStatsSumsAliasedRows
andrew Oct 2, 2026
8cc63c4
Cache rewritten npm and Composer metadata (#402)
montehurd Oct 3, 2026
4b1625b
Copy inherited Composer fields shallowly when expanding (#401)
montehurd Oct 3, 2026
f60772d
Support HTTP byte-range requests for local file cached artifact downl…
PhantomPhoton Oct 4, 2026
dc1fc5b
Coalesce concurrent metadata fetches (#400)
montehurd Oct 4, 2026
34985b5
Support npm content-addressed tarball URLs
andrew Oct 4, 2026
8d6c5ca
Merge pull request #406 from git-pkgs/fix/npm-metadata-tarballs
andrew Oct 4, 2026
866e559
Add cooldown package pattern overrides (#407)
andrew Oct 4, 2026
3901435
Fix cached package ecosystem filters
andrew Oct 5, 2026
54aafe3
Merge original ecosystem filter proposal
andrew Oct 5, 2026
88bccdf
Update supportedEcosystems comment for filter pills
andrew Oct 5, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 5 additions & 2 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -43,8 +43,11 @@ jobs:
with:
go-version-file: go.mod

- name: Install golangci-lint
run: go install github.com/golangci/golangci-lint/v2/cmd/golangci-lint@v2.13.1

- name: golangci-lint
run: go tool golangci-lint run ./...
run: golangci-lint run ./...

helm:
name: Helm chart
Expand All @@ -54,7 +57,7 @@ jobs:
with:
persist-credentials: false

- uses: azure/setup-helm@1a275c3b69536ee54be43f2070a358922e12c8d4 # v4.3.1
- uses: azure/setup-helm@9bc31f4ebc9c6b171d7bfbaa5d006ae7abdb4310 # v5.0.1
with:
version: v3.18.6

Expand Down
8 changes: 4 additions & 4 deletions .github/workflows/publish.yml
Original file line number Diff line number Diff line change
Expand Up @@ -26,12 +26,12 @@ jobs:
persist-credentials: false

- name: Set up QEMU
uses: docker/setup-qemu-action@96fe6ef7f33517b61c61be40b68a1882f3264fb8 # v4.2.0
uses: docker/setup-qemu-action@99012661954931238ded8c8b007157a8430204e1 # v4.4.0
with:
platforms: linux/amd64,linux/arm64

- name: Set up Docker Buildx
uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4.3.0
uses: docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4.4.1

- name: Log in to the Container registry
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f
Expand All @@ -50,7 +50,7 @@ jobs:

- name: Build and push Docker image
id: build
uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a
uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc
with:
context: .
platforms: linux/amd64,linux/arm64
Expand Down Expand Up @@ -112,7 +112,7 @@ jobs:
persist-credentials: false
ref: ${{ github.sha }}

- uses: azure/setup-helm@1a275c3b69536ee54be43f2070a358922e12c8d4 # v4.3.1
- uses: azure/setup-helm@9bc31f4ebc9c6b171d7bfbaa5d006ae7abdb4310 # v5.0.1
with:
version: v3.18.6

Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/swagger.yml
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@ jobs:
go-version-file: go.mod

- name: Install swag
run: go install github.com/swaggo/swag/cmd/swag@latest
run: go install github.com/swaggo/swag/cmd/swag@v1.16.6

- name: Generate swagger
run: go generate ./internal/server
Expand Down
18 changes: 13 additions & 5 deletions .github/workflows/zizmor.yml
Original file line number Diff line number Diff line change
Expand Up @@ -5,14 +5,22 @@ on:
branches:
- main
paths:
- '.github/workflows/**'
- '.github/**'
- '**/action.yml'
- '**/action.yaml'
- 'zizmor.yml'
- 'zizmor.yaml'
pull_request:
branches:
- main
paths:
- '.github/workflows/**'
- '.github/**'
- '**/action.yml'
- '**/action.yaml'
- 'zizmor.yml'
- 'zizmor.yaml'
workflow_dispatch:

permissions: {}

jobs:
zizmor:
runs-on: ubuntu-latest
Expand All @@ -26,4 +34,4 @@ jobs:
persist-credentials: false

- name: Run zizmor
uses: zizmorcore/zizmor-action@3dc1ecc9bcb9e94e9b2c709687979e1298497054 # v0.6.2
uses: zizmorcore/zizmor-action@cc914d7f3750a2d13d75c7f184a1060aa0e9d482 # v0.6.4
1 change: 1 addition & 0 deletions CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -160,6 +160,7 @@ mux.Handle("/newregistry/", http.StripPrefix("/newregistry", newHandler.Routes()
- Keep functions short and focused
- Write tests for new functionality
- Document exported types and functions
- A new Prometheus metric needs a tile on `/ui/analytics` and an entry in `metricSurface` (`internal/server/analytics_coverage_test.go`). The page is meant to be a complete view of `/metrics`, so `TestEveryMetricIsSurfaced` fails until both exist.

## Testing

Expand Down
2 changes: 1 addition & 1 deletion Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@ COPY . .
ARG TARGETARCH
RUN CGO_ENABLED=0 GOOS=linux GOARCH=${TARGETARCH} go build -ldflags="-s -w" -o /proxy ./cmd/proxy

FROM alpine:3.24.1
FROM alpine:3.24.2

RUN apk add --no-cache ca-certificates

Expand Down
113 changes: 110 additions & 3 deletions README.md

Large diffs are not rendered by default.

21 changes: 21 additions & 0 deletions cmd/proxy/main.go
Original file line number Diff line number Diff line change
Expand Up @@ -106,11 +106,13 @@ import (
"log/slog"
"os"
"os/signal"
"runtime/debug"
"strings"
"syscall"

"github.com/git-pkgs/proxy/internal/config"
"github.com/git-pkgs/proxy/internal/database"
"github.com/git-pkgs/proxy/internal/denylist"
"github.com/git-pkgs/proxy/internal/handler"
"github.com/git-pkgs/proxy/internal/mirror"
"github.com/git-pkgs/proxy/internal/server"
Expand All @@ -128,6 +130,15 @@ var (
Commit = "unknown"
)

func init() {
if Version != "dev" {
return
}
if bi, ok := debug.ReadBuildInfo(); ok && bi.Main.Version != "" && bi.Main.Version != "(devel)" {
Version = bi.Main.Version
}
}

func main() {
if len(os.Args) > 1 {
switch os.Args[1] {
Expand Down Expand Up @@ -468,6 +479,10 @@ func runMirror() {
fmt.Fprintf(os.Stderr, "invalid configuration: %v\n", err)
os.Exit(1)
}
if !cfg.Storage.CacheArtifacts {
fmt.Fprintf(os.Stderr, "error: mirror is not available with storage.cache_artifacts: false: mirrored artifacts would never be served\n")
os.Exit(1)
}

logger := setupLogger("info", "text")

Expand Down Expand Up @@ -507,6 +522,12 @@ func runMirror() {
fetcher := fetch.NewFetcher()
resolver := fetch.NewResolver()
proxy := handler.NewProxy(db, store, fetcher, resolver, logger)
proxy.Denylist, err = denylist.New(cfg.Denylist.Packages)
if err != nil {
_ = db.Close()
fmt.Fprintf(os.Stderr, "invalid denylist: %v\n", err)
os.Exit(1) //nolint:gocritic // db closed above
}
proxy.CacheMetadata = true // mirror always caches metadata
proxy.MetadataTTL = cfg.ParseMetadataTTL()
proxy.MetadataMaxSize = cfg.ParseMetadataMaxSize()
Expand Down
51 changes: 51 additions & 0 deletions config.example.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -14,12 +14,34 @@ base_url: "http://localhost:8080"
# Set to "0" to disable the timeout. Default: "30s".
# http_timeout: "30s"

# Memory for rewritten npm and Composer metadata, so each upstream document is
# rewritten once rather than on every request. Set to "0" to rewrite on every
# request. Default: "256MB".
# metadata_rewrite_cache_size: "256MB"

# Public URL where the web UI is reached. Defaults to base_url when unset.
# Set this separately when the UI is served on a different hostname than the
# package endpoints — for example, the UI on a public domain behind auth while
# build machines hit a Docker network alias for the package endpoints.
# ui_base_url: "https://proxy.example.com/ui"

# Attribute requests to the leftmost X-Forwarded-For entry rather than the TCP
# peer address, in the structured log, the access log and the request-source
# table on /ui/analytics.
#
# Enable this only when the proxy sits behind a load balancer or ingress that
# sets the header. Any client can send it: behind one it is the only way to see
# past the hop, in front of one it lets a caller forge its own address.
# trust_forwarded_for: false

# Show the request-source table on /ui/analytics: caller addresses, the tool
# each ran and how much each pulled.
#
# Off by default. The proxy has no authentication of its own, so leave this off
# unless /ui is gated by a reverse proxy; anyone who can reach the page can
# otherwise read the addresses of your build fleet.
# ui_request_sources: false

# Artifact storage configuration
storage:
# Storage backend URL
Expand Down Expand Up @@ -52,6 +74,12 @@ storage:
# Empty or "0" means unlimited
max_size: ""

# Store fetched artifacts. Set to false to stream every download from
# upstream without storing it; metadata filtering, cooldown and the
# denylist still apply. Useful when another cache sits in front of the
# proxy. false is incompatible with direct_serve, scanning and mirror_api.
cache_artifacts: true

# Redirect cached artifact downloads to presigned storage URLs (HTTP 302)
# instead of streaming through the proxy. Only effective for S3, GCS, and Azure.
# Leave disabled if clients reach the proxy through an authenticating gateway,
Expand Down Expand Up @@ -81,6 +109,10 @@ database:
# Example: "postgres://user:password@localhost:5432/proxy?sslmode=disable"
url: ""

# How often cache hit counts and last-access times are written, batched in
# one transaction. "0" writes each hit as it happens.
hit_flush_interval: "1s"

# Logging configuration
log:
# Minimum log level: "debug", "info", "warn", "error"
Expand Down Expand Up @@ -174,6 +206,11 @@ upstream:
# Debian/APT repository URL (used by /debian endpoint)
debian: "http://deb.debian.org/debian"

# Additional Debian/APT archives, served at /debian/{name}/.
# The names "pool" and "dists" are reserved for the main archive's own paths.
debian_repositories:
security: "https://security.debian.org/debian-security"

# RPM repository URL (used by /rpm endpoint)
rpm: "https://dl.fedoraproject.org/pub/fedora/linux"

Expand Down Expand Up @@ -295,6 +332,20 @@ cooldown:
# "pkg:npm/lodash": "0"
# "pkg:npm/@babel/core": "14d"

# Per-package glob overrides, after exact packages and before ecosystems.
# package_patterns:
# "pkg:npm/@example/*": "0"

# Exact versions to deny, independently of cooldown and scanning.
# Metadata filtering: npm, PyPI and Cargo. Shared artifact downloads, including
# cache hits, are blocked with 403; signed APT metadata is left unchanged.
# Use versioned PURLs without qualifiers/subpaths. Restart after changes.
# denylist:
# packages:
# - "pkg:pypi/requests@2.31.0"
# - "pkg:cargo/some-crate@1.2.3"
# - "pkg:npm/%40scope/example@4.5.6"

# Pre-cache artifact scanning. When enabled, every artifact is staged into
# storage and scanned by the configured scanners before it is committed to
# the cache and served to clients. Scanners never receive artifact bytes
Expand Down
Loading
Loading