My repository defines an extra NuGet feed in nuget.config:
<?xml version="1.0" encoding="utf-8"?>
<configuration>
<packageSources>
<add key="nuget.org" value="https://api.nuget.org/v3/index.json" />
<add key="some-package-source" value="https://some-package-source/nuget/v3/index.json" />
</packageSources>
<packageSourceMapping>
<packageSource key="nuget.org">
<package pattern="*" />
</packageSource>
<packageSource key="some-package-source">
<package pattern="SomePackage.*" />
</packageSource>
</packageSourceMapping>
</configuration>
Recently, Dependabot jobs fail on this feed:
proxy | GET https://some-package-source:443/nuget/v3/index.json
proxy | * egress not allowlisted some-package-source
proxy | 403 https://some-package-source:443/nuget/v3/index.json
proxy | Remote response: Forbidden
updater | ERROR Error type: private_source_authentication_failure
From the source, the allowlist only includes hosts taken from job credentials (dynamicHosts(cfg.Credentials)). Declaring the feed again under registries: in dependabot.yml should get it allowlisted, but that duplicates what nuget.config already defines. It also isn't obvious: nothing in the docs says a registries: entry is needed just to allow a host, since NuGet already reads the source from nuget.config.
It would be nice if Dependabot could either:
- Include package sources from the repository's
nuget.config in the allowlist, or
- Document that feeds must be declared under
registries: to get past the egress allowlist
My repository defines an extra NuGet feed in
nuget.config:Recently, Dependabot jobs fail on this feed:
From the source, the allowlist only includes hosts taken from job credentials (
dynamicHosts(cfg.Credentials)). Declaring the feed again underregistries:independabot.ymlshould get it allowlisted, but that duplicates whatnuget.configalready defines. It also isn't obvious: nothing in the docs says aregistries:entry is needed just to allow a host, since NuGet already reads the source fromnuget.config.It would be nice if Dependabot could either:
nuget.configin the allowlist, orregistries:to get past the egress allowlist