Skip to content

Egress allowlist blocks NuGet sources defined in nuget.config #278

Description

@LouisMT

My repository defines an extra NuGet feed in nuget.config:

<?xml version="1.0" encoding="utf-8"?>
<configuration>

  <packageSources>
    <add key="nuget.org" value="https://api.nuget.org/v3/index.json" />
    <add key="some-package-source" value="https://some-package-source/nuget/v3/index.json" />
  </packageSources>

  <packageSourceMapping>
    <packageSource key="nuget.org">
      <package pattern="*" />
    </packageSource>

    <packageSource key="some-package-source">
      <package pattern="SomePackage.*" />
    </packageSource>
  </packageSourceMapping>

</configuration>

Recently, Dependabot jobs fail on this feed:

proxy | GET https://some-package-source:443/nuget/v3/index.json
proxy | * egress not allowlisted some-package-source
proxy | 403 https://some-package-source:443/nuget/v3/index.json
proxy | Remote response: Forbidden
updater | ERROR Error type: private_source_authentication_failure

From the source, the allowlist only includes hosts taken from job credentials (dynamicHosts(cfg.Credentials)). Declaring the feed again under registries: in dependabot.yml should get it allowlisted, but that duplicates what nuget.config already defines. It also isn't obvious: nothing in the docs says a registries: entry is needed just to allow a host, since NuGet already reads the source from nuget.config.

It would be nice if Dependabot could either:

  • Include package sources from the repository's nuget.config in the allowlist, or
  • Document that feeds must be declared under registries: to get past the egress allowlist

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions