mirror of
https://github.com/safedep/pmg.git
synced 2026-08-03 07:24:09 +02:00
docs: Add doc for trusted packages and proxy mode (#102)
This commit is contained in:
@@ -0,0 +1,36 @@
|
||||
# Proxy Mode
|
||||
|
||||
PMG supports an experimental proxy based interception as an alternative to the current optimistic dependency resolution. When enabled via `--experimental-proxy-mode` flag:
|
||||
|
||||
- PMG starts a micro-proxy server on a random localhost port
|
||||
- Run `npm` and other supported package managers configured to use the proxy
|
||||
- Intercept package registry requests and analyze packages as they are downloaded
|
||||
- Block malicious packages and allow trusted packages to be installed
|
||||
|
||||
## Usage
|
||||
|
||||
```bash
|
||||
pmg --experimental-proxy-mode npm install lodash
|
||||
```
|
||||
|
||||
## Configuration
|
||||
|
||||
To permanently enable proxy mode, add the following to your `config.yml` file:
|
||||
|
||||
```yaml
|
||||
experimental_proxy_mode: true
|
||||
```
|
||||
|
||||
## Supported Package Managers
|
||||
|
||||
| Package Manager | Status |
|
||||
| --------------- | --------- |
|
||||
| `npm` | ✅ Active |
|
||||
| `npx` | 🕒 Planned |
|
||||
| `yarn` | 🕒 Planned |
|
||||
| `pnpm` | 🕒 Planned |
|
||||
| `pnpx` | 🕒 Planned |
|
||||
| `bun` | 🕒 Planned |
|
||||
| `pip` | 🕒 Planned |
|
||||
| `uv` | 🕒 Planned |
|
||||
| `poetry` | 🕒 Planned |
|
||||
@@ -0,0 +1,19 @@
|
||||
# Trusted Packages
|
||||
|
||||
`pmg` allows you to trust a package. Trusted packages are not scanned and always allowed to be installed.
|
||||
|
||||
## Configuration
|
||||
|
||||
Trusted packages are configured in the `config.yml` file. See [config template](../config/config.template.yml) for the configuration schema.
|
||||
If you don't have a `config.yml` file, you can create one by running `pmg setup install`.
|
||||
|
||||
### Example
|
||||
|
||||
```yaml
|
||||
trusted_packages:
|
||||
- purl: pkg:npm/safedep/pmg
|
||||
reason: "All versions of PMG are trusted"
|
||||
- purl: pkg:npm/express@4.18.0
|
||||
reason: "Version 4.18.0 of Express is a trusted package"
|
||||
```
|
||||
|
||||
Reference in New Issue
Block a user