Supported Protocols

OSA Proxy implementation

This page describes the current OSA Proxy implementation. The archived Java/Spring implementation is available in Archived Java/Spring implementation.

This section describes which resources OSA Proxy checks and which responses it can modify for each ecosystem.

Summary

EcosystemManifest scanningPackage scanningResponse modification
MavenYesYesRemoves blocked versions from maven-metadata.xml and updates latest and release.
GradleYesYesWorks through Maven-compatible repositories: filters metadata and checks downloaded packages.
IvyNoYesEvaluates package artifacts according to the path layout pattern.
npmYesYesRemoves blocked versions from metadata, updates dist-tags and tarball links.
PyPIYesYesRemoves blocked links from Simple API pages, rewrites download URLs through the proxy.
NuGetYesYesModifies service index and registration metadata, removes blocked versions.
Go modulesYesYesRemoves blocked versions from @v/list, proxies module zip and SumDB.
CocoaPodsYesYesEvaluates .podspec.json, rewrites source.http URLs for configured additional registries.
SwiftYesYesModifies release lists (removes or marks problem: 410), evaluates release zip archives.
HexYesYesValidates and re-signs protobuf manifests with RSA key (removes or marks retired: security), evaluates package archives.
ComposerYesYesModifies Packagist/Composer metadata and rewrites dist URLs through the proxy.
RubyGemsYesYesChecks RubyGems metadata and downloaded .gem packages.
Conan v2YesYesHandles search, list, and revisions, removes blocked versions, and checks packages.
R (CRAN)NoYesPACKAGES, PACKAGES.gz, and PACKAGES.rds indexes are not modified.
DebianNoYesPackages indexes are not modified.
Alpine (APK)NoYesAPKINDEX indexes are not modified.
RPMNoYesrepodata metadata is not modified.
DockerYesNoChecks image manifests (scan-container); manifest lists are used to resolve image manifests and are not sent for checking as separate components. Blob/layer requests are proxied without separate layer checks. Several Docker repositories use subdomains.

scan-manifest and scan-package

scan-manifest enables checking and modification of metadata from which the package manager selects available versions. When a blocking policy is triggered, unsafe versions are removed from the response or marked as blocked when the format supports it.

scan-package enables checking of downloaded artifacts: archives, binary packages, module zip files, R packages, .gem, .deb, .apk, or .rpm. If a policy blocks the component, the download is interrupted with the HTTP code from codescoring.block-status-code.

For R, Debian, Alpine, RPM, and Ivy, only scan-package is used: indexes are not modified, so the package manager can still see the version in the index, but downloading the specific package is blocked when it violates a policy.

For Docker, container image manifest scanning is controlled by scan-container (enabled by default). Manifest lists are used to resolve image manifests; blob/layer requests are proxied to the registry.

For npm, NuGet, PyPI, Swift, and Hex, the remove-blocked-versions: false setting is supported: blocked versions remain in metadata with a format marker (such as problem: 410 for Swift or retired: security for Hex). Composer and Conan always remove blocked versions.

Maven

  • Metadata: maven-metadata.xml.
  • Packages: .jar, .war, .ear, and other Maven artifacts.
  • When metadata is modified, blocked versions are removed and latest/release are updated to the latest allowed version.

npm

  • Metadata: package JSON metadata.
  • Packages: .tgz.
  • Blocked versions and related time entries are removed from metadata, and dist-tags are recalculated to allowed versions.

PyPI

  • Metadata: Simple API pages.
  • Packages: .whl, .tar.gz, .zip, and other Python package archives.
  • Links to blocked versions are removed, and download URLs are rewritten so downloads go through OSA Proxy.

NuGet

  • Metadata: service index and registration index.
  • Packages: .nupkg.
  • The client uses the /nuget-api/v3/index.json route; metadata is rewritten to OSA Proxy URLs.

Go modules

  • Metadata: version list @v/list.
  • Packages: module .zip.
  • Blocked versions are removed from the version list. SumDB uses sumdb-registry and the GOSUMDB client setting.

Ivy

  • Metadata: ivy.xml and descriptor files are proxied without modification.
  • Packages: JAR, ZIP, and other artifacts matched according to the configured layout (sbt-default, ivy-default, or custom layout).
  • A policy violation interrupts artifact downloading with the block status code.

CocoaPods

  • Metadata: evaluates .podspec.json specifications. CDN index files (all_pods.txt, CocoaPods-version.yml) pass through unmodified.
  • Packages: dependency archives downloaded via source.http.
  • URLs for trusted upstream hosts in additional-packages-registries are rewritten through OSA Proxy to scan archives. Blocked podspecs are blocked entirely.

Swift Package Registry

  • Metadata: package release list. When remove-blocked-versions: true (default), blocked versions are removed; when false, they are marked with problem: 410 citing the policy name.
  • Packages: release ZIP archives.
  • Package.swift files pass through without individual CodeScoring requests.

Hex

  • Metadata: binary protobuf manifests. OSA Proxy validates the upstream registry signature, modifies the release list, and signs the response with its own RSA key.
  • Packages: .tar package archives.
  • When remove-blocked-versions: false, versions are marked as retired: security, enabling filtering through the built-in osa-proxy/codescoring Hex policy.

Composer

  • Metadata: Composer/Packagist metadata.
  • Packages: dist archives .zip, .tar, .tgz, .tar.gz, .tar.bz2, .tar.xz.
  • Dist URLs are rewritten to OSA Proxy routes. For external dist hosts, use packages-registry and additional-packages-registries.

RubyGems

  • Metadata: RubyGems indexes.
  • Packages: .gem.
  • Metadata and downloaded gem packages are checked.

Conan v2

  • Metadata: Conan API v2 search, list, and revisions requests.
  • Packages: Conan recipe and package artifacts.
  • Blocked versions are always removed from results.

R (CRAN)

  • Metadata: PACKAGES, PACKAGES.gz, and PACKAGES.rds indexes are proxied without modification.
  • Packages: source .tar.gz files and supported R binary archives.
  • A policy violation blocks the package download, but the version remains visible in the index.

Docker

  • Metadata: Docker image manifest. Checking is controlled by scan-container (default true). Manifest lists are used to resolve image manifests.
  • Packages: there is no separate scan-package; blob/layer requests are proxied to the registry.
  • Pull-through proxy mode: when codescoring-pull-through-proxy: true, OSA Proxy forwards the external pull URL to CodeScoring during container checks.
  • Several Docker repositories are separated by subdomains (repository[*].name), because Docker Registry API v2 uses fixed /v2/ paths.

Blocking Diagnostics

If a package manager does not display the blocking reason, check the corresponding metadata endpoint directly:

curl https://osa-proxy.example.com/npm/lodash
curl https://osa-proxy.example.com/pypi/simple/requests/
curl https://osa-proxy.example.com/maven/org/apache/commons/commons-lang3/maven-metadata.xml
curl https://osa-proxy.example.com/nuget/nuget-api/v3/registration5-gz-semver2/newtonsoft.json/index.json
curl https://osa-proxy.example.com/go/github.com/gin-gonic/gin/@v/list
Was this page helpful?