Supported Protocols
This page describes the current OSA Proxy implementation. The archived Java/Spring implementation is available in Archived Java/Spring implementation.
This section describes which resources OSA Proxy checks and which responses it can modify for each ecosystem.
Summary
scan-manifest and scan-package
scan-manifest enables checking and modification of metadata from which the package manager selects available versions. When a blocking policy is triggered, unsafe versions are removed from the response or marked as blocked when the format supports it.
scan-package enables checking of downloaded artifacts: archives, binary packages, module zip files, R packages, .gem, .deb, .apk, or .rpm. If a policy blocks the component, the download is interrupted with the HTTP code from codescoring.block-status-code.
For R, Debian, Alpine, RPM, and Ivy, only scan-package is used: indexes are not modified, so the package manager can still see the version in the index, but downloading the specific package is blocked when it violates a policy.
For Docker, container image manifest scanning is controlled by scan-container (enabled by default). Manifest lists are used to resolve image manifests; blob/layer requests are proxied to the registry.
For npm, NuGet, PyPI, Swift, and Hex, the remove-blocked-versions: false setting is supported: blocked versions remain in metadata with a format marker (such as problem: 410 for Swift or retired: security for Hex). Composer and Conan always remove blocked versions.
Maven
- Metadata:
maven-metadata.xml. - Packages:
.jar,.war,.ear, and other Maven artifacts. - When metadata is modified, blocked versions are removed and
latest/releaseare updated to the latest allowed version.
npm
- Metadata: package JSON metadata.
- Packages:
.tgz. - Blocked versions and related
timeentries are removed from metadata, anddist-tagsare recalculated to allowed versions.
PyPI
- Metadata: Simple API pages.
- Packages:
.whl,.tar.gz,.zip, and other Python package archives. - Links to blocked versions are removed, and download URLs are rewritten so downloads go through OSA Proxy.
NuGet
- Metadata: service index and registration index.
- Packages:
.nupkg. - The client uses the
/nuget-api/v3/index.jsonroute; metadata is rewritten to OSA Proxy URLs.
Go modules
- Metadata: version list
@v/list. - Packages: module
.zip. - Blocked versions are removed from the version list. SumDB uses
sumdb-registryand theGOSUMDBclient setting.
Ivy
- Metadata:
ivy.xmland descriptor files are proxied without modification. - Packages: JAR, ZIP, and other artifacts matched according to the configured
layout(sbt-default,ivy-default, or custom layout). - A policy violation interrupts artifact downloading with the block status code.
CocoaPods
- Metadata: evaluates
.podspec.jsonspecifications. CDN index files (all_pods.txt,CocoaPods-version.yml) pass through unmodified. - Packages: dependency archives downloaded via
source.http. - URLs for trusted upstream hosts in
additional-packages-registriesare rewritten through OSA Proxy to scan archives. Blocked podspecs are blocked entirely.
Swift Package Registry
- Metadata: package release list. When
remove-blocked-versions: true(default), blocked versions are removed; whenfalse, they are marked withproblem: 410citing the policy name. - Packages: release ZIP archives.
Package.swiftfiles pass through without individual CodeScoring requests.
Hex
- Metadata: binary protobuf manifests. OSA Proxy validates the upstream registry signature, modifies the release list, and signs the response with its own RSA key.
- Packages:
.tarpackage archives. - When
remove-blocked-versions: false, versions are marked asretired: security, enabling filtering through the built-inosa-proxy/codescoringHex policy.
Composer
- Metadata: Composer/Packagist metadata.
- Packages: dist archives
.zip,.tar,.tgz,.tar.gz,.tar.bz2,.tar.xz. - Dist URLs are rewritten to OSA Proxy routes. For external dist hosts, use
packages-registryandadditional-packages-registries.
RubyGems
- Metadata: RubyGems indexes.
- Packages:
.gem. - Metadata and downloaded gem packages are checked.
Conan v2
- Metadata: Conan API v2
search,list, andrevisionsrequests. - Packages: Conan recipe and package artifacts.
- Blocked versions are always removed from results.
R (CRAN)
- Metadata:
PACKAGES,PACKAGES.gz, andPACKAGES.rdsindexes are proxied without modification. - Packages: source
.tar.gzfiles and supported R binary archives. - A policy violation blocks the package download, but the version remains visible in the index.
Docker
- Metadata: Docker image manifest. Checking is controlled by
scan-container(defaulttrue). Manifest lists are used to resolve image manifests. - Packages: there is no separate
scan-package; blob/layer requests are proxied to the registry. - Pull-through proxy mode: when
codescoring-pull-through-proxy: true, OSA Proxy forwards the external pull URL to CodeScoring during container checks. - Several Docker repositories are separated by subdomains (
repository[*].name), because Docker Registry API v2 uses fixed/v2/paths.
Blocking Diagnostics
If a package manager does not display the blocking reason, check the corresponding metadata endpoint directly:
