Skip to content

Add network allowlist of common package registries and code hosts#3

Open
E-privo wants to merge 3 commits into
mainfrom
codex/list-trusted-package-repository-urls
Open

Add network allowlist of common package registries and code hosts#3
E-privo wants to merge 3 commits into
mainfrom
codex/list-trusted-package-repository-urls

Conversation

@E-privo
Copy link
Copy Markdown
Collaborator

@E-privo E-privo commented Mar 2, 2026

Motivation

  • Add a centralized network allowlist to permit build and runtime egress to common package registries, artifact hosts, and source code hosting services.

Description

  • Add network-allowlist.txt containing a curated list of domains (e.g., pypi.org, npmjs.com, maven.org, github.com, gcr.io, quay.io) used for dependency resolution, container registries, and source hosting.

Testing

  • No automated tests were run for this change.

Codex Task

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant