Dependency Proxy for Self-Hosted CI Runners
CI pipelines install dependencies on every run, which makes them a prime target for supply chain attacks. Instead of adding a registry configuration to every repository, you can configure the DevGuard dependency proxy once on your self-hosted runners. Every job running on them then downloads npm, Go and PyPI packages through DevGuard, without any change to the projects themselves.
Proxy URLs with a Secret
The proxy URLs in the runner configuration contain a dependency proxy secret:
| Ecosystem | Environment variable | URL |
|---|---|---|
| npm | npm_config_registry | https://<your-devguard-url>/api/v1/dependency-proxy/<secret>/npm/ |
| Go modules | GOPROXY | https://<your-devguard-url>/api/v1/dependency-proxy/<secret>/go/ |
| PyPI | PIP_INDEX_URL | https://<your-devguard-url>/api/v1/dependency-proxy/<secret>/pypi/simple/ |
The secret links the requests to your organization, project or repository in DevGuard, so the proxy applies the rules and the minimum package age configured there. Requests without a secret are only checked against the malicious package database.
GitLab Runner
GitLab Runner passes the variables listed in environment of a [[runners]] section to every job it runs. Add the proxy URLs to the runner's config.toml (by default /etc/gitlab-runner/config.toml). This works with every executor, for example Shell, Docker or Kubernetes: