Dependency Proxy for Self-Hosted CI Runners

CI pipelines install dependencies on every run, which makes them a prime target for supply chain attacks. Instead of adding a registry configuration to every repository, you can configure the DevGuard dependency proxy once on your self-hosted runners. Every job running on them then downloads npm, Go and PyPI packages through DevGuard, without any change to the projects themselves.

Proxy URLs with a Secret

The proxy URLs in the runner configuration contain a dependency proxy secret:

EcosystemEnvironment variableURL
npmnpm_config_registryhttps://<your-devguard-url>/api/v1/dependency-proxy/<secret>/npm/
Go modulesGOPROXYhttps://<your-devguard-url>/api/v1/dependency-proxy/<secret>/go/
PyPIPIP_INDEX_URLhttps://<your-devguard-url>/api/v1/dependency-proxy/<secret>/pypi/simple/

The secret links the requests to your organization, project or repository in DevGuard, so the proxy applies the rules and the minimum package age configured there. Requests without a secret are only checked against the malicious package database.

GitLab Runner

GitLab Runner passes the variables listed in environment of a [[runners]] section to every job it runs. Add the proxy URLs to the runner's config.toml (by default /etc/gitlab-runner/config.toml). This works with every executor, for example Shell, Docker or Kubernetes:

Further Reading

Have feedback? We want to hear from you!

Fields marked with * are required