From 63b161542d00a8c01081e16091ae530a886659d1 Mon Sep 17 00:00:00 2001 From: Julian Kepka Date: Wed, 30 Sep 2026 15:48:59 +0200 Subject: [PATCH 1/2] feat: add php and maven to dependency proxy documentation --- src/nix-tests/flake.nix | 3 + src/nix-tests/nixmd.mts | 14 +- .../how-to-guides/dependency-proxy/_meta.ts | 2 + .../how-to-guides/dependency-proxy/index.mdx | 6 + .../dependency-proxy/setup-composer-proxy.mdx | 168 ++++++++++++++++ .../dependency-proxy/setup-go-proxy.mdx | 2 + .../dependency-proxy/setup-maven-proxy.mdx | 183 ++++++++++++++++++ .../dependency-proxy/setup-npm-proxy.mdx | 2 + .../dependency-proxy/setup-oci-proxy.mdx | 2 + .../dependency-proxy/setup-pypi-proxy.mdx | 2 + src/pages/how-to-guides/index.mdx | 2 + 11 files changed, 382 insertions(+), 4 deletions(-) create mode 100644 src/pages/how-to-guides/dependency-proxy/setup-composer-proxy.mdx create mode 100644 src/pages/how-to-guides/dependency-proxy/setup-maven-proxy.mdx diff --git a/src/nix-tests/flake.nix b/src/nix-tests/flake.nix index ff1e516..76459b8 100644 --- a/src/nix-tests/flake.nix +++ b/src/nix-tests/flake.nix @@ -21,6 +21,9 @@ nodejs python3 go + maven + php + phpPackages.composer jq crane ]; diff --git a/src/nix-tests/nixmd.mts b/src/nix-tests/nixmd.mts index bd208ac..3e31fbe 100644 --- a/src/nix-tests/nixmd.mts +++ b/src/nix-tests/nixmd.mts @@ -55,6 +55,8 @@ const DEFAULT_MDX_FILES = [ 'src/pages/how-to-guides/dependency-proxy/setup-npm-proxy.mdx', 'src/pages/how-to-guides/dependency-proxy/setup-pypi-proxy.mdx', 'src/pages/how-to-guides/dependency-proxy/setup-go-proxy.mdx', + 'src/pages/how-to-guides/dependency-proxy/setup-maven-proxy.mdx', + 'src/pages/how-to-guides/dependency-proxy/setup-composer-proxy.mdx', 'src/pages/how-to-guides/dependency-proxy/setup-oci-proxy.mdx', ] @@ -281,10 +283,14 @@ function main(): void { `timeout ${SCRIPT_TIMEOUT} bash ${shQuote(resolve(script))}` try { - execFileSync('nix', ['develop', FLAKE_NIX, '-c', 'bash', '-c', inner], { - stdio: ['ignore', 'inherit', 'inherit'], - env, - }) + execFileSync( + 'nix', + ['develop', FLAKE_NIX, '-c', 'bash', '-c', inner], + { + stdio: ['ignore', 'inherit', 'inherit'], + env, + }, + ) console.log(`OK: ${script}`) } catch { console.error(`FAILED: ${script}`) diff --git a/src/pages/how-to-guides/dependency-proxy/_meta.ts b/src/pages/how-to-guides/dependency-proxy/_meta.ts index 9180ff6..da6b5a1 100644 --- a/src/pages/how-to-guides/dependency-proxy/_meta.ts +++ b/src/pages/how-to-guides/dependency-proxy/_meta.ts @@ -4,6 +4,8 @@ export default { 'setup-go-proxy': { title: 'Setup Go Proxy' }, 'setup-npm-proxy': { title: 'Setup NPM Proxy' }, 'setup-pypi-proxy': { title: 'Setup PyPI Proxy' }, + 'setup-maven-proxy': { title: 'Setup Maven Proxy' }, + 'setup-composer-proxy': { title: 'Setup Composer Proxy' }, 'setup-oci-proxy': { title: 'Setup OCI Proxy' }, 'ci-runners': { title: 'Self-Hosted CI Runners' }, } diff --git a/src/pages/how-to-guides/dependency-proxy/index.mdx b/src/pages/how-to-guides/dependency-proxy/index.mdx index 97c5ecc..e755ab1 100644 --- a/src/pages/how-to-guides/dependency-proxy/index.mdx +++ b/src/pages/how-to-guides/dependency-proxy/index.mdx @@ -32,6 +32,8 @@ DevGuard includes a built-in dependency proxy that acts as a protective layer be | npm | `/api/v1/dependency-proxy/npm` | | Go modules | `/api/v1/dependency-proxy/go` | | PyPI | `/api/v1/dependency-proxy/pypi/simple` | +| Maven | `/api/v1/dependency-proxy/maven` | +| Composer (Packagist) | `/api/v1/dependency-proxy/composer` | | OCI (container images) | `/v2/` — pull `//:` | For setup instructions, see the ecosystem-specific guides: @@ -39,6 +41,8 @@ For setup instructions, see the ecosystem-specific guides: - [Setup npm Proxy](/how-to-guides/dependency-proxy/setup-npm-proxy) - [Setup Go Proxy](/how-to-guides/dependency-proxy/setup-go-proxy) - [Setup PyPI Proxy](/how-to-guides/dependency-proxy/setup-pypi-proxy) +- [Setup Maven Proxy](/how-to-guides/dependency-proxy/setup-maven-proxy) +- [Setup Composer Proxy](/how-to-guides/dependency-proxy/setup-composer-proxy) - [Setup OCI Proxy](/how-to-guides/dependency-proxy/setup-oci-proxy) To route all CI jobs through the proxy at once, see [Self-Hosted CI Runners](/how-to-guides/dependency-proxy/ci-runners). @@ -54,6 +58,8 @@ The minimum age is configured per organization, project or repository and applie | npm | Supported | | PyPI | Supported | | Go modules | Supported | +| Maven | Supported | +| Composer (Packagist) | Supported | | OCI (container images) | Not supported — registries expose no reliable publish date, see [Setup OCI Proxy](/how-to-guides/dependency-proxy/setup-oci-proxy) | ## Cache & Security diff --git a/src/pages/how-to-guides/dependency-proxy/setup-composer-proxy.mdx b/src/pages/how-to-guides/dependency-proxy/setup-composer-proxy.mdx new file mode 100644 index 0000000..c8c6fa4 --- /dev/null +++ b/src/pages/how-to-guides/dependency-proxy/setup-composer-proxy.mdx @@ -0,0 +1,168 @@ +--- +title: Setup Composer Proxy with DevGuard Dependency Proxy +description: "Configure Composer to route PHP package downloads from Packagist through the DevGuard dependency proxy for malicious package detection and supply chain security." +seo: + robots: index,follow + og: + image: /og-image.png + type: article + schema: + type: TechArticle + keyword_primary: setup composer proxy with devguard +lang: en-US +ignoreChecks: null +--- + +import { Callout } from '@document-writing-tools/kernux-theme' + +# Setup Composer Proxy with DevGuard Dependency Proxy + +PHP projects are just as exposed to supply chain attacks as any other ecosystem. In 2022, attackers took over the abandoned `hautelook/phpass` package on Packagist and published new releases that stole AWS credentials from every environment that installed them. Because `composer install` resolves the whole dependency tree automatically, a single compromised package is enough to reach every developer machine and CI runner of a project. + +The DevGuard dependency proxy sits between Composer and Packagist. Every package request is checked against the [OSV dataset](https://osv.dev) before it reaches your `vendor` directory, blocking known malicious packages automatically. + +- **Registry URL**: `/api/v1/dependency-proxy/composer` + +## Configuration + +Disable the default Packagist repository and add the DevGuard proxy instead. Disabling `packagist.org` is required: otherwise Composer keeps it as a fallback and downloads packages directly from Packagist whenever the proxy does not serve them. To apply it to every project on your machine, set it in your global Composer configuration: + +```bash {ignore} +composer config --global repo.packagist.org false +composer config --global repo.devguard composer https:///api/v1/dependency-proxy/composer +``` + +To scope it to a single project, run the same commands without `--global` in the project directory. Composer then adds the repositories to your `composer.json`: + +```json +{ + "repositories": [ + { + "name": "devguard", + "type": "composer", + "url": "https:///api/v1/dependency-proxy/composer" + }, + { + "packagist.org": false + } + ] +} +``` + +Run `composer config repositories` to verify that the DevGuard proxy is the only repository left. + +Once set, all `composer install`, `composer update` and `composer require` invocations resolve packages through DevGuard transparently. + + + The proxy serves packages from Packagist as `zip` archives from GitHub, GitLab and Bitbucket only. The `source` entries of a package are removed, so `--prefer-source` has no effect, and packages whose archives are hosted elsewhere are rejected. + + + + Composer only accepts `https` repositories by default. Set `composer config secure-http false` only for local testing against a DevGuard instance without TLS. Never disable it in production. + + + + On startup, the proxy blocks all requests until the malicious package database is fully loaded. This initialization period prevents cache poisoning. See [Cache Management](/how-to-guides/dependency-proxy/cache-management) for details. + + +## Testing + +DevGuard ships a test package, `fake-org/malicious-package`, that is permanently flagged as malicious for all versions. The script below uses a project-local Composer home and cache, so every download goes through the proxy and your global configuration stays untouched: + +```bash +mkdir -p composer-proxy-test && cd composer-proxy-test +export COMPOSER_HOME="$(pwd)/.composer" +export COMPOSER_CACHE_DIR="$(pwd)/.composer-cache" +export COMPOSER_NO_INTERACTION=1 + +composer init --name=devguard/composer-proxy-test +# only needed for a DevGuard instance without TLS, such as a local test instance +composer config secure-http false +composer config repo.packagist.org false +composer config repo.devguard composer https:///api/v1/dependency-proxy/composer + +# psr/log installs through the proxy +composer require psr/log:3.0.2 + +# fake-org/malicious-package must be rejected +if composer require fake-org/malicious-package; then + echo "fake-org/malicious-package was NOT blocked - check your proxy configuration" >&2 + exit 1 +fi + +# check that the proxy answered with 403 Forbidden, for the version list and for a download +for path in p2/fake-org/malicious-package.json \ + dist/fake-org/malicious-package/1.0.0.zip; do + status=$(curl -s -o /dev/null -w "%{http_code}" \ + "https:///api/v1/dependency-proxy/composer/$path") + if [ "$status" != "403" ]; then + echo "expected 403 Forbidden for $path, got $status" >&2 + exit 1 + fi +done +``` + +If the install is blocked, the proxy is working correctly. Composer reports the `403 Forbidden` for the package's metadata file. All other packages resolve normally from Packagist. + +### Testing the minimum package age + +The [minimum package age](/how-to-guides/dependency-proxy#minimum-package-age) is configured per repository and only applies to requests using the repository's proxy URL, which contains a secret. The proxy uses the release time Packagist reports for each version: versions that are too new are removed from the package metadata, so Composer resolves to the newest version that is old enough, and downloads of a too new version are rejected. + +To verify it, temporarily set the minimum age to 87600 hours (10 years). `monolog/monolog` 3.7.0 was published in June 2024, so the proxy must reject it, while `composer require` without a version still resolves to an older version: + + + The proxy enforces the minimum age centrally, for every client and without any client configuration. + + +```bash +# set the minimum package age of the repository to 10 years +devguard-scanner curl --token -X PUT \ + -d '{"rules":"","minReleaseAge":87600}' \ + https:///api/v1/organizations//config-files/dependency-proxy-configs/ + +# the repository's Composer proxy URL applies its settings +COMPOSER_PROXY=$(devguard-scanner curl --token -s \ + https:///api/v1/organizations//dependency-proxy-urls/ \ + | jq -r .composer) + +# use a fresh project and cache, so no downloaded version is reused +cd .. && mkdir -p composer-min-age-test && cd composer-min-age-test +export COMPOSER_CACHE_DIR="$(pwd)/.composer-cache" +composer init --name=devguard/composer-min-age-test +composer config secure-http false +composer config repo.packagist.org false +composer config repo.devguard composer "$COMPOSER_PROXY" + +# monolog/monolog 3.7.0 is younger than 10 years and must be rejected +if composer require monolog/monolog:3.7.0; then + echo "monolog/monolog 3.7.0 was NOT blocked by the minimum package age" >&2 + exit 1 +fi + +# check that the proxy answered with 403 Forbidden +status=$(curl -s -o /dev/null -w "%{http_code}" \ + "${COMPOSER_PROXY%/}/dist/monolog/monolog/3.7.0.zip") +if [ "$status" != "403" ]; then + echo "expected 403 Forbidden for monolog/monolog 3.7.0, got $status" >&2 + exit 1 +fi + +# without a version, Composer resolves to the newest version that is old enough +composer require monolog/monolog +composer show monolog/monolog | grep versions + +# reset the minimum package age +devguard-scanner curl --token -X PUT \ + -d '{"rules":"","minReleaseAge":0}' \ + https:///api/v1/organizations//config-files/dependency-proxy-configs/ +``` + +## Further Reading + +- [Dependency Proxy Overview](/how-to-guides/dependency-proxy) +- [Cache Management](/how-to-guides/dependency-proxy/cache-management) +- [Setup npm Proxy](/how-to-guides/dependency-proxy/setup-npm-proxy) +- [Setup Go Proxy](/how-to-guides/dependency-proxy/setup-go-proxy) +- [Setup PyPI Proxy](/how-to-guides/dependency-proxy/setup-pypi-proxy) +- [Setup Maven Proxy](/how-to-guides/dependency-proxy/setup-maven-proxy) +- [OSV (Open Source Vulnerabilities)](https://osv.dev) diff --git a/src/pages/how-to-guides/dependency-proxy/setup-go-proxy.mdx b/src/pages/how-to-guides/dependency-proxy/setup-go-proxy.mdx index 7eb7d9a..506f9b0 100644 --- a/src/pages/how-to-guides/dependency-proxy/setup-go-proxy.mdx +++ b/src/pages/how-to-guides/dependency-proxy/setup-go-proxy.mdx @@ -131,4 +131,6 @@ devguard-scanner curl --token -X PUT \ - [Cache Management](/how-to-guides/dependency-proxy/cache-management) - [Setup npm Proxy](/how-to-guides/dependency-proxy/setup-npm-proxy) - [Setup PyPI Proxy](/how-to-guides/dependency-proxy/setup-pypi-proxy) +- [Setup Maven Proxy](/how-to-guides/dependency-proxy/setup-maven-proxy) +- [Setup Composer Proxy](/how-to-guides/dependency-proxy/setup-composer-proxy) - [OSV (Open Source Vulnerabilities)](https://osv.dev) diff --git a/src/pages/how-to-guides/dependency-proxy/setup-maven-proxy.mdx b/src/pages/how-to-guides/dependency-proxy/setup-maven-proxy.mdx new file mode 100644 index 0000000..3942a3b --- /dev/null +++ b/src/pages/how-to-guides/dependency-proxy/setup-maven-proxy.mdx @@ -0,0 +1,183 @@ +--- +title: Setup Maven Proxy with DevGuard Dependency Proxy +description: "Configure Maven and Gradle to route artifact downloads through the DevGuard dependency proxy for malicious package detection and supply chain security." +seo: + robots: index,follow + og: + image: /og-image.png + type: article + schema: + type: TechArticle + keyword_primary: setup maven proxy with devguard +lang: en-US +ignoreChecks: null +--- + +import { Callout } from '@document-writing-tools/kernux-theme' + +# Setup Maven Proxy with DevGuard Dependency Proxy + +Maven Central is a target for typosquatting just like npm or PyPI. Attackers publish artifacts under group IDs that look almost like well-known ones, for example `org.fasterxml.jackson.core` instead of `com.fasterxml.jackson.core`, and wait for a developer or an automated dependency update to pick the wrong coordinates. Because Maven resolves transitive dependencies and build plugins automatically, a single malicious artifact can end up on every developer machine and CI runner that builds the project. + +The DevGuard dependency proxy sits between your build tool and Maven Central. Every artifact request is checked against the [OSV dataset](https://osv.dev) before it reaches your local repository, blocking known malicious packages automatically. + +- **Registry URL**: `/api/v1/dependency-proxy/maven` + +## Configuration + +### Maven + +Add a mirror to your Maven settings (`~/.m2/settings.xml`). `*` routes every repository through DevGuard, including repositories declared in a project's `pom.xml`, so no dependency bypasses the check: + +```xml + + + + devguard + DevGuard Dependency Proxy + https:///api/v1/dependency-proxy/maven + * + + + +``` + +Once set, all `mvn` invocations resolve dependencies and plugins through DevGuard transparently. No changes to your `pom.xml` are required. In CI, commit the file to your repository and pass it with `mvn -s settings.xml`. + + + The proxy fetches artifacts from Maven Central only. Artifacts that are exclusively published to other repositories will not resolve through the mirror. + + +### Gradle + +Replace `mavenCentral()` with the proxy in your `settings.gradle.kts`: + +```kotlin +dependencyResolutionManagement { + repositories { + maven { url = uri("https:///api/v1/dependency-proxy/maven") } + } +} +``` + + + On startup, the proxy blocks all requests until the malicious package database is fully loaded. This initialization period prevents cache poisoning. See [Cache Management](/how-to-guides/dependency-proxy/cache-management) for details. + + +## Testing + +DevGuard ships a test artifact, `com.fake:malicious-package`, that is permanently flagged as malicious for all versions. The script below uses a project-local `settings.xml` and local repository, so it does not touch your `~/.m2`: + +```bash +mkdir -p maven-proxy-test && cd maven-proxy-test + +cat > settings.xml < + $(pwd)/.m2/repository + + + devguard + https:///api/v1/dependency-proxy/maven + * + + + +EOF + +# commons-io and the maven-dependency-plugin are downloaded through the proxy +mvn -B -s settings.xml org.apache.maven.plugins:maven-dependency-plugin:3.8.1:get \ + -Dartifact=commons-io:commons-io:2.16.1 + +# com.fake:malicious-package must be rejected +if mvn -B -s settings.xml org.apache.maven.plugins:maven-dependency-plugin:3.8.1:get \ + -Dartifact=com.fake:malicious-package:1.0.0; then + echo "com.fake:malicious-package was NOT blocked - check your proxy configuration" >&2 + exit 1 +fi + +# check that the proxy answered with 403 Forbidden, for the artifact and for its version list +for path in com/fake/malicious-package/1.0.0/malicious-package-1.0.0.pom \ + com/fake/malicious-package/maven-metadata.xml; do + status=$(curl -s -o /dev/null -w "%{http_code}" \ + "https:///api/v1/dependency-proxy/maven/$path") + if [ "$status" != "403" ]; then + echo "expected 403 Forbidden for $path, got $status" >&2 + exit 1 + fi +done +``` + +If the download is blocked, the proxy is working correctly. Maven reports the `403 Forbidden` in its `Could not transfer artifact` error. All other artifacts resolve normally from Maven Central. + +Checksum verification keeps working behind the proxy: Maven downloads the `.sha1` and `.md5` files of every artifact through DevGuard and verifies them as usual. + +### Testing the minimum package age + +The [minimum package age](/how-to-guides/dependency-proxy#minimum-package-age) is configured per repository and only applies to requests using the repository's proxy URL, which contains a secret. Maven Central has no publish date API, so the proxy uses the upload time Maven Central reports for each file. Versions that are too new are removed from `maven-metadata.xml`, and `` and `` point to the newest version that is old enough. Downloads of a too new version are rejected. + +To verify it, temporarily set the minimum age to 87600 hours (10 years). `com.google.code.gson:gson:2.11.0` was published in May 2024, so the proxy must reject it, while `RELEASE` still resolves to an older version: + + + Maven has no client-side minimum release age. The proxy enforces it centrally, for every build and without any client configuration. + + +```bash +# set the minimum package age of the repository to 10 years +devguard-scanner curl --token -X PUT \ + -d '{"rules":"","minReleaseAge":87600}' \ + https:///api/v1/organizations//config-files/dependency-proxy-configs/ + +# the repository's Maven proxy URL applies its settings +MAVEN_PROXY=$(devguard-scanner curl --token -s \ + https:///api/v1/organizations//dependency-proxy-urls/ \ + | jq -r .maven) + +# same mirror id and local repository, so the plugin downloaded above is reused +cat > settings-min-age.xml < + $(pwd)/.m2/repository + + + devguard + $MAVEN_PROXY + * + + + +EOF + +# gson 2.11.0 is younger than 10 years and must be rejected +if mvn -B -s settings-min-age.xml org.apache.maven.plugins:maven-dependency-plugin:3.8.1:get \ + -Dartifact=com.google.code.gson:gson:2.11.0; then + echo "com.google.code.gson:gson:2.11.0 was NOT blocked by the minimum package age" >&2 + exit 1 +fi + +# check that the proxy answered with 403 Forbidden +status=$(curl -s -o /dev/null -w "%{http_code}" \ + "${MAVEN_PROXY%/}/com/google/code/gson/gson/2.11.0/gson-2.11.0.pom") +if [ "$status" != "403" ]; then + echo "expected 403 Forbidden for com.google.code.gson:gson:2.11.0, got $status" >&2 + exit 1 +fi + +# RELEASE resolves to the newest version that is old enough +mvn -B -s settings-min-age.xml org.apache.maven.plugins:maven-dependency-plugin:3.8.1:get \ + -Dartifact=com.google.code.gson:gson:RELEASE +ls .m2/repository/com/google/code/gson/gson/ + +# reset the minimum package age +devguard-scanner curl --token -X PUT \ + -d '{"rules":"","minReleaseAge":0}' \ + https:///api/v1/organizations//config-files/dependency-proxy-configs/ +``` + +## Further Reading + +- [Dependency Proxy Overview](/how-to-guides/dependency-proxy) +- [Cache Management](/how-to-guides/dependency-proxy/cache-management) +- [Setup npm Proxy](/how-to-guides/dependency-proxy/setup-npm-proxy) +- [Setup Go Proxy](/how-to-guides/dependency-proxy/setup-go-proxy) +- [Setup PyPI Proxy](/how-to-guides/dependency-proxy/setup-pypi-proxy) +- [Setup Composer Proxy](/how-to-guides/dependency-proxy/setup-composer-proxy) +- [OSV (Open Source Vulnerabilities)](https://osv.dev) diff --git a/src/pages/how-to-guides/dependency-proxy/setup-npm-proxy.mdx b/src/pages/how-to-guides/dependency-proxy/setup-npm-proxy.mdx index 3e4f702..fa999ec 100644 --- a/src/pages/how-to-guides/dependency-proxy/setup-npm-proxy.mdx +++ b/src/pages/how-to-guides/dependency-proxy/setup-npm-proxy.mdx @@ -150,4 +150,6 @@ devguard-scanner curl --token -X PUT \ - [Cache Management](/how-to-guides/dependency-proxy/cache-management) - [Setup Go Proxy](/how-to-guides/dependency-proxy/setup-go-proxy) - [Setup PyPI Proxy](/how-to-guides/dependency-proxy/setup-pypi-proxy) +- [Setup Maven Proxy](/how-to-guides/dependency-proxy/setup-maven-proxy) +- [Setup Composer Proxy](/how-to-guides/dependency-proxy/setup-composer-proxy) - [OSV (Open Source Vulnerabilities)](https://osv.dev) diff --git a/src/pages/how-to-guides/dependency-proxy/setup-oci-proxy.mdx b/src/pages/how-to-guides/dependency-proxy/setup-oci-proxy.mdx index 1cd86b1..bfc580b 100644 --- a/src/pages/how-to-guides/dependency-proxy/setup-oci-proxy.mdx +++ b/src/pages/how-to-guides/dependency-proxy/setup-oci-proxy.mdx @@ -100,3 +100,5 @@ done - [Setup npm Proxy](/how-to-guides/dependency-proxy/setup-npm-proxy) - [Setup Go Proxy](/how-to-guides/dependency-proxy/setup-go-proxy) - [Setup PyPI Proxy](/how-to-guides/dependency-proxy/setup-pypi-proxy) +- [Setup Maven Proxy](/how-to-guides/dependency-proxy/setup-maven-proxy) +- [Setup Composer Proxy](/how-to-guides/dependency-proxy/setup-composer-proxy) diff --git a/src/pages/how-to-guides/dependency-proxy/setup-pypi-proxy.mdx b/src/pages/how-to-guides/dependency-proxy/setup-pypi-proxy.mdx index 0bb8cbe..8a0c8d0 100644 --- a/src/pages/how-to-guides/dependency-proxy/setup-pypi-proxy.mdx +++ b/src/pages/how-to-guides/dependency-proxy/setup-pypi-proxy.mdx @@ -178,4 +178,6 @@ deactivate - [Cache Management](/how-to-guides/dependency-proxy/cache-management) - [Setup npm Proxy](/how-to-guides/dependency-proxy/setup-npm-proxy) - [Setup Go Proxy](/how-to-guides/dependency-proxy/setup-go-proxy) +- [Setup Maven Proxy](/how-to-guides/dependency-proxy/setup-maven-proxy) +- [Setup Composer Proxy](/how-to-guides/dependency-proxy/setup-composer-proxy) - [OSV (Open Source Vulnerabilities)](https://osv.dev) \ No newline at end of file diff --git a/src/pages/how-to-guides/index.mdx b/src/pages/how-to-guides/index.mdx index f506561..c88ca63 100644 --- a/src/pages/how-to-guides/index.mdx +++ b/src/pages/how-to-guides/index.mdx @@ -63,6 +63,8 @@ Connect DevGuard with your development platforms: - [Setup npm Proxy](/how-to-guides/dependency-proxy/setup-npm-proxy) — Configure the npm dependency proxy. - [Setup PyPI Proxy](/how-to-guides/dependency-proxy/setup-pypi-proxy) — Configure the PyPI dependency proxy. - [Setup Go Proxy](/how-to-guides/dependency-proxy/setup-go-proxy) — Configure the Go dependency proxy. +- [Setup Maven Proxy](/how-to-guides/dependency-proxy/setup-maven-proxy) — Configure the Maven dependency proxy. +- [Setup Composer Proxy](/how-to-guides/dependency-proxy/setup-composer-proxy) — Configure the Composer dependency proxy. - [Malicious Package Blocking](/how-to-guides/dependency-proxy) — Block malicious packages automatically. - [Cache Management](/how-to-guides/dependency-proxy/cache-management) — Manage the dependency proxy cache. From 0452c22a8feb57ad84d6eadfd04431ab86c7fd1c Mon Sep 17 00:00:00 2001 From: Julian Kepka Date: Tue, 6 Oct 2026 09:27:32 +0200 Subject: [PATCH 2/2] fix: meta description length --- .../how-to-guides/dependency-proxy/setup-composer-proxy.mdx | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/pages/how-to-guides/dependency-proxy/setup-composer-proxy.mdx b/src/pages/how-to-guides/dependency-proxy/setup-composer-proxy.mdx index 952f19c..868f2d9 100644 --- a/src/pages/how-to-guides/dependency-proxy/setup-composer-proxy.mdx +++ b/src/pages/how-to-guides/dependency-proxy/setup-composer-proxy.mdx @@ -1,6 +1,6 @@ --- title: Setup Composer Proxy with DevGuard Dependency Proxy -description: "Configure Composer to route PHP package downloads from Packagist through the DevGuard dependency proxy for malicious package detection and supply chain security." +description: "Configure Composer to route Packagist package downloads through the DevGuard dependency proxy for malicious package detection and supply chain security." seo: robots: index,follow og: