Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[NuGet.org Bug]: fuget.org is not from trusted domains. #8856

Open
dimonovdd opened this issue Oct 21, 2021 · 4 comments
Open

[NuGet.org Bug]: fuget.org is not from trusted domains. #8856

dimonovdd opened this issue Oct 21, 2021 · 4 comments
Assignees
Labels

Comments

@dimonovdd
Copy link

Impact

It bothers me. A fix would be nice

Describe the bug

fuget.org is not from trusted domains.

Badges generated in fuget.org are not displayed in the Readme:

Repro Steps

Try using this badge in Readme:

fuget.org

https://www.fuget.org/packages/MSBuild.CompactJsonResources/badge.svg

Expected Behavior

a Badge should be displayed

Screenshots

image

Additional Context and logs

No response

@lyndaidaii lyndaidaii self-assigned this Nov 4, 2021
@lyndaidaii
Copy link
Contributor

lyndaidaii commented Nov 9, 2021

@dimonovdd Thank you for your suggestion to add fuget.org. We evaluate each domain that we add to our allowlist from security and privacy perspective. Unfortunately, we are not able to add this domain into our allowlist now. After evaluation, the biggest concern we have is that fuget.org doesn't have proper privacy policy. We will consider to include in the future if they include proper privacy policy. Thanks, please let me know if you have any other question. For now, I suggest you to use other domain that in allowlist as alternative approach.

@dimonovdd
Copy link
Author

This is strange because there is a link to fuget.org in the side menu.

Maybe we should mention @praeclarum

image

@lyndaidaii
Copy link
Contributor

@dimonovdd, from screenshot you shared, I guess it might be project website of one package. We allow package author to link to their project website if they are not scam link, or not violate a copyright along with other condition. We evaluate image allowlist and project link differently. Since we render those third party image at readme on NuGet.org, it has more privacy and security concerns. Our goal is to protect our customer data. Please let me know if you have more questions.

@304NotModified
Copy link
Contributor

304NotModified commented Apr 23, 2024

related: #9783

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

3 participants