Skip to content

Guardrails / clojure

Repositories are ones the team allows ​

clojure/repositories-allowed@v1

Every Maven repository the manifest adds beyond the defaults resolves from a host on the allowed list.

Idclojure/repositories-allowed
Versionv1
Categoryclojure
Default severityerror
Interpreterpython3
Timeout30 seconds
Violations tolerated0
Collectsclojure

Collectors ​

This guardrail doesn't gather anything itself. It relies on the collectors below, which the CLI runs once per build before any check, and reads what they found from GUARDRAIL_FACTS. If a collector collects nothing, this guardrail is skipped, not failed.

CollectorGathersInputs it is given
clojureThe Clojure build in the project directory: which tool it uses, the Clojure version it depends on, the source paths and aliases it declares, the repositories it resolves from, and every dependency with its alias, origin and whether it is pinned.projectDir

The inputs above are this guardrail's own inputs, passed straight through to the collector. Setting one in buildnote.json changes what is collected, and two guardrails configured the same way share a single collection.

Configuration ​

json
{
  "guardrails": {
      "failOn": "error",
      "checks": [
          {
              "use": "clojure/repositories-allowed@v1",
              "severity": "error",
              "with": {
                  "projectDir": ".",
                  "allowedHosts": "repo1.maven.org,repo.clojars.org,clojars.org,central.sonatype.com"
              },
              "exemptions": []
          }
      ]
  }
}

Inputs ​

InputDescriptionDefaultEnvironment variable
projectDirDirectory holding the project, relative to the directory the CLI runs in..GUARDRAIL_INPUT_PROJECTDIR
allowedHostsComma separated hosts a repository may resolve from. A repository on any other host is a violation.repo1.maven.org,repo.clojars.org,clojars.org,central.sonatype.comGUARDRAIL_INPUT_ALLOWEDHOSTS

How to fix ​

Resolve only from hosts your team has vetted, and give every repository entry the URL it resolves from:

clojure
{:mvn/repos {"clojars" {:url "https://repo.clojars.org/"}}}

Add an internal mirror to allowedHosts instead of leaving it unnamed. An unvetted repository is exactly what a dependency confusion attack needs: if someone publishes a package under your coordinates on a host the build can reach, the build resolves it as if it were yours. An entry with no :url tells you nothing about where its artifacts come from.

More in clojure ​

  • clojure/dependencies-pinned. Every dependency in the manifests names a single released version, or the exact commit a git dependency builds from.
  • clojure/no-local-dependencies. No dependency comes from a :local/root, so the build resolves everything from this commit and not from the machine it runs on.
  • clojure/version-declared. The project depends on the Clojure release it builds against, and that release is no older than the configured floor.

All 4 clojure guardrails

Buildnote Limited
Registered in England and Wales, Reg: 16140412