Skip to content

Pass Forge auth token to module resolution - #287

Draft
seanmil wants to merge 1 commit into
OpenVoxProject:mainfrom
seanmil:auth_forge_module_resolutions
Draft

Pass Forge auth token to module resolution#287
seanmil wants to merge 1 commit into
OpenVoxProject:mainfrom
seanmil:auth_forge_module_resolutions

Conversation

@seanmil

@seanmil seanmil commented Aug 18, 2026

Copy link
Copy Markdown
Contributor

If the user has configured an authentication token for a Forge API-compatible endpoint, and if the user is running a version of puppetfile-resolver which supports receiving configuration for an authentication token, then pass it. Otherwise, warn the user that the metadata retrieval will not be authenticated.

This is required for JFrog Artifactory Puppet repositories starting with Artifactory Self-Managed 7.161.16 or Artifactory SaaS 7.164.0, which resolved CVE-2026-66379.

If the user has configured an authentication token for a Forge
API-compatible endpoint, and if the user is running a version
of puppetfile-resolver which supports receiving configuration
for an authentication token, then pass it. Otherwise, warn
the user that the metadata retrieval will not be authenticated.

This is required for JFrog Artifactory Puppet repositories
starting with Artifactory Self-Managed 7.161.16 or
Artifactory SaaS 7.164.0, which resolved CVE-2026-66379.

Signed-off-by: Sean E. Millichamp <sean@bruenor.org>
@seanmil

seanmil commented Aug 18, 2026

Copy link
Copy Markdown
Contributor Author

This should probably be held until puppetlabs/puppetfile-resolver#19 is merged/released.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant