NuGetGallery icon indicating copy to clipboard operation
NuGetGallery copied to clipboard

[NuGet.org Bug]: fuget.org is not from trusted domains.

Open dimonovdd opened this issue 4 years ago • 4 comments

Impact

It bothers me. A fix would be nice

Describe the bug

fuget.org is not from trusted domains.

Badges generated in fuget.org are not displayed in the Readme:

Repro Steps

Try using this badge in Readme:

fuget.org

https://www.fuget.org/packages/MSBuild.CompactJsonResources/badge.svg

Expected Behavior

a Badge should be displayed

Screenshots

image

Additional Context and logs

No response

dimonovdd avatar Oct 21 '21 21:10 dimonovdd

@dimonovdd Thank you for your suggestion to add fuget.org. We evaluate each domain that we add to our allowlist from security and privacy perspective. Unfortunately, we are not able to add this domain into our allowlist now. After evaluation, the biggest concern we have is that fuget.org doesn't have proper privacy policy. We will consider to include in the future if they include proper privacy policy. Thanks, please let me know if you have any other question. For now, I suggest you to use other domain that in allowlist as alternative approach.

lyndaidaii avatar Nov 09 '21 07:11 lyndaidaii

This is strange because there is a link to fuget.org in the side menu.

Maybe we should mention @praeclarum

image

dimonovdd avatar Nov 09 '21 08:11 dimonovdd

@dimonovdd, from screenshot you shared, I guess it might be project website of one package. We allow package author to link to their project website if they are not scam link, or not violate a copyright along with other condition. We evaluate image allowlist and project link differently. Since we render those third party image at readme on NuGet.org, it has more privacy and security concerns. Our goal is to protect our customer data. Please let me know if you have more questions.

lyndaidaii avatar Nov 09 '21 18:11 lyndaidaii

related: #9783

304NotModified avatar Apr 23 '24 11:04 304NotModified