关于通过防火墙规则仅允许访问带已验证所有者的NuGet包的问询
Great question—this is a super common ask for teams looking to lock down package security without cutting off access to critical dependencies entirely. Let me break down what's possible and the best approach here:
First, the bad news: Firewall URL filters alone can't do this
The "verified package owner" status is metadata that NuGet serves via its API, not something encoded in the package download URLs themselves. All NuGet packages (verified or not) are hosted at URLs likehttps://api.nuget.org/v3-flatcontainer/{package-name}/{version}/{package-name}.{version}.nupkg—there's no difference in the URL structure to distinguish verified vs. unverified packages. So a firewall can't parse that owner status from the URL to block/allow requests.The good news: Use a private NuGet proxy repository as a middle layer
This is the standard enterprise solution for this exact scenario. Tools like Azure Artifacts, GitHub Packages, Nexus Repository, or JFrog Artifactory let you set up a private feed that acts as a proxy to nuget.org, with built-in rules to filter packages:- Configure the private feed to pull packages from nuget.org as an upstream source.
- Enable policies to only sync packages where the owner is verified (most modern private repo tools support this filter).
- Restrict your development servers to only access this private feed via firewall rules, blocking direct access to nuget.org entirely.
- Bonus: You can add extra layers like manual approval for new packages, or enforce package signing requirements to further harden security.
Client-side enforcement as an extra layer
Even with a private repo, you can add a safety net in yournuget.configfile to enforce that only packages from verified owners are installed. Use thepackageSourceMappingandtrustedSignerssections to lock down which sources and owners are allowed. This prevents accidental installs of unapproved packages even if someone bypasses the firewall (though the firewall should be your primary line of defense).
At the end of the day, the firewall can't directly distinguish verified vs. unverified packages, but combining a private proxy repo with firewall restrictions gives you the control you need.
内容的提问来源于stack exchange,提问作者Rob Bowman

