Skip to content

Commit bf801ab

Browse files
authored
Update trusted domains for image rendering on NuGet.org (#3462)
Syncing the published image allow list
1 parent 952d25c commit bf801ab

1 file changed

Lines changed: 8 additions & 9 deletions

File tree

docs/nuget-org/package-readme-on-nuget-org.md

Lines changed: 8 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -78,42 +78,41 @@ Due to security and privacy concerns, NuGet.org restricts the domains from which
7878

7979
NuGet.org allows all images, including badges, from the following trusted domains to be rendered:
8080
* api.codacy.com
81-
* app.codacy.com
8281
* api.codeclimate.com
8382
* api.dependabot.com
84-
* api.travis-ci.com
8583
* api.reuse.software
86-
* app.fossa.com
87-
* app.fossa.io
84+
* api.travis-ci.com
85+
* app.codacy.com
86+
* app.deepsource.com
8887
* avatars.githubusercontent.com
89-
* badge.fury.io
9088
* badgen.net
9189
* badges.gitter.im
92-
* buildstats.info
93-
* caniuse.bitsofco.de
9490
* camo.githubusercontent.com
91+
* caniuse.bitsofco.de
9592
* cdn.jsdelivr.net
9693
* cdn.syncfusion.com
9794
* ci.appveyor.com
9895
* circleci.com
96+
* cloudback.it
9997
* codecov.io
10098
* codefactor.io
10199
* coveralls.io
102100
* dev.azure.com
103101
* flat.badgen.net
104102
* github.com/.../workflows/.../badge.svg
105103
* gitlab.com
106-
* img.shields.io
107104
* i.imgur.com
105+
* img.shields.io
106+
* infragistics.com
108107
* isitmaintained.com
108+
* media.githubusercontent.com
109109
* opencollective.com
110110
* raw.github.com
111111
* raw.githubusercontent.com
112112
* snyk.io
113113
* sonarcloud.io
114114
* travis-ci.com
115115
* travis-ci.org
116-
* wakatime.com
117116
* user-images.githubusercontent.com
118117

119118
If you feel that another domain should be added to the allow-list, please feel free to [file an issue](https://github.com/NuGet/NuGetGallery/issues) and it will be reviewed by our engineering team for privacy and security compliance. Images with relative local paths and images hosted from unsupported domains will not be rendered and will produce a warning on the readme file preview and package details page that is only visible to the package owners.

0 commit comments

Comments
 (0)