Artifact Firewall 0.3.2

Released: 2026-06-13

Fixed

  • Manifests and artifacts served through a JFrog Artifactory virtual repo are now correctly identified, filtered, and rewritten — in both standalone and integrated mode, with no configuration. Previously the package path was assumed to sit at the registry root, so these requests were skipped (“not a transform path”).
    • npm / PyPI: the Artifactory API prefix (.../api/<type>/<repo>/) is stripped before identification.
    • Maven: maven-metadata.xml and .pom files are evaluated against the coordinates in the document body, not the URL path.
    • NuGet: V3 responses are dispatched by resource token (registration / flatcontainer / query / index.json), which match Artifactory’s layout as well as nuget.org’s.
  • npm and PyPI manifest responses with a Content-Type the firewall can’t filter (an Artifactory vnd.rt npm variant, a charset parameter, or a PyPI HTML simple index) now stream through unchanged instead of returning an error.

®Varnish Software, Wallingatan 12, 111 60 Stockholm, Organization nr. 556805-6203