Approved Registries
dependencies.approved-registries
Restricts dependency resolution to an approved list of package registries. Catches projects that pull from a public index instead of the organization's registry, including projects that never configured a registry at all.
Compatible Integrations
This guardrail works with the following integrations. Click to see how to use Approved Registries with each collector.
Enable This Guardrail
Add the parent policy to your lunar-config.yml to enable this guardrail.
policies:
- uses: github://earthly/lunar-lib/policies/dependencies@v1.0.5
include: [approved-registries]
# with: ...
How This Guardrail Works
This guardrail is part of the Dependency Guardrails policy. It evaluates data collected by integrations and produces a pass/fail check with actionable feedback.
When enabled, this check runs automatically on every PR and in AI coding workflows, providing real-time enforcement of your engineering standards.
Learn How Lunar Works →Configuration Options
These inputs can be configured in your lunar-config.yml to customize
how the parent policy (and this guardrail) behaves.
| Input | Required | Default | Description |
|---|---|---|---|
language
|
Required | — | Programming language to check (e.g., "go", "java", "python", "nodejs") |
min_versions
|
Optional |
{}
|
JSON object mapping dependency paths to minimum safe versions (e.g., {"github.com/example/lib": "1.0.0"}) |
include_indirect
|
Optional |
false
|
Whether to also check indirect (transitive) dependencies |
allowed_registries
|
Required | — | Comma-separated list of allowed package registry hosts (e.g. "dl.cloudsmith.io") |
Dependency Guardrails
This guardrail is part of the Dependency Guardrails policy, which includes 3 guardrails for security and compliance.
Ready to Automate Your Standards?
See how Lunar can turn your AGENTS.md, engineering wiki, compliance docs, or postmortem action items into automated guardrails with our 200+ built-in guardrails.