FAQ
Using Package Masks
1min
Under Package Mask Configurations you can specify your company's internal package naming convention.
Package masks help SOOS identify your internally developed packages when SCA scans are performed. Adding package masks helps SOOS link together projects and avoid gaps when generating dependency trees by ensuring that your internal packages are not shown as Unknown Package Issues within the dependency tree.
Internal packages are easily identifiable in the Dependency Tree.
More importantly, it helps to warn you about Dependency Substitution attacks where a malicious actor may try to publish a public package with the same name as your internal packages.
Updated 25 Feb 2025
Did this page help you?