HTTP 403 error to your package manager, which stops the installation. The error names the reason the package was blocked, such as detected malware or a version that is newer than your organization’s minimum package age policy.
Your security or platform team configures the Package Firewall policy that decides which installations are allowed. You see an error only when the policy blocks a package you request. If it is set to warn instead, the installation still proceeds and no error is shown. Both blocked and warned installations are recorded in the Package Firewall logs. Depending on the block reason, you can add an exception for the package, change the minimum age or vulnerability severity threshold, or update the restricted license list. To modify the policy, contact your security or platform team that manages it.
Package Firewall evaluates each package version against the policy and blocks the installation when the version meets one of the following conditions:
- Malware detected
- Vulnerability detected
- Minimum package age not met
- Restricted license
- All versions blocked