user

Inedo Blog


Navigation
AuthorCrista Perlton
Crista Perlton

Crista Perlton

Featured

Inedo

[🎥 New Video] Builds & Projects: Tracking Application Dependencies and Compliance with ProGet and pgutil

Posted on June 23rd, 2026.

Modern applications often rely on hundreds of open-source and third-party packages, making it difficult to track exactly what software is being used across an organization. Without visibility into package usage, teams can struggle to identify vulnerable, deprecated, or non-compliant dependencies and understand their impact on...

Featured

Inedo

Making SBOMs For Your NuGet Projects and Why You Need Them: Generating SBOMs with ProGet and pgutil

Posted on June 11th, 2026.

Software Bills of Materials (SBOMs) have become an increasingly important part of software development. Whether you’re being asked to provide an SBOM to customers, improving supply chain visibility, or simply trying to understand exactly what dependencies your applications contain, having an accurate inventory is becoming a...

Featured

Inedo

Getting Started with pgutil: Managing ProGet from the Command Line

Posted on May 28th, 2026.

If you’ve used ProGet for a while, you may have heard of pgutil, but maybe never really dug into what it does or why you’d use it. Simply put, pgutil is ProGet’s cross-platform command-line tool for managing your instance without having to do everything through the web UI. It’s especially useful for automating repetitive tasks, scripting...

Featured

Python

PyPI Package Dependencies and Their Unintended Consequences

Posted on April 16th, 2026.

Having uncontrolled package dependencies can lead to some unintended consequences, like version conflict and even malicious and vulnerable packages. Let’s see what happens when you let those dependency trees go unchecked.

Featured

ProGet

Choosing the Right S3 Alternatives for Artifact Storage

Posted on December 24th, 2025.

If you work with CI/CD pipelines, artifact repositories, or DevOps workflows, you’ll be familiar with Amazon S3. It’s flexible and widely used, but as your repository grows, costs can add up fast. Storage is just one piece of it; request charges and egress fees can catch teams off guard, especially when traffic spikes. As you...

Featured

Package Management

How File Shares for OSS Packages Create More Problems Than They Solve

Posted on December 11th, 2025.

If you’re managing projects that rely on multiple teams delivering consistent components, you’ve probably noticed the chaos that comes from storing build artifacts and libraries in shared folders. Each team has its own way of organizing files, versions get mixed up, and no one really knows which asset the project should be using....

Featured

Package Management

How Pulling OSS Packages Directly Leads to Chaos

Posted on December 9th, 2025.

You’re likely pulling OSS packages straight from NuGet.org, npmjs.com, or PyPI.org, via the CLI. It’s the path of least resistance and the fastest way to get what your teams need. But without something sitting in the middle, it’s hard to know exactly what’s being pulled in or whether it meets your org’s requirements. When you pull OSS...

Featured

Package Management

How Team-Specific Registries Lead to Organization Wide Friction

Posted on December 4th, 2025.

Internal registries are a smart way to manage OSS packages. They let you curate reusable code for your apps and cut down on risky repeat pulls from the wild. But when every team spins up its own siloed registry and tooling sprawls across the org, you end up with duplicate work, outdated packages, and security headaches that didn’t need...

Featured

ProGet Migration

From Sonatype to ProGet: Simplify Your Migration

Posted on November 28th, 2025.

Inedo’s newest whitepaper, “Migrating from Sonatype to ProGet,” releases this month and is available online. Migrating from Sonatype Nexus to ProGet is more than just copying your packages over. Nexus spreads its features across different products—Repository, Lifecycle, Firewall—while ProGet rolls everything together:...

Featured

Package Management

How Downloading Without Curation Leads to Security Risks 

Posted on November 25th, 2025.

Many teams pull open-source packages into their projects without thinking twice. They might stash them locally, pass them around through CI pipelines, or build and test on their own. But without internal repositories or any guardrails in place, each team ends up working in its own bubble. That kind of flexibility can feel great at first,...