Couple of questions before next week relating to Dagger as a bit of a 'walled garden' which I think may be of interest, particularly to enterprise users:
-
Can the Dagger engine differentiate between queries made to it that originated from
dagger callvsdagger query/dagger run/dagger anything else? If so, could it be configured to disable anything other thandagger call? -
Could there be an option to whitelist certain domains? e.g. Dagger engine configuration that allows modules and dependencies from
company.gitlab.combut errors if a module or dependency is from anywhere else.
Context: I think an option to have Dagger restricted to approved sources only would be well-received. Appreciate this can be (and is usually) done outside of Dagger, but if these would be small changes that can get security teams onside that might be an easy win.