Dependency Exemptions
Request, review, and manage temporary exemptions that allow blocked or warned dependencies to be used through Harness Artifact Registry's Dependency Firewall.
When Dependency Firewall flags a package version as Blocked or Warning, an exemption is the supported way to grant temporary access. A developer files a request with a business justification and remediation plan, an approver reviews it, and on approval the version becomes usable for a fixed duration. After the duration elapses the exemption expires and the original policy verdict applies again.
Roles
Requester
Any AR user with download access to artifacts in the project. Files exemption requests from the Policy Violations tab and can edit or withdraw pending requests.
Exemption Approver
Reviews requests and approves or rejects them from the Exemptions tab. The same person can be both Requester and Approver.
Prerequisites
Dependency Firewall is enabled. Go to the Dependency Firewall overview to enable it on your upstream proxy registries.
At least one upstream proxy registry has produced a
WarningorBlockedpolicy violation.For approval actions, the user holds the Exemption Approver role on the project.
Exemption Lifecycle
Every exemption moves through these states:
PENDING
Requester submits the form.
The version stays under its original Warning or Blocked verdict.
APPROVED
Approver approves the request. The duration timer starts now.
The version becomes usable until expiry.
REJECTED
Approver rejects the request.
The original verdict stands.
EXPIRED
The approved duration has elapsed.
The original verdict applies again. A new request is required to renew.
The Exemptions tab summary cards (Total, Approved, Rejected, Pending, Expired) and the row Status column both reflect these states.
Request an Exemption
Requesters file an exemption from a specific row on the Policy Violations tab.
Open Dependency Firewall in the project's left navigation and stay on the Policy Violations tab.
Find the dependency and version you need access to. The Status column shows
WARNINGorBLOCKED.On the row, open the overflow menu (
⋮) and choose Request Exemption.

Fill in the slide-out form. Package Name and Version are pre-filled from the violation row.
FieldDescriptionPackage Name
Pre-filled. Read-only.
Version
Pre-filled. Add additional versions in the same field if more than one is needed.
Exemption duration (in days)
Number of days the exemption stays active once approved.
Business justification
Why the exemption is necessary for your operation.
Remediation plan
How and when you plan to upgrade or replace the dependency.
Click Send Exemption Request. The request enters the
PENDINGstate and is visible to every Exemption Approver on the Exemptions tab.

Review and Decide on a Request
Approvers act on PENDING requests from the Exemptions tab.
Open Dependency Firewall and switch to the Exemptions tab.
Click the Pending Exemptions summary card to filter the table, or use Registries, Package Types, or Search to narrow the list.
Click Details on the row to open the request.
Review the Dependency Information and Exemption Details (requested date, requested duration, business justification, remediation plan).
Click Approve or Reject in the page header.

The status updates immediately on the Exemptions tab. The decision is final, the request cannot be re-opened. To make further changes the requester must submit a new request.
When a request is Approved, the exact package@version is pulled into the corresponding upstream proxy registry and becomes available for use through that registry. Subsequent pulls of that version succeed instead of being blocked by the firewall, until the exemption expires.
Track Exemptions
The Exemptions tab provides a view of every exemption at the current scope and its current state.

The table columns are:
Package Name
Dependency name with its package-type icon.
Versions
Version or versions covered by the exemption.
Upstream Registry
Upstream proxy that surfaced the violation.
Status
Current lifecycle state.
Requested At
Submission time.
Updated At
Last status change (approval, rejection, edit).
Expires At
For APPROVED requests, the absolute expiry timestamp. Pending requests do not expire.
Use the Registries and Package Types dropdowns or the Search box to scope the list.
Edit or Withdraw a Pending Request
Any user with download permission at the current scope can modify a pending request. Once a request reaches APPROVED or REJECTED it is locked.
On the Exemptions tab, find the row in
PENDINGstatus.Open the row overflow menu (
⋮).Choose Edit Exemption to update the duration, justification, or remediation plan, or Delete to withdraw the request.

Troubleshooting
Next steps
Last updated
Was this helpful?