Custom Configuration
How to edit the configuration file on Linux
Custom application configuration can be achieved by editing the customer.env environment file.
The following steps are required to change different parameters in this file:
Navigate to /etc/mdssc/customer.env and open the file
If the parameter that needs to be changed is not present, add the new parameter with the desired value. If it already exists, just edit the value.
Save the file
In order for the changes to apply, please restart the application by running the following command:
Changing certificate validation
This environment variable controls certificate validation for MetaDefender Software Supply chain integrations during HTTP(S) requests. It is useful when comes the needing to accept a partially valid certificate chain or a self-signed certificate.
VALUE can be one of the following:
Default → Invalid certificate instances can't be integrated into MetaDefender Software Supply Chain
IgnoreChainErrors → Instances with certificate chain errors can be integrated
IgnoreAllErrors → Instances with invalid certificate can be integrated
Showing Direct Upload Scans in Results
When enabled, direct file upload scans are included in connection views and scan results.
Default value to this environment variable is true.
Saving Archive Scan Results
When enabled, scan results for archive contents are stored for later access, default value is true.
Waiting for Archive Extraction to Complete
When enabled, the scan process waits until archive extraction is fully completed before continuing. Default value is true.
Waiting for External Processing to Finish
When enabled, the scan process waits for external processing to complete before finalizing. Default value is true.
How Connection Status Is Kept Up to Date
Sets the interval, in milliseconds, for sending heartbeat signals over SignalR connections. This value is also used to throttle status updates for cross-domain transfers.
Default value is 2000 ms.
Archive Scan Performance Mode
When enabled, archive scanning prioritizes speed over detailed inventory results (thinner file inventory inside archives).
Default value is false.
Use this if archive scans feel slow. Setting ARCHIVE_PERFORMANCE_MODE=true typically makes results arrive noticeably faster, with the trade-off of less detailed archive contents.
Maximum Concurrent Discoveries
Controls scan parallelism by allowing more discovery jobs to run at the same time.
Default value is 4.
Use this if small scans wait behind one large scan. Increase the value to process more scans in parallel, but ensure you have enough CPU and memory headroom.
RabbitMQ Scanning Prefetch Count
Controls scan message throughput by defining how many scan messages a worker can prefetch and hold at once.
Default value is 30.
Use this if overall scan throughput is low on strong hardware. Increase the value to let workers pick up more scan work at once. If the system becomes overloaded, lower it instead.
Temporary Archive Retention (Seconds)
Controls how long temporary extracted archive files are kept before cleanup.
Default value is 3600 seconds.
Use this if disk fills up during heavy archive scanning. Lower the value to clean up temporary extracted files sooner.
Number of Trusted Proxies
Sets how many proxies in front of the application are trusted to report the client's IP address.
Default value is 1.
Use this if MetaDefender Software Supply Chain sits behind a load balancer or ingress. Set the value to 2. Otherwise all users share the load balancer's address and are rate-limited together.
Note: The following limits apply to source code repositories, which are downloaded as ZIP archives. Sizes are given in B, KB, MB, GB or TB, where 1 KB = 1024 bytes. A repository that exceeds a limit is not scanned, and the reason appears in the Scan failed message on its report page.
Maximum Archive Download Size
Sets the largest repository archive that can be downloaded for scanning. The download stops as soon as the archive exceeds this size.
Default value is 5GB.
Maximum Archive Extracted Size
Sets the largest total size a repository archive can expand to when it is extracted.
Default value is 10GB.
Use this if a repository fails to scan because its archive expands beyond the maximum extracted size. Raise the value to allow larger repositories, making sure the host has enough free disk space.
Maximum Archive File Count
Sets the largest number of files and folders a repository archive can contain.
Default value is 100000.
Use this if a repository fails to scan because its archive contains too many files. Raise the value to allow repositories with more files.
Maximum Archive Expansion Factor
Sets how many times larger than its compressed size a repository archive can become when extracted.
Default value is 1000.
Use this if a repository with highly compressible content fails to scan because it exceeds the expansion factor. Raise the value to allow it.