Docs

FC-UIP-PKG-002: Restricted package

Package on the configured disallow list is declared in project.json.

highgovernanceuipathUiPath ST-USG-014

What it detects

Package on the configured disallow list is declared in project.json. Flowcerta surfaces this finding from the active validation pipeline for supported file types and platforms.

Why it matters

This finding matters because it weakens workflow reliability, security posture, or audit readiness.

Example violation

Package on the configured disallow list is declared in project.json.

Fix guidance

UiPath

  • Remove the package from project.json or replace it with an approved alternative before publishing.
  • Use platform-native assets, credentials, bounded retries, and Log Message checkpoints instead of hardcoded literals or silent failure paths.
  • Revalidate the workflow after the change and confirm the finding no longer appears.

Verification steps

  1. Run validation again and confirm the rule no longer appears in the finding list.
  2. Review the changed workflow artifact directly to verify the risky pattern is gone.
  3. Capture the new validation result as evidence for the relevant owner or compliance review.

Compliance references

This page is generated from the canonical Flowcerta rule registry used by validation scoring.

Browse all rule playbooks