Corporate and addons

19 views
Skip to first unread message

Sean Randall

unread,
Jul 16, 2026, 4:38:22 AM (10 days ago) Jul 16
to nvda-...@nvaccess.org

HI list

 

I have recently returned to work after we had a baby and  my employer’s now running a zero trust security policy. I couldn’t use NVDA’s check for updates feature even with administrative access because the URl wasn’t vetted. This was easy enough to work around because the website wasn’t blocked, so I could download the installer.

 

The next problem was addons; the addonstore.nvaccess.org subdomain had to be let through the system. This is a 2 or 3 day process, but now NVDA happily reports which of my addons are out-of-date.

 

The problem is that I presume the addons themselves are all stored outside nvaccess? I can’t download any of them. If I have to get exemptions for every single github repo I’m going to go mad.

 

Can anyone validate this is indeed how the addon store works before I proceed further? I.e. it’s a catalogue pointing to a variety of other URLs, without hosting the addons directly?

 

Thanks,

Sean.

 

--

Sean Randall
Digital accessibility Specialist.
Email: con...@SeanRandall.me
Tel/Whatsapp/iMessage: +44(0)7969662640
UK.Linkedin.Com/In/AccessibleSean

 

Obaida Tamimi

unread,
Jul 16, 2026, 4:50:33 AM (10 days ago) Jul 16
to nvda-...@nvaccess.org
" Hi Sean,
Welcome back to work! Regarding your question, you are absolutely correct. The NVDA Add-on Store functions primarily as a directory or catalogue.
It points to various external locations (such as GitHub repositories or other developer-hosted URLs) where the actual add-on files (.nvda-addon) reside. It does not host the files directly on NV Access servers. This is why you are encountering issues with your company's 'zero trust' security policy, as the system tries to reach those external domains.
Unfortunately, if your security policy requires vetting every individual URL, you would indeed need to whitelist each repository as you attempt to download them.
Hope this clarifies things for you!


--
***
Please note: the NVDA project has a Citizen and Contributor Code of Conduct.
NV Access expects that all community members will read and abide by the rules set out in this document while participating in this group.
https://github.com/nvaccess/nvda/blob/master/CODE_OF_CONDUCT.md
 
You can contact the group owners and moderators via nvda-user...@nvaccess.org.
---
You received this message because you are subscribed to the Google Groups "NVDA Screen Reader Discussion" group.
To unsubscribe from this group and stop receiving emails from it, send an email to nvda-users+...@nvaccess.org.
To view this discussion visit https://groups.google.com/a/nvaccess.org/d/msgid/nvda-users/003101dd14fe%24732dc110%2459894330%24%40seanrandall.me.

Sean Randall

unread,
Jul 16, 2026, 5:04:57 AM (10 days ago) Jul 16
to nvda-...@nvaccess.org

Thanks for confirming that.

I think what I’ll do is take a portable copy off the work system, update the addons outside work, and then bring them back into my application data. This might cause the occasional issue with addons doing tasks on install? I wonder if I can work around that by leaving them as pending on the portable and having them effectively look like they were  installed manually? Or maybe I’ll just get the addon files and do them one at a time.

 

It’s a bit of a bear, but it shouldn’t be too bad.

 

Thanks for confirming again.

 

S.

Obaida Tamimi

unread,
Jul 16, 2026, 5:15:29 AM (10 days ago) Jul 16
to nvda-...@nvaccess.org
Good luck! If you need any help, don't hesitate to contact the group.


Matthew Horspool

unread,
Jul 16, 2026, 8:59:49 PM (10 days ago) Jul 16
to nvda-...@nvaccess.org

Hi Sean,

I wouldn't bother leaving them pending in the portable copy at the outset. I can't imagine that any tasks on install are important enough to be run specifically on the work computer. If they need to write files, there's a good chance that either those files will be stored in UserConfig anyway, or they're stored outside UserConfig but don't need to be rewritten every time there's an update.

Of course, if an add-on doesn't work after the portable copy has been merged back in, trying again with add-ons pending wouldn't be a bad trouble shooting step, but I'd be amazed if you find you need to do this.

Matthew

Reply all
Reply to author
Forward
0 new messages