Offer now: 50% off your base fee for 3 months + €100 usage credit.Start trialSee what’s new

Block risky dependencies at the perimeter.

The next generation Bytesafe Dependency Firewall intercepts every package request before it reaches developers, CI/CD pipelines or AI agents. Block malicious, vulnerable and policy-violating packages in real time, with every decision logged and explained. Existing customers get a supported migration path.

bytesafe.dev / Firewall
47
Blocked today
1,284
Requests today
12
Active rules
Package
Rule
Status
malicious-pkg@2.1.0
Malware scan
BLOCKED
lodash@4.17.20
CVSS ≥ 7.0
BLOCKED
react@19.1.1
Allowlist
APPROVED
new-release@0.0.1
Age < 7 days
DELAYED
axios@1.7.9
Allowlist
APPROVED
Blocked
malicious-pkg@2.1.0
Malware
By Exception
lodash@4.17.21
Exception
Delayed
new-release@0.0.1
Age < 7d
Approved
react@19.1.1
Allowlist

Why a new dependency firewall?

The way teams consume open source has changed. Dependencies enter through developers, CI/CD pipelines, automation, AI coding tools and internal repository flows. The previous-generation firewall was built around a hosted registry and proxy model that predates this picture.

The next generation Dependency Firewall is designed as a standalone control point. It intercepts package requests from all of these sources, evaluates them against policy and passes decisions to your existing repository. Think of it like a network firewall, but applied to open source dependencies instead of network traffic.

The policy engine is new from the ground up: more granular rules, live decision logs, malware scanning and exception management that the previous-generation firewall does not have.

What the next generation Dependency Firewall adds

Capabilities not available in the previous-generation firewall.

Redesigned policy engine

Rules based on package name, version range, age, license, vulnerability severity (CVSS and EPSS), ecosystem metadata and organization-specific criteria. More granular than the previous-generation firewall's plugin-based controls.

Malware scanning

Catch known malicious packages before they are installed, cached or promoted internally. Uses dedicated malware databases, not just vulnerability feeds.

Decision transparency

See exactly why a package was approved, blocked or approved by exception. Live logs show the package, version, rule, requester and timestamp. Developers and security teams read from the same log.

Time-limited exceptions

Grant a time-limited exception for a package that would otherwise be blocked. The exception is logged with the reason and expiry. Exceptions expire automatically without manual follow-up.

Policy as code

Manage firewall configuration and rules as code. Review changes in version control, roll back safely and deploy through existing automation.

Publish scanning

Packages are scanned for malware, secrets and sensitive data before they are published to an upstream registry.

Standalone. No package manager included.

The next generation Dependency Firewall is a control point only. It sits in front of JFrog Artifactory, Sonatype Nexus, GitLab, Azure DevOps and other repository managers. It does not replace them.

npm, PyPI, Maven, NuGet, Go, Composer, Cargo, Conda, Containers

Support for the most popular ecosystems from day one, with a model designed for broader coverage over time.

Flexible deployment

Managed SaaS hosted in the EU by default. Also runs in your own cloud account or in your data center. On-premise keeps every package request and decision log inside your network.

Works with the repositories you already use

JFrog Artifactory
Sonatype Nexus
GitLab
GitHub Packages
Azure Artifacts
AWS CodeArtifact

Offer now

50% off your base fee for 3 months + €100 usage credit.

How the next generation Dependency Firewall differs from the current one

The two products share a name and a purpose. The architecture, policy model and capabilities are different.

Next gen
Current
What it is
Standalone Dependency Firewall. Sits in front of your existing package registry manager and does not replace it.
Package registry manager with security policies. The previous-generation firewall stores and serves packages.
Package management
No package manager. Designed for teams that already run JFrog Artifactory, Sonatype Nexus, GitLab, Azure DevOps or similar.
Built-in package registry. Teams without a dedicated repository manager used it for storage and serving.
Policy engine
Redesigned rule engine: package name, version range, age, license, CVSS, EPSS and custom rules. More granular and more composable.
Plugin-based controls: vulnerability scanner, license compliance, quarantine, delay upstream, block install scripts and others.
Package state
Stateless: packages are approved, blocked or approved by exception. Observations track which packages have passed through and when.
Quarantine state: packages can be held pending review or attestation.
Decision visibility
Live logs showing the package, version, requester, rule and outcome. Developers see exactly why an install failed and who triggered it.
Basic activity logging.
Exceptions
Time-limited exceptions with an approval trail. Exceptions expire automatically and are logged with the reason.
Not available.
Vulnerability blocking
Define exact CVSS and EPSS score thresholds per rule. Block on numeric score, not just severity label.
Vulnerability scanner plugin with severity levels (Low, Moderate, High, Critical).
Malware scanning
Built-in scanning against dedicated malware databases. Separate from vulnerability feeds.
Not available. Vulnerability feeds only.
Publish scanning
Packages are scanned before upload to your upstream registry.
Not included.
Operations
API-driven. Policy as code. Designed for automation and GitOps workflows.
Managed through the current product UI.
Ecosystems
npm, PyPI, Maven, NuGet, Go, Composer, Cargo, Conda, Containers. Broader coverage planned.
npm, NuGet, Maven, PyPI.
Status
Active. New customer onboarding focuses on the next generation Dependency Firewall.
Previous-generation firewall. End of life December 31, 2026. Existing customers can evaluate the new generation now and follow the supported migration path.

One meter sets your price.
The other two come with it.

Your price follows whichever you use most: active users, packages scanned or downloads served. The other two are included at the same plan size.

Enterprise dependency firewalls most often bill on several axes at once: a seat count, a scan count and a bandwidth line, each with its own overage. One team pays three times for being a single size measured three ways, and the invoice is hard to forecast.

Bytesafe measures all three meters and charges for the largest one only. The price per unit falls as you grow. Nothing throttles and nothing blocks when a month runs heavy: the plan sizes itself to the trailing 30 days and settles back as the spike ages out. Optional Cloud add-ons cover SSO/OIDC, container image firewall and Deep Scan. Enterprise plans agree limits in the contract.

See full pricing

Migration and end of life

The previous-generation Bytesafe reaches end of life on December 31, 2026. Existing customers can start evaluating the new generation now and migrate before that date. We provide a supported migration path and work through the transition with you based on your setup, ecosystems and repository architecture.

New customers

New customer onboarding focuses on the next generation Dependency Firewall. We are not onboarding new customers to the previous-generation firewall.

Book a demo to see it in action or get a walkthrough of how it fits your setup. Or start a free trial and set up your first policy.

Existing customers

You can keep using the previous-generation firewall while you prepare and test your migration. Both generations run at the same time, so you can validate the new firewall before production workloads switch.

If you use Bytesafe to store private packages, migration also includes moving those packages to a dedicated repository manager or private registry.

Plan your migration

Common questions

Questions from prospects, existing customers and teams evaluating the transition.

Can existing customers use the next generation Dependency Firewall today?
Yes. Start a free trial today and evaluate the new Dependency Firewall while continuing to use the previous-generation firewall. The migration page for existing customers covers the process, the commercial offer and the relevant documentation.
When will the previous-generation firewall reach end of life?
The previous-generation Bytesafe reaches end of life on December 31, 2026. Existing customers can evaluate the new generation now and migrate before that date. We help plan the migration based on your existing Bytesafe setup and repository architecture.
Are new customers onboarded to the previous-generation firewall?
No. New customer onboarding focuses entirely on the next generation Dependency Firewall.
Will migration be automatic?
No. We will work with each customer to determine the right migration approach based on their setup, ecosystems and repository architecture. Migration paths will differ depending on whether you used the previous-generation firewall as a registry or only as a proxy.
Does the next generation Dependency Firewall replace our existing repository manager?
No. The next generation Dependency Firewall is a standalone control point designed to work in front of your existing repository. It does not store or serve packages.
The previous-generation firewall also stored our packages. What happens to that?
The new Dependency Firewall is a standalone enforcement layer with no package storage. If you relied on the previous-generation firewall for package storage, you will need to migrate to a private package repository such as JFrog Artifactory, Sonatype Nexus or a similar solution. if you would like to discuss a migration path.
Which ecosystems are supported?
npm, PyPI, Maven, NuGet, Go, Composer (beta), Cargo (beta), Conda (beta) and Containers are supported. Additional ecosystem support is planned. Contact us if you need a specific ecosystem that is not listed.
How does pricing work?
Cloud is priced on whichever you use most: active users, packages scanned or downloads served. The other two are included at the same size, so you are never billed twice for one team. From EUR 99 a month. See the pricing page for current plans.

Prepare for the next generation Dependency Firewall

Talk to us about access, migration or how the new firewall fits with your repository architecture.

See how it worksBook a demo