Redesigned policy engine
Rules based on package name, version range, age, license, vulnerability severity (CVSS and EPSS), ecosystem metadata and organization-specific criteria. More granular than the current firewall's plugin-based controls.
The next generation Bytesafe Dependency Firewall intercepts every package request before it reaches developers, CI/CD pipelines or AI agents. Block malicious, vulnerable and policy-violating packages in real time, with every decision logged and explained. Now in early access for new customers, with a supported migration path for existing customers.
The way teams consume open source has changed. Dependencies enter through developers, CI/CD pipelines, automation, AI coding tools and internal repository flows. The current firewall was built around a hosted registry and proxy model that predates this picture.
The next generation Dependency Firewall is designed as a standalone control point. It intercepts package requests from all of these sources, evaluates them against policy and passes decisions to your existing repository. Think of it like a network firewall, but applied to open source dependencies instead of network traffic.
The policy engine is new from the ground up: more granular rules, live decision logs, malware scanning and exception management that the current firewall does not have.
Capabilities not available in the current firewall.
Rules based on package name, version range, age, license, vulnerability severity (CVSS and EPSS), ecosystem metadata and organization-specific criteria. More granular than the current firewall's plugin-based controls.
Catch known malicious packages before they are installed, cached or promoted internally. Uses dedicated malware databases, not just vulnerability feeds.
See exactly why a package was approved, blocked or approved by exception. Live logs show the package, version, rule, requester and timestamp. Developers and security teams read from the same log.
Grant a time-limited exception for a package that would otherwise be blocked. The exception is logged with the reason and expiry. Exceptions expire automatically without manual follow-up.
Manage firewall configuration and rules as code. Review changes in version control, roll back safely and deploy through existing automation.
Packages are scanned for malware, secrets and sensitive data before they are published to an upstream registry.
The next generation Dependency Firewall is a control point only. It sits in front of JFrog Artifactory, Sonatype Nexus, GitLab, Azure DevOps and other repository managers. It does not replace them.
Support for the most popular ecosystems from day one, with a model designed for broader coverage over time.
Works with the repositories you already use
Early access is open
Run the next generation of our existing Dependency Firewall before general availability.
The two products share a name and a purpose. The architecture, policy model and capabilities are different.
Pricing scales with the number of firewall endpoints you run. Developers, package requests and bandwidth are unlimited on every plan.
At hundreds or thousands of developers, per-seat and consumption-based pricing from competitors becomes difficult to forecast and expensive to justify. Most enterprise dependency firewalls charge per developer or per package volume. Adding a team or scaling headcount raises the invoice.
Bytesafe keeps the base model tied to the number of firewalls you control, with optional Cloud add-ons for SSO/OIDC, premium support and container image firewall. Growing headcount does not change your cost. Enterprise plans are available with custom firewall footprints and volume pricing.
See full pricingSupported ecosystems
The current firewall will reach end of life. The timeline has not been set. Existing customers will receive advance notice with a migration path before any action is required.
New customers
New customer onboarding focuses on the next generation Dependency Firewall. We are not onboarding new customers to the current firewall.
Book a demo to see it in action or get a walkthrough of how it fits your setup.
Existing customers
You will continue on the current firewall until a migration path is agreed. We will contact you with a timeline and work through the migration together based on your setup, ecosystems and repository architecture.
If you used the current firewall as a package registry, migration will include moving that storage to a dedicated repository. We can discuss the options with you as part of the migration process.
Questions from prospects, existing customers and teams evaluating the transition.
Talk to us about access, migration or how the new firewall fits with your repository architecture.