Offer now: 50% off your base fee for 3 months + €100 usage credit.Start trialSee what’s new
Coming early Q4 2026

Container Dependency Firewall

Every Docker and OCI image layer is scanned for malware, secrets and vulnerable OS packages before it reaches developers or a production node.

EU-based company · Software supply chain security since 2018.

Container Firewall
2
Blocked today
304
Requests today
3
Active rules
Image
Rule
Status
library/debian:9
CVSS > 8.5
BLOCKED
library/centos:7
CVSS > 8.5
BLOCKED
library/alpine:3.20
Clean
ALLOWED
ghcr.io/acme/api:1.4
Exception
ALLOWED
node:22-bookworm
Age < 7 days
DELAYED
docker · crane · oras

Easy setup, no changes to your workflow

Log in once and pull as before. Your tooling never notices. Docker, crane and oras talk to the firewall the same way they talk to any registry. From then on, every image your team pulls is checked against your rules.

# Log in to a specific firewall
docker login <firewall-host> \
-u <namespace>/<firewall-id> -p <token>
 
# Pull an image from the firewall
docker pull <firewall-host>/alpine:3.20

What the firewall checks on every pull

Block images with known CVEs
Bytesafe matches every installed OS package against current advisory data. Set a CVSS or EPSS threshold, and images with vulnerabilities above it are blocked.
Find malware and secrets in every layer
Every layer is scanned, and findings apply to the whole image. A secret key committed in an early layer is still reported when a later layer deletes the file, because the layer holding it still ships.
Delay newly published tags
Set a minimum age, and a tag published this morning is held until it has been public for that long. It is the same safety delay Bytesafe applies to new package versions, based on the image's own build date.
Block by name, tag, age or source
Match on repository, tag, release age or upstream, then block or log. When a team needs a blocked image, grant a time-limited exception from the block entry.

Findings grouped by the build step that introduced them

Each build step carries its own severity counts, so you can tell a finding that came with the base image from one your build added.

Bytesafe image page for library/debian:9 showing build steps grouped by base image and a vulnerability table with CVSS scores and fix versions
library/debian:9 resolves to 119 OS packages and 33 advisories, grouped by the base image that introduced them.

Package inventory read from the image

Inventory comes from the package databases inside the image.

Bytesafe image page for library/centos:7 showing 185 packages and 1,127 advisories
library/centos:7: 185 OS packages, 1,127 advisories, 67 of them critical.

Supported OS package formats

Three package formats, covering the base images almost every container starts from.

apk
Alpine
dpkg
Debian, Ubuntu, and distroless images
rpm
RHEL, Fedora, CentOS, SUSE

Offer now

50% off your base fee for 3 months + €100 usage credit.

Creat policies from simple rules

Match on repository name, tag, release age, upstream or upstream type. Add malware, secrets and vulnerability checks on top. Each rule blocks, logs, or both.

Bytesafe rules table for an OCI firewall with secrets, vulnerabilities and malware rules
Three rules on one OCI firewall: secrets on push, CVSS above 8.5 on pull, and malware on pull.

Logs show the image, the rule and the user

Blocked pulls list the image, the tag, the rule and the user. Exceptions can be granted from the block details and expire on a date you set.

Bytesafe firewall log showing blocked pulls of library/centos and library/debian
Block details showing the rule id, execution phase, CVSS threshold, effect and whether an exception can be added
Opening a blocked pull shows the rule that matched, the threshold it used, and whether an exception can be granted.

Works with any OCI registry

Docker Hub, GitHub Container Registry, Amazon ECR, Google Artifact Registry, Artifactory, Harbor, or a registry you run yourself. Each one is configured as an upstream with its own credentials.

Docker Hub
GitHub Container Registry
JFrog Artifactory
Any OCI registry

Frequently asked questions

Common questions from security and platform teams.

Do I have to change my Dockerfiles?
Yes. The firewall host need to be added to the FROM line eg "FROM eu-sov-1.bytesafecloud.eu/alpine:3.20."
Does it work with Kubernetes?
Yes. imagePullSecrets are per registry host, so a cluster pulls through the firewall with one secret and no rewriting of image names across manifests.
What happens on the first pull of an image nobody has pulled before?
The pull waits while the layers are scanned. Every later pull that shares those layers reads the stored findings instead, including pulls of other images and from other teams.
A CVE is published three months after an image was scanned. Is it caught?
Yes. What gets stored is the contents of each layer, never the verdict. Every pull is matched against the advisory data as it stands at that moment, so an image that passed in January is blocked the day an advisory lands that crosses your threshold. Nothing is rescanned and nothing needs re-pulling for that to take effect.
How are multi-arch images handled?
The index is served as-is, and each platform is evaluated on its own manifest when the client resolves it. You see the platform list on the image page and can switch between them.
Which OS package formats are supported?
apk for Alpine, dpkg for Debian and Ubuntu including distroless images that keep packages in status.d, and rpm for RHEL, Fedora, CentOS and SUSE.
Which registries can it proxy?
Any registry that speaks the OCI Distribution spec: Docker Hub, GitHub Container Registry, Amazon ECR, Google Artifact Registry, Artifactory, Harbor, or a registry you run yourself. Each is configured as an upstream with its own credentials, and one firewall can front several at once. Docker Hub is preconfigured so a new firewall works straight away, and adding credentials to it raises its pull rate limit.
Can someone pull a blocked layer directly?
No. A layer is served only after a manifest that references it passed the rules, so requesting a blob by digest does not get around a block.
Which clients work with the firewall?
Any client that follows the OCI Distribution spec should work, including Docker, crane and oras. Each one talks to the firewall the way it talks to a registry, so nothing about how your builds pull images has to change.
Does it replace my container registry?
No. It sits in front of the registries you already use. Images keep living where they live, and the firewall decides which ones reach your builds and clusters.

The same firewall for your package registries

Container images run on the same policy engine, the same advisory data and the same audit log as the package ecosystems below.

Bytesafe Platform

Software Supply Chain Security and Transparency

Three products that block risky packages at install, collect supplier transparency documents, and analyze them.

Book a demo

A 30-minute session where we pull a real image through a firewall with your rules. Your registries stay where they are.

Book a Demo