More flexible rules
Build rules on package name, version range, age, license, vulnerability score (CVSS and EPSS), upstream and other package properties. Conditions combine.
If you use the previous-generation Bytesafe, this page is for you. The new Dependency Firewall is open for evaluation, and we are starting to move customers across.
Everything you need to plan and run the migration is on this page. Start evaluating now, well ahead of the end-of-life date.
End of life
December 31, 2026
Previous-generation Bytesafe
This date does not apply to the new Dependency Firewall.
The previous generation combines dependency security with a hosted package repository. The new generation separates them: Bytesafe enforces policy on every package request, and your packages are stored by your repository manager or the upstream registry. That separation is what makes the new capabilities possible.
Previous generation
Packages are stored in Bytesafe. Policies and plugins control what can be used.
New generation
The firewall checks every request against your firewall rules and exceptions. Private packages are stored in your repository manager.
How much work the migration is depends on where your packages live today.
Only public packages: nothing to move. Set up your firewalls and rules, then point your package managers at them.
A repository manager you already run: it keeps storing your packages while Bytesafe enforces policy. JFrog Artifactory, Sonatype Nexus, GitHub Packages, GitLab, Azure Artifacts and AWS CodeArtifact all work.
Private packages stored in Bytesafe: those packages need to be moved to a dedicated package repository.
A redesigned policy and enforcement model, plus capabilities the previous-generation firewall does not have.
Build rules on package name, version range, age, license, vulnerability score (CVSS and EPSS), upstream and other package properties. Conditions combine.
Block known malicious packages before they reach a developer machine or a CI/CD pipeline.
Every request is logged: the package, the version, the rule that made the decision and who asked for it.
Let a blocked package through with a documented exception. Set an expiry and the exception lifts itself.
Configure everything in the dashboard, or take the same configuration as JSON through the API and CLI, keep it in version control and review policy changes like code.
Packages are inspected for malware, secrets and sensitive data before they are published to an upstream registry.
Most existing customers should pay about the same or less. We can confirm your expected price before you migrate.
Your plan is based on whichever is highest: active users, packages scanned or downloads served. The other two are included.
A few customers may pay more because of higher usage or Enterprise requirements. We will review your setup and confirm your price before you move.
Existing-customer migration offer
Base fee and usage, first 3 months after migration
50%off
No double payment. Your offer starts when your previous-generation subscription closes and the new one begins.
Nothing switches at once. Both generations run at the same time while you set up and test the new firewall, so you move at your own pace. Evaluating and migrating come at no additional cost.
Sign up yourself, no approval needed. Trials start at 14 days, and we automatically extend them for existing customers to cover the full evaluation and migration period at no additional cost. Set up a firewall, point one project or CI/CD pipeline at it, and compare what it allows and blocks against your existing setup.
Recreate policies as rules, connect a repository manager and move private packages. Your current setup keeps working until you point traffic away from it, and nothing is switched off on our side before the end-of-life date.
After you migrate, tell us when your offer should start. We close your previous-generation subscription and apply 50% off your new invoice, base fee and usage, for the first 3 months after migration, so you never pay for both.
How the new firewall works, how to configure rules and exceptions, connect package ecosystems and integrate with your environment.
Explore the documentationThe detailed process for moving registries, private packages, policies and plugins from the previous generation.
Read the migration guideEvery setup is different. Ask us about your migration plan, repository architecture, moving private packages, recreating existing policies, pricing or how the new Dependency Firewall fits your environment.
Start a trial now, evaluate and migrate at no additional cost, and get 50% off the entire invoice, base fee and usage, for the first 3 months after migration. Contact us if you would like to review the migration together first.