Dependency Firewall offer: 50% off your base fee for 3 months + €100 usage credit.Start trialSee what’s new

PyPI Dependency Firewall

Python packages can execute build code when installed from source. Bytesafe blocks risky packages before they reach pip, uv or Poetry. New releases can also be delayed to reduce exposure to emerging threats.

Dependency Firewall sits in front of your existing repository, protecting developers, CI/CD pipelines and AI agents.

EU-based company · Software supply chain security since 2018.

Logs

Firewall pypi-ci
StatusPackageRule
Allowed
pyyaml@5.3.1
Exception
Blocked
django@3.2.0
Block CVSS ≥ 7
Allowed
numpy@2.3.3
Log all downloads
Blocked
fastapi@0.118.0
Delay 7 days
Blocked
ctx@0.2.2
Known malware
Allowed
requests@2.32.5
Log all downloads
Allowed
boto3@1.40.40
Log all downloads
Allowed
pydantic@2.11.9
Log all downloads

Intercepts every PyPI package request before it reaches you.

Every package install is a potential entry point. Traditional SCA tools find problems after packages are already in your environment. Dependency Firewall intercepts every PyPI request before it reaches your developers, CI/CD pipelines or AI agents.

You define the rules: block packages with known CVEs, block known malicious packages, or delay newly published versions for a configurable period to give the ecosystem community time to surface zero-day threats.

Works in front of enterprise repository platforms and any PyPI registry. No agent installs. No workflow changes.

Public PyPI registry

Vulnerable and malicious versions included

Risky packages
Bytesafe

Dependency Firewall

Policy engine
Vetted packages only

Developers and CI/CD

Internal environment

What Dependency Firewall does for PyPI

Each firewall runs the checks you turn on, on every package request. Rules block or log, and every decision is recorded.

Malware blocking
Blocks packages that match malware data, including malicious payloads and suspicious install hooks. Every block is logged with the package and the rule.
Vulnerability blocking
Blocks versions with CVEs above a CVSS or EPSS score you set, per firewall. New advisories apply on the next request.
Package delay
Holds newly published versions for a window you set, so malware feeds can catch a bad release before your builds install it.
Time-limited exceptions
Unblock one package or version with a reason and an expiry date. The rule keeps applying to everything else, and the exception lapses on its own.
Dependency confusion
Upstream priority rules make internal package names always resolve from your private registry. A public package with the same name cannot take its place.
Package observations
Every package that passes records first-seen and last-seen time and request counts. When a new advisory lands, you see which firewalls served the package and since when.
Audit log
Every allow, block and exception is logged with the package, version, rule, requester and time. Export it to your SIEM.

Dependency Firewall offer

Half the base fee for your first 3 months

€49.50 instead of €99 per month, plus €100 usage credit. Start with a 14-day trial. See what's new

How PyPI installs go through the firewall

Your package manager asks the firewall instead of the public registry. The firewall fetches the package from upstream, checks it against your rules and serves it only if it passes.

  1. 1

    Change the registry setting

    Point pip, uv or Poetry at the firewall, on laptops and CI runners. Lockfiles, manifests and install commands stay the same.

  2. 2

    Set the rules

    Block by CVSS or EPSS score, known malware, license or package age. Shared rules go on a baseline firewall that team and CI firewalls inherit, and they run first.

    Rules on a firewall: block downloads with CVSS above 7, log all downloads, and a 7-day delay inherited from npm-baseline
    Rules on the npm-ci firewall. The 7-day delay is inherited from npm-baseline. Shown for npm.
  3. 3

    Read the log

    A version held back by a rule is left out of the version list, so the package manager resolves an older one. A blocked download fails the install. Every decision is logged with the rule and who asked.

    Firewall log: lerna, nx and js-yaml versions blocked by the 7-day delay, other packages allowed
    New versions held by the delay rule, next to allowed downloads. Shown for npm.

Configure pip to install through Dependency Firewall

Set your pip index URL to the Bytesafe Dependency Firewall endpoint. pip, Poetry, uv and Pipenv all support custom index URLs. Existing requirements files and pyproject.toml dependencies continue to work without changes.

Works with the repositories you already use

JFrog Artifactory
Sonatype Nexus
GitLab
GitHub Packages
Azure Artifacts
AWS CodeArtifact

Inside Dependency Firewall

The screens your developers and security team work with.

1 of 7 · Logs

Live firewall logs

Every request is logged: package name, version, status, ecosystem, which firewall evaluated it, which rule triggered and who requested it. Filter by firewall or user, and tail live during incidents or CI/CD runs.

Developers get a fast answer when an install fails, and AppSec gets an audit trail for every decision.

Live request log with blocked packages and rule details
Live request log with blocked packages and rule details

Known attacks on PyPI

Malicious releases, account takeovers and dependency confusion have all been used against packages there.

ultralytics

Compromised package

The ultralytics PyPI package (a popular computer vision library with millions of downloads) was compromised via a malicious GitHub Actions workflow. The attacker published versions with a cryptomining payload embedded.

ctx

Account takeover

An attacker published a malicious version of the ctx package, which had been abandoned for years. The new version exfiltrated all environment variables to an external server. Any project using ctx in a CI/CD pipeline leaked secrets.

colourama

Typosquatting

A package named colourama (one letter from colorama, one of the most downloaded PyPI packages) contained a cryptocurrency clipboard hijacker. A single typo in requirements.txt installed malware silently.

Also blocks vulnerable and malicious container images before they reach a build agent or production node.

Container Dependency Firewall

Compared with other enterprise dependency firewalls

Other enterprise dependency firewalls are often bundled into repository platforms. Dependency Firewall is an independent firewall that works with any registry and is built in the EU.

CriterionDependency FirewallOther enterprise firewalls
Works with your existing repositoryYes, as a proxy in front of itBundled into their platform most often
Deploys in minutesYesUsually weeks of platform work most often
Predictable pricingOne meter sets the price, no overageSeveral axes with overage most often
EU data residencyYesNo, US-based most often

Frequently asked questions

How do I configure pip to use Bytesafe Dependency Firewall?
Set the index-url in your pip.conf (or pip.ini on Windows) to your Bytesafe Dependency Firewall endpoint. For CI/CD, set the PIP_INDEX_URL environment variable. See docs.bytesafe.dev for the full configuration reference.
Does it work with Poetry, uv and Pipenv?
Yes. Poetry supports custom sources via [[tool.poetry.source]] in pyproject.toml. uv supports index configuration via uv.toml or environment variables. Pipenv supports PIPENV_PYPI_MIRROR. All point to the same Bytesafe Dependency Firewall endpoint.
Can I protect AI agent environments and model training pipelines?
Yes. AI and ML pipelines frequently run pip install in containers and serverless environments. Pointing those environments at Bytesafe Dependency Firewall ensures the same security policies apply to automated installs as to developer workstations.
Does it work with private Python packages on a private PyPI server?
Yes. Bytesafe Dependency Firewall can proxy multiple index sources. Internal packages resolve from your private PyPI server, and public packages resolve from PyPI. Dependency confusion attacks that target internal package names are blocked.
Can different PyPI projects have different policies?
Yes. You can create separate firewalls per project. They are lightweight and easy to clone. You can also differentiate by the user or token used for the session. Firewall configurations are small JSON files that can be managed in Git.
Can PyPI packages be delayed before they reach developers?
Yes. Dependency Firewall can hold newly published package versions for a window you configure before they reach developers or pipelines. Centralizing delay rules means the protection applies automatically across all teams and pipelines without each project configuring it separately.
What happens if a PyPI package passes through but malware is found later?
The firewall tracks all packages via observations: first-seen date, last-seen date, and which firewalls they passed through. When new malware data surfaces, you can see exactly which projects downloaded the affected package and when.
Can firewall rules be automated?
Yes. All configuration is available via API. Configurations can be version-controlled in Git and deployed through your existing automation. All changes are tracked with full rollback support.
Does Dependency Firewall work with enterprise repository platforms?
Yes. Dependency Firewall speaks the same protocols as your package managers, so it is fully transparent to enterprise repository platforms and package registries, including JFrog Artifactory, Sonatype Nexus, GitLab, GitHub Packages and Azure Artifacts.
How is licensing structured?
Two plans: Cloud for SaaS and Enterprise for custom deployment, Managed Cloud or On-Premise. Cloud is priced on whichever you use most: active users, packages scanned or downloads served. See pricing for plan details and add-ons.

Bytesafe Platform

Software Supply Chain Security and Transparency

Three products that block risky packages at install, collect supplier transparency documents, and analyze them.

Put PyPI installs behind the firewall

Try the setup above on one project and check the firewall log after the next install. Or book a demo and go through your registries and rules with an engineer.

Book a Demo