Dependency Firewall offer: 50% off your base fee for 3 months + €100 usage credit.Start trialSee what’s new

How Dependency Firewall checks every package before install

Dependency Firewall sits between your builds and the package registries. Each request is checked against your rules before the package reaches a developer, pipeline or AI agent.

Where Dependency Firewall sits

Between the public registries and everything that installs packages. Clients keep using npm, pip, Maven or Docker. Only the registry URL changes.

How this compares to SCA scanners and repository managers

Follow one package request

A pipeline asks for lodash 4.17.20, a version with a known high-severity CVE. Here is what the firewall does with it.

  1. 1

    Request

    A CI job runs npm install. npm asks the firewall for lodash, the same way it would ask the public registry.

    $ npm install lodash@4.17.20
    # registry=https://registry.bytesafe.dev/r/team-web/
  2. 2

    Check

    Dependency Firewall fetches the package from upstream and runs every rule on the firewall against it.

    lodash@4.17.205 rules on team-web
    • Known malwareNo match
    • Install scriptsNone
    • Release age ≥ 7 daysPublished 2020
    • License allowlistMIT
    • CVSS ≥ 7.0CVE-2021-23337, 7.2
  3. 3

    Decide

    One failing rule is enough. The version is blocked, and npm sees a version that does not exist.

    npm error code ETARGET
    npm error notarget No matching version found for lodash@4.17.20.
  4. 4

    Log

    The build stops before any code from the package runs. The log records the rule, package, version, user and IP.

    Time
    2026-09-29 09:58:13
    Status
    Blocked
    Package
    lodash@4.17.20
    Rule
    CVSS ≥ 7.0
    User
    ci-web (GitHub Actions)
    IP
    10.0.4.17

Every request ends in one of four states

All four are logged with the same detail. Filter the log by status, firewall, phase or user.

Allowed
The package passes every rule and installs as usual.
Blocked
A rule failed. The client gets version not found, and the log shows which rule.
Delayed
The version is newer than the hold window you set. Clients do not see it until it is old enough.
By exception
An admin unblocked this package for a set time. The reason and expiry are logged.

What Dependency Firewall checks

Each firewall runs the checks you turn on, on every request, across all supported ecosystems.

Malware
Blocks packages that match malware data, including malicious payloads and suspicious install hooks.
Vulnerabilities
Blocks CVEs above a CVSS or EPSS score you set. New advisories apply on the next request.
Dependency confusion
On by default. Internal package names always resolve from your private registry.
Licenses
Blocks disallowed licenses before they reach a build.
Release age
Holds newly published versions for a window you set, so malware feeds can catch a bad release first.
Trust downgrades
Flags npm releases published with weaker provenance than the version before them. npm only today.
Container layers
Scans every image layer for malware and secrets, and matches apk, dpkg and rpm packages against advisories.
Your own rules
Block or allow by package name, version range, requester, team or upstream source.

Write your own rules

A rule matches on one or more conditions, then blocks the request or only logs it. Rules stack per firewall and apply on save.

Rules can match on

  • Package name
  • Version range
  • Upstream
  • Internal or external
  • CVSS and EPSS
  • Known malware
  • Package age
  • Provenance downgrade
  • Deprecation
  • Previous observations
  • Secrets

On by default

Dependency confusion protection, and a check for upstreams that disagree about the same package.

Rules as code

Manage rules through the API from GitOps or your automation, and roll back to any earlier configuration.

New rule
CancelCreate
Selector
Applies when (Execution Phase)
Resolving package versions∨

Runs as the client asks which versions exist. Filtered versions are invisible to the client.

Package
*
Version
*
Version Range
>=1.0.0 <2.0.0
Upstream
Any∨
Upstream type
Any∨
Max Age
7 days∨
Analysis
Function
None∨
Effect
Enabled
Block
Log
Description
Delay new releases by 7 days
Summary

While resolving the available versions of any package released within the last 7 days:

Blocks the version and records a log entry.

Also evaluated when a matching version is downloaded directly. The same effect applies to the download.

Dependency Firewall offer

Half the base fee for your first 3 months

€49.50 instead of €99 per month, plus €100 usage credit. Start with a 14-day trial, no card required. See what's new

Works with the repositories you already use

Dependency Firewall acts as a proxy in front of your existing repository. Developers and CI/CD pipelines keep their existing registry URLs and credentials. No migration required.

JFrog Artifactory
Sonatype Nexus
GitLab
GitHub Packages
Azure Artifacts
AWS CodeArtifact

Route one pipeline through the firewall

Start with a single CI job or one developer's npm config. The firewall log shows what was allowed, what was blocked and which rule decided.

Firewall logs: new versions of lerna and nx blocked by a 7-day delay, other npm packages allowed