Dependency Firewall offer: 50% off your base fee for 3 months + €100 usage credit.Start trialSee what’s new

Dependency Confusion Prevention

Internal package names resolve from your private registry, every time. Dependency Firewall checks upstreams in the order you set, so a public package with the same name and a higher version number is blocked.

A request for an internal package. The private copy is served and the public copy with a higher version is blocked.

Public registries accept any unclaimed name

If an internal package name is free on the public registry, anyone can publish it there. A client that looks in both places can pick the public copy because its version number is higher.

Internal names are easy to find
Lockfiles, error messages and published front-end bundles contain the names of internal packages.
Mixed sources resolve by version number
pip with --extra-index-url, and virtual repositories that merge public and private sources, take the highest version they find.
Every project has its own config
Each .npmrc and pip.conf has to be right. One wrong file is enough.

How it works with Dependency Firewall

  1. 1Add your private registry as an upstream

    Artifactory, Nexus, GitLab, GitHub Packages or Azure Artifacts, next to the public registry.

  2. 2Set the priority

    Internal names and namespaces resolve from the private upstream. Public copies of those names are blocked.

  3. 3Developers change nothing

    Package names in manifests stay the same. The firewall decides where each one comes from.

One registry URL for both sources

Developers and pipelines point at the firewall only. It fetches internal packages from your private registry and everything else from the public one, so no project lists two sources.

runner image setup
# npm, Yarn and pnpm
npm config set registry https://registry.bytesafe.dev/r/<firewall-id>/
 
# pip
pip config set global.index-url https://registry.bytesafe.dev/pypi/<firewall-id>/simple/
 
# Go modules
export GOPROXY=https://registry.bytesafe.dev/go/<firewall-id>/,direct
The only client setting. Upstream order lives on the firewall.

Who works with it

Security teams
Set the upstream priority once. Every install through the firewall follows it.
Developers
Internal packages install as before, with no per-project configuration.
Platform engineers
Retire the extra-index and scope settings spread across repositories.

Questions

Do developers need to change how they reference internal packages?

No. Package names stay the same. The firewall handles where they resolve from.

Does this work with scoped npm packages?

Yes. Rules can match a namespace or scope as well as a single package name.

Which ecosystems are covered?

Every supported package ecosystem, including npm, PyPI, Maven, NuGet, Go, Cargo, RubyGems and Composer.

Try it on one registry

Point one package manager at Dependency Firewall and check the log after the next install. The trial runs 14 days.

Firewall logs: new versions of lerna and nx blocked by a 7-day delay, other npm packages allowed