Incident response
The kill switch
Stop a malicious package everywhere at once and find everyone who has it.
12
- What to kill: a package, one file by sha256, or an advisory
- Everyone who downloaded it in the last 30 days
| Kill | Stops |
|---|---|
| A package | Every version, or a range, tag or digest you name. Exact names only. |
| One file, by its sha256 | That exact file under any name, including copies that turn up later. |
| An advisory | Every version the vulnerability scan has recorded against a CVE, GHSA or PYSEC id. |
Hundreds at once, from a CSV
When an advisory lists a whole campaign, admins can use Kill from a CSV. One row per package: package, version, type. Type is npm, pypi (or python) or oci (or docker). An empty version kills every version.
campaign.csv
package,version,type
event-stream,3.3.6,npm
ua-parser-js,0.7.29 || 0.8.0 || 1.0.0,npm
requests,==2.31.0,pypi
library/nginx,1.25.3,docker
flatmap-stream,,npm
- Pick the file or paste the rows, and write the reason.
- Click Check the file. The list shows every package, which are already killed, and each row that cannot be read with its line number. Nothing is killed yet.
- Click Kill N package(s) and confirm. Rows for the same package become one kill. Admins get one email with the list, and each kill is in the audit trail.
- Open Kill switch and fill in Kill something. The reason is shown to every developer who is refused, so say what to use instead.
- Tick Also delete the cached copies now if the files must not stay on disk.
- Click Kill it. It takes effect within seconds, beats every allow rule, scope and waiver, and works in audit mode.
- Use who pulled it for the last 30 days of downloads by token, application, environment and address. Admins and approvers also get this by email.
- Use Consumers for the longer history and a per application SBOM.
- When it is safe, lift the kill with a note.