Features
35 things it does, all in the free version
There is no paid tier to unlock. Grouped by when you need them: keeping bad packages out, the morning something gets through anyway, the developers and approvers who use it every day, and running it.
Keep bad packages out
Allow lists and block lists
Whitelist or blacklist by name, scope, wildcard or version range, for every type. A blocked version is not even listed to the client.
Read moreMalware scanning
ClamAV, a hash blocklist, your own scanner and the OpenSSF known malicious feed, on every cached file. Optionally before the first download.
Read moreTyposquat detection
lodahs, reqeusts, l0dash, python-numpy. Lookalike names are caught and warned about, or refused.
Read moreDependency confusion protection
Reserve your npm scopes, PyPI prefixes, image namespaces and NuGet ids. A public package with your internal name is never fetched.
Read moreCooling off new releases
Brand new versions wait a few days before your builds see them, which is when hijacks get caught.
Read moreSafe version resolution
Versions with serious advisories are left out, so a range quietly settles on the newest safe one.
Read moreLicense policy
Allowed, needs review and blocked SPDX lists, with holds that follow a license change.
Read moreProvenance verification
npm SLSA provenance and PyPI PEP 740 attestations checked against Sigstore, offline, on the box.
Read moreIntegrity alerts and quarantine
A file that changes after it was first seen is held. The original keeps being served.
Read moreWhen something goes wrong
Kill switch
Take a package, a version range, one file hash or a whole advisory away from everyone, at once.
Read moreLockdown and degraded modes
For the week an ecosystem is on fire. Stop fetching anything new, keep building from what you hold.
Read moreWho has it
Search a package, a hash or a CVE and see the applications, environments and pipelines that pulled it.
Read moreVulnerability monitoring
OSV, CISA KEV and FIRST EPSS against everything allowed and cached. npm audit answered locally.
Read moreAudit trail
Every sign in and every change, with before and after, who, from where, and whether it worked.
Read moreDevelopers and approvals
Requests and auto approve
A blocked install opens a request. Clean ones can approve themselves, risky ones wait for a person.
Read moreCheck, walk and review
See what the rules say before you install. Walk a dependency tree. Review a lockfile or an SBOM.
Read moreWaivers
A written down, time boxed yes for one finding on one package, scoped to an app or environment.
Read moreDry run
Replay up to 90 days of real downloads against a rule before anybody switches it on.
Read moreTokens, apps and environments
Every download is tied to a token, an application and an environment. Rules can be scoped to them.
Read moreFormats and running it
Private npm registry
npm, pnpm, Yarn and Bun. Publish your own packages under reserved names, mirror the rest.
Read morePyPI proxy and private index
pip, uv and Poetry. PEP 503, 691, 658 and 700, and twine uploads for your own projects.
Read moreDocker registry mirror
Pull through Docker Hub, GHCR, Quay or Harbor, and push your own images to reserved namespaces. Everything by digest, the layers scanned.
Read morePrivate NuGet feed and proxy
dotnet and Visual Studio through nuget.org or a private feed, and dotnet nuget push for your own ids.
Read moreMaven repository proxy
mvn, Gradle and sbt through Maven Central, Nexus or Artifactory. Every file checked against its .sha1.
Read moreRubyGems mirror
Bundler and gem install through the compact index, with every .gem checked against its sha256.
Read moreComposer and Packagist proxy
Composer through Packagist. Each release is fetched once from its exact commit, scanned and kept.
Read moreCocoaPods CDN mirror
pod install through a CDN that lists only allowed pods, with their code fetched, checked and scanned here.
Read moreSwift package registry
SwiftPM through an SE-0292 registry that serves GitHub tags as releases, each archive scanned and kept.
Read moreRPM mirror for dnf and yum
AlmaLinux, Rocky Linux and Red Hat repositories, every package checked and scanned before dnf gets it.
Read moreAPT mirror for Debian and Ubuntu
Debian and Ubuntu archives for apt, every .deb checked and scanned, with an optional filtered index.
Read moreArtifacts, SBOMs and lifecycle
Every file stored once by SHA-256, CycloneDX and SPDX out, properties and promotion stages.
Read moreS3 and Azure storage
Keep the cache in a bucket. Every upload checked by hash, and a local copy cap on the disk.
Read moreSSO, roles and allow lists
OpenID Connect, five roles checked on every request, IP allow lists and break glass keys.
Read moreSIEM and email
Signed webhooks, Splunk HEC and syslog in JSON or CEF. Digests instead of a mail per event.
Read moreMore than one node
Point two nodes at one MariaDB, RDS included, and put a load balancer in front.
Read moreAnd the plumbing
The small things that make it pleasant
- Every refusal in the traffic log has a why link that explains it in one place: the rule or check, the evidence, and what to do next.
- Import and export of rules as JSON or CSV with no limit, in one transaction, with a try it first button.
- Cache housekeeping that catches the database and the disk drifting apart, and puts things back.
- Your own name, header icon and favicon in the portal.
- Documentation built into the portal for each role, with your address in every example and a PDF of it.
- Stale metadata served when npm or PyPI is down, for as long as you say.
- Upgrades with one command that tag the running image first, so a bad one goes back in one more.
One container, about two minutes
A Linux box with Docker, or one without it, and a reverse proxy for TLS. The installer does the rest and it is safe to run twice. Free, MIT licensed, nothing to sign up for.