When something goes wrong
Kill switch for compromised packages
A kill takes a package, some of its versions, one file by its hash, or everything an advisory is recorded against, away from everyone at once. It beats every allow rule, pin, scope and exemption, and audit only mode, until someone lifts it.
Name the package and optionally the versions (3.3.6, >=2.0.0 <2.3.1, or empty for all of them), say why, and press Kill it. Approvers and admins can do it. It works for every package type, images included. Killed versions are left out of the metadata each client reads (npm search and dist-tags too), and a lockfile asking for one gets a 403 carrying your reason, so the developer staring at a failed build knows what happened and which version to move to. The reason reaches the other clients as well: dotnet prints it from the X-NuGet-Warning header, mvn and Gradle show it in their error line, and Bundler prints it from a 451.
- By file hash. Those exact bytes are refused under whatever name and registry they turn up with, including a copy that only arrives later.
- By advisory.
CVE-2021-44228, a GHSA, a PYSEC or aMAL-id from the OpenSSF malicious packages feed. Every version the scan has recorded against it goes, and anything matched later is covered from then on. A newMAL-advisory is put on the kill switch by the vulnerability scan itself, unless you switch that off. - From a CSV. For the day an advisory lists hundreds of packages. Up to 5,000 rows, checked first, nothing killed until you have seen the list.
Admins get an email the moment it happens, listing who pulled the package in the last 30 days, and who pulled it on the page shows version, token, application, environment and address from the traffic log. Also delete the cached copies now removes the files straight away. Lift puts things back to what the rules say, and lifted kills stay listed.
In short
- Package, version range, SHA-256, advisory id, or a CSV of hundreds, for every type
- Beats every allow rule, scope, waiver and audit only mode
- Your reason appears in the npm, pip, dotnet, mvn and Bundler error
- Instant email with who pulled it in the last 30 days
- Kills can never be waived
In the documentation
- The kill switch Administrator Guide
- Scenarios: what happens, and what you do Administrator Guide
Goes well with
- Who has it Search a package, a hash or a CVE and see the applications, environments and pipelines that pulled it.
- Lockdown and degraded modes For the week an ecosystem is on fire. Stop fetching anything new, keep building from what you hold.
- Audit trail Every sign in and every change, with before and after, who, from where, and whether it worked.
One container, about two minutes
A Linux box with Docker, or one without it, and a reverse proxy for TLS. The installer does the rest and it is safe to run twice. Free, MIT licensed, nothing to sign up for.