Install-path firewall · open source

Block malicious packages before they download.

$ curl -fsSL https://chain305.com/install.sh | bash

Installs the CLI and turns the guard on · no account · works offline · what it sends

Real refusal, real product · captions available

How the local guard works

One shell hook. Every decision on your machine.

  1. 01 · You, or your coding agent

    npm install crossenv

    npm, pip, cargo, gem, go

  2. 02 · chainsaw guard, on this machine

    • typosquat distance
    • known-malicious index
    • package bytes, when on disk

    shell hook · no daemon · works offline

  3. Refused

    typosquat of "cross-env" · nothing downloaded

    Allowed

    fetched from the registry as usual

Real output · reproduce it offline in 30s
$ npm install crossenv
chainsaw  offline known-malicious + typosquat active (231875 malicious packages indexed)
chainsaw  ✗ blocked  npm:crossenv — looks like a typosquat of "cross-env" (distance 1, edit-distance, target rank #1931)
chainsaw  ✗ refused at the install path — nothing was installed
  • No daemon. A shell hook for npm, pip, cargo, gem and go.
  • Works offline. Malicious and typosquat seeds ship inside the binary.
  • Readable. The engine is open source at github.com/chain305/chainsaw-core.

How it fires

One signed Rego policy. Five surfaces.

The pull request, the install path, publish, Kubernetes admission and your laptop read the same rule. The PR check sees only the manifest diff, so byte-level rules wait for the install.

Policy

One signed Rego policy bundle

The same rule at every surface below.

  1. 01 · Pull request

    GitHub Action / chainsaw pr-scan

    Fails the check on the dependency diff. Coordinate only: CVSS and malware rules apply from install on.

  2. 02 · Install path

    npm / PyPI / Maven / NuGet / Docker + 12 more

    Refuses the fetch, with the reason and the exception path.

  3. 03 · Publish

    Hosted repo upload

    Refuses an upload from your own build that fails policy.

  4. 04 · K8s admission

    Validating webhook

    Refuses the pod when the image fails the same Rego.

  5. 05 · Laptop

    Local guard install hook / MDM

    Refuses on the developer's machine, even where the proxy was bypassed.

Evidence

One signed audit row

carries every refusal, wherever it happened.

Who it's for

Same guard. Four jobs.

Developers

Typosquats and malicious updates are refused before they touch your disk.

  • “Builds get slower.” Repeat installs serve from Chainsaw's cache. CI usually gets faster.
  • “I can't debug a block.” The error names the rule, the reason and the exception reviewer.
  • “A new rule breaks me.” Ask for new rules in monitor first. The audit log records what would have been blocked.
See how →

AppSec

A CVE drops, you push one policy edit, and that version stops installing everywhere.

  • Refuse bad packages on the install path. Vulnerability, license and version rules plus 25 supply-chain signals beyond CVE run before a package enters a build. Depth varies by ecosystem.
  • Cut the exposure window. One policy edit rolls out in minutes, with no upgrade PR needed to halt new spread.
  • Give devs a useful error. The refusal names the rule, the reason and who owns the exception path.
See how →

DevSecOps

The same license, version and provenance rules in CI, on laptops and in Dockerfiles.

  • Model your policy once. License, version and provenance rules. One policy for CI, laptops and Dockerfiles.
  • Watch monitor-mode traffic. Every install gets a verdict in the audit log. Nothing breaks.
  • Export evidence on demand. CycloneDX SBOMs per repo. Audit logs stream to Splunk HEC, Microsoft Sentinel or IBM QRadar on Enterprise.
See how →

Enterprise IT

One baseline for every org, on SaaS, in your VPC or air-gapped. Same binary.

  • Stand up one instance. Managed SaaS, your cloud or air-gapped. Same binary, same API.
  • Publish the policy centrally. One org-wide policy for vulnerabilities, licenses, provenance and supply-chain signals.
  • Scope rules by repository. Target a rule at specific repositories. Exceptions carry an expiry and optional two-person approval.
See how →

Run it for the org

Policy at the registry, even on laptops without the CLI.

Put the proxy between your developers and the upstream registries. One signed policy, and one signed audit row for every decision.

Surface Ecosystems Reaches
Local guard free 5 npm, pip, cargo, gem, go the machine it is installed on
Registry proxy 16 the five above plus Maven, Composer, NuGet, Hugging Face, CocoaPods, Swift, pub, Docker, APT, yum, DNF every machine that installs through it, CLI or not
Chainsaw report showing policy violations grouped by owning team.
Report Refusals grouped by the team that owns the repository. Demo org seeded with synthetic install traffic.

Runs as managed SaaS, in your VPC (your Postgres, blob store and audit logs; no inbound connection from us) or air-gapped with CHAINSAW_OFFLINE=1, sideloading intelligence on your own cadence. SSO and SCIM are on Team; SIEM export and on-prem are Enterprise; the audit trail ships on every plan. Deployment models → Procurement kit →

Compared to the alternatives

More than a registry. Not a scanner.

Registries store packages and scanners report on them. Neither decides on the install path.

More than a registry

vs Cloudsmith · JFrog · Nexus · Verdaccio

  • Sits in front of the registry you already have. Nothing to migrate.
  • Refuses on the install path. A cache does not decide what is safe.
Read the full diff →

Not a scanner

vs Snyk · Sonatype · Mend

  • Refuses before bytes land, not in a PR comment after the fact.
  • Enforced org-wide, not an opt-in CLI per developer.
Read the full diff →

Objections, handled

Common questions

Do I need an account?

No. The guard runs with no account and no server. Sign in only to share one policy across a team.

Is it actually free?

Yes. The local guard and all 25 detection signals are free. The guard runs the checks that need no network; the rest run on the hosted proxy, also free. Paid plans add the team control plane: shared policy, dashboards, SSO and SIEM.

Will it break my installs or CI?

Start in monitor mode. Every rule logs what it would have blocked before you switch it to enforce.

What happens if Chainsaw goes down?

Degraded data fails open by default, and the gap is written to the audit trail. Set CHAINSAW_COVERAGE_MODE=closed and name the sources you treat as mandatory, and it refuses anything it could not check against them.

Two commands, local, free

Run it, then try to break it

No account needed. Paste two lines, then try npm install crossenv.