More than a registry
vs Cloudsmith · JFrog · Nexus · Verdaccio
- Sits in front of the registry you already have. Nothing to migrate.
- Refuses on the install path. A cache does not decide what is safe.
Install-path firewall · open source
Installs the CLI and turns the guard on · no account · works offline · what it sends
Named incidents
How the local guard works
01 · You, or your coding agent
npm install crossenv npm, pip, cargo, gem, go
02 · chainsaw guard, on this machine
shell hook · no daemon · works offline
Refused
typosquat of "cross-env" · nothing downloaded
Allowed
fetched from the registry as usual
$ npm install crossenv
chainsaw ✗ blocked npm:crossenv — looks like a typosquat of "cross-env" (distance 1, edit-distance, target rank #1931)
chainsaw ✗ refused at the install path — nothing was installed How it fires
The pull request, the install path, publish, Kubernetes admission and your laptop read the same rule. The PR check sees only the manifest diff, so byte-level rules wait for the install.
Policy
One signed Rego policy bundle
The same rule at every surface below.
01 · Pull request
GitHub Action / chainsaw pr-scan
Fails the check on the dependency diff. Coordinate only: CVSS and malware rules apply from install on.
02 · Install path
npm / PyPI / Maven / NuGet / Docker + 12 more
Refuses the fetch, with the reason and the exception path.
03 · Publish
Hosted repo upload
Refuses an upload from your own build that fails policy.
04 · K8s admission
Validating webhook
Refuses the pod when the image fails the same Rego.
05 · Laptop
Local guard install hook / MDM
Refuses on the developer's machine, even where the proxy was bypassed.
Evidence
One signed audit row
carries every refusal, wherever it happened.
Who it's for
Typosquats and malicious updates are refused before they touch your disk.
A CVE drops, you push one policy edit, and that version stops installing everywhere.
The same license, version and provenance rules in CI, on laptops and in Dockerfiles.
One baseline for every org, on SaaS, in your VPC or air-gapped. Same binary.
Run it for the org
Put the proxy between your developers and the upstream registries. One signed policy, and one signed audit row for every decision.
| Surface | Ecosystems | Reaches |
|---|---|---|
| Local guard free | 5 npm, pip, cargo, gem, go | the machine it is installed on |
| Registry proxy | 16 the five above plus Maven, Composer, NuGet, Hugging Face, CocoaPods, Swift, pub, Docker, APT, yum, DNF | every machine that installs through it, CLI or not |
Runs as managed SaaS, in your VPC (your Postgres, blob store and audit logs; no inbound
connection from us) or air-gapped with CHAINSAW_OFFLINE=1, sideloading intelligence
on your own cadence. SSO and SCIM are on Team; SIEM export and on-prem are Enterprise; the
audit trail ships on every plan.
Deployment models → Procurement kit →
Compared to the alternatives
Registries store packages and scanners report on them. Neither decides on the install path.
More than a registry
vs Cloudsmith · JFrog · Nexus · Verdaccio
Not a scanner
vs Snyk · Sonatype · Mend
Objections, handled
No. The guard runs with no account and no server. Sign in only to share one policy across a team.
Yes. The local guard and all 25 detection signals are free. The guard runs the checks that need no network; the rest run on the hosted proxy, also free. Paid plans add the team control plane: shared policy, dashboards, SSO and SIEM.
Start in monitor mode. Every rule logs what it would have blocked before you switch it to enforce.
Degraded data fails open by default, and the gap is written to the audit trail. Set CHAINSAW_COVERAGE_MODE=closed and name the sources you treat as mandatory, and it refuses anything it could not check against them.
Two commands, local, free
No account needed. Paste two lines, then try npm install crossenv.