# Pinning, cooldowns, blocklists, SCA — where Chainsaw fits | Chainsaw

> The four common ways teams keep a bad package out of a build — conceded fairly — and where Chainsaw sits behind them. Written to survive a skeptical reader.

Source: https://chain305.com/comparison/

---

Where Chainsaw fits

# Pinning, cooldowns, blocklists, SCA. Chainsaw sits behind them.

They solve different parts of the problem, and most of them stack.

Approach

When it acts

What it's good at

Where it stops

Lockfile pinning

At resolve

Reproducible builds, no surprise upgrades.

A later compromised version still gets pulled once you bump it. Doesn't judge intent.

Dependency cooldown pnpm minimumReleaseAge

At resolve

Cheap, free, catches fast-reverted compromises.

Probabilistic: relies on someone else getting burned first. No org-wide enforcement. A Shai-Hulud-style worm spreads through trusted maintainers and packages that already passed the window.

Malicious-package blocklist Safe Chain, etc.

At install

Blocks known-bad against a feed, free.

Only as good as the feed's coverage. A blocklist isn't a policy you can shape per team.

SCA scanner Snyk · Sonatype · Mend

After install

Inventory, CVE matching, license checks.

Reports after the install script already ran. CVE-centric.

Chainsaw — free CLI

At install, offline

Blocks known-malicious + typosquats for npm/PyPI/Go/Rust/Ruby, same engine each. No account.

No deep install-script behavioral analysis on the laptop — that's the proxy.

Chainsaw — proxy

At install, on the path

25 signals beyond CVE. Monitor mode. Enforcement across CI, endpoint, network.

npm and PyPI have full behavioral parity. Some signals thin or absent on registries without per-version publisher metadata.

Measured, one run

## Numbers we can reproduce

An earlier 0.00% didn't reproduce, so it was re-measured. The verdict that refuses an install, one run:

Real malware hard-blocked

Top packages false-blocked

**43.7%** · 104 of 238

**0.47%** · 4 of 860

One 1,098-package corpus, own-bytes only, before the 231k-entry known-malicious feed floor. The corpus builder and harness are in the repo.

The four false blocks

Each is an indicator in genuine shipping code: `tqdm`'s Telegram progress-bar backend, `ipython`'s `%dpaste` magic, `huggingface-hub`'s documented webhook endpoint, and `browser-use`, which reads browser credential-store paths as its entire purpose.

The looser "a signal fired" measure (dated)

It surfaces, it doesn't block: 69% of real malware at a 5% signal rate on benign packages. Measured on a superseded 597-sample corpus and not re-run, so it is never quoted beside 0.47%. Both cells of one row, never one cell from each.

No product pitch — just the teardowns

## A teardown of each notable package attack

What happened, what stopped it, and where Chainsaw would and wouldn't have caught it.

[Get the teardowns](https://chain305.com/teardowns/) [Try the free CLI →](https://chain305.com/cli-download/)

---

## Long form

The full text behind this page, including detail the page itself leaves out.

Where Chainsaw fits

### Pinning, cooldowns, blocklists, SCA. Chainsaw sits behind them.

Four common ways teams try to keep a bad package out of a build. They solve different parts of the problem, and most of them stack.

This page concedes what the alternatives do well before saying where they stop. The honest version is more convincing than the flattering one — the audience already knows the alternatives, and will trust us more for being fair about them.

Approach

When it acts

What it's good at

Where it stops

Lockfile pinning

At resolve

Reproducible builds, no surprise upgrades.

A pinned package that later gets a compromised version still gets pulled once you bump it. Doesn't judge intent.

Dependency cooldown pnpm minimumReleaseAge

At resolve

Cheap, free, catches fast-reverted compromises.

Probabilistic — relies on someone else getting burned first. No org-wide enforcement. Misses a cooled-then-compromised trusted maintainer.

Malicious-package blocklist Safe Chain, etc.

At install

Blocks known-bad against a feed, free.

Only as good as the feed's coverage. A blocklist isn't a policy you can shape per team.

SCA scanner Snyk · Sonatype · Mend

After install

Inventory, CVE matching, license checks.

Reports after the install script already ran. CVE-centric, weaker on behavioral supply-chain signals. Alert volume.

Chainsaw — free CLI

At install, offline

Blocks known-malicious + typosquats for npm/PyPI/Go/Rust/Ruby, same engine each. No account.

No deep install-script behavioral analysis on the laptop — that's the proxy.

Chainsaw — proxy

At install, on the path

25 signals beyond CVE: install-script exfiltration, maintainer takeover, publish-velocity. Monitor mode. Enforcement across CI, endpoint, network.

npm and PyPI have full behavioral parity. Some signals thin or absent on registries without per-version publisher metadata.

#### Before you assume it's "another SCA tool"

It isn't, and the difference is timing. A scanner looks at what you already installed. Chainsaw decides whether the install happens. An install script that steals your env vars runs the moment the package lands — before any scanner reads it. That's the whole reason the category exists.

So the honest framing: SCA reports, Chainsaw refuses, and most teams should run both. We're not trying to replace your scanner's inventory or its CVE feed. [The full SCA head-to-head is here.](https://chain305.com/vs-sca/)

#### On cooldowns, since it's the first thing people say

Cooldowns are good. We mean that. A one-day or seven-day delay on new versions dodges a lot of smash-and-grab compromises that get yanked within hours. Two things a cooldown doesn't give you:

1.  **Enforcement.** A cooldown is a setting each developer can have or not have. Chainsaw is a policy the org applies at the proxy, so CI and laptops follow the same rules — and you can prove it.
2.  **Coverage of the slow attack.** A Shai-Hulud-style worm spreads through maintainers you already trust and packages that already passed their cooldown window. A delay doesn't see that. Behavioral signals do.

Keep your cooldown. Chainsaw sits behind it and catches the cases it can't.

#### What we will not claim

-   We won't pretend the free CLI does behavioral install-script analysis. It does typosquat and known-malicious blocking offline; the behavioral signals live in the proxy. We'll tell you which tier you're getting.
-   We won't claim "zero false positives" — we used to publish 0.00%, it didn't reproduce, and we re-measured rather than leave it up. What we'll show is a scoped, reproducible pair, both halves from the same run over one 1,098-package corpus (238 real malicious samples, 860 real top packages), and both **own-bytes only — before the 231k-entry known-malicious feed floor**, which is what actually stops an install of a package already named as malware:
    
    -   The verdict that **refuses** an install hard-blocks **43.7% of real malware at a 0.47% false-block rate** — 104 of 238 samples, 4 of 860 top packages. We can name all four, and every one is an indicator sitting in genuine shipping code: `tqdm`'s Telegram progress-bar backend, `ipython`'s `%dpaste` magic, `huggingface-hub`'s documented webhook endpoint, and `browser-use`, which reads browser credential-store paths as its entire purpose.
    -   The looser "a signal fired" measure — which surfaces, it doesn't block — reached **69% of real malware at a 5% signal rate on benign packages**. Treat that pair as **dated**: it was measured on a superseded 597-sample corpus and has not been re-run, so we don't quote it beside 0.47%. We quote both cells of whichever row we're in, never one cell from each.
    
    The corpus builder and the harness are in the repo, so you can rebuild both and check us — the four names above come out of the harness, not out of a marketing doc. A reproducible 0.47% beats an unreproducible zero, and it's now a CI budget rather than a claim. Better still, monitor mode shows the number on _your_ dependencies before you enforce anything.
-   We won't use a customer logo until a customer says yes.

If any of that changes, this page changes with it.

No product pitch — just the teardowns

#### We publish a short teardown of notable supply-chain incidents, about once a month

What happened, what actually stopped it, where Chainsaw would and wouldn't have caught it. If that's useful, the list is here.

[Get the teardowns](https://chain305.com/teardowns/) [Try the free CLI →](https://chain305.com/cli-download/)
