# Integrations | Chainsaw

> Ready-to-paste snippets for GitHub Actions, GitLab CI, Jenkins, CircleCI, and more. Sixteen package ecosystems, SIEM sinks, and SSO providers in one place.

Source: https://chain305.com/integrations/

---

Integrations

# Wire Chainsaw into your CI and package managers in ten lines

One token and one URL per package manager.

CI providers

## Copy-paste snippets for your pipeline

1.  01 · CI runner
    
    `npm ci`
    
    Credentials from your CI secret store
    
2.  02 · Chainsaw proxy
    
    Policy on every fetch
    
    /chainproxy/repository/@default/npmjs/
    
3.  03 · Audit record
    
    One audit row per fetch
    
    Splunk HEC, Sentinel, QRadar or a webhook (table below)
    

### GitHub Actions

```
- name: Configure Chainsaw
  env:
    CHAINSAW_CLIENT_ID: ${{ secrets.CHAINSAW_CLIENT_ID }}
    CHAINSAW_CLIENT_SECRET: ${{ secrets.CHAINSAW_CLIENT_SECRET }}
  run: |
    echo "registry=https://chain305.com/chainproxy/repository/@default/npmjs/" >> .npmrc
    echo "//chain305.com/chainproxy/repository/@default/npmjs/:_authToken=$CHAINSAW_CLIENT_ID:$CHAINSAW_CLIENT_SECRET" >> .npmrc
    echo "//chain305.com/chainproxy/repository/@default/npmjs/:always-auth=true" >> .npmrc
- name: Install
  run: npm ci
```

GitLab CI

```
install:
  script:
    - echo "registry=https://chain305.com/chainproxy/repository/@default/npmjs/" >> ~/.npmrc
    - echo "//chain305.com/chainproxy/repository/@default/npmjs/:_authToken=$CHAINSAW_CLIENT_ID:$CHAINSAW_CLIENT_SECRET" >> ~/.npmrc
    - echo "//chain305.com/chainproxy/repository/@default/npmjs/:always-auth=true" >> ~/.npmrc
    - npm ci
```

Jenkins

```
withCredentials([usernamePassword(credentialsId: 'chainsaw',
  usernameVariable: 'CHAINSAW_CLIENT_ID', passwordVariable: 'CHAINSAW_CLIENT_SECRET')]) {
  sh '''
    echo "registry=https://chain305.com/chainproxy/repository/@default/npmjs/" > .npmrc
    echo "//chain305.com/chainproxy/repository/@default/npmjs/:_authToken=$CHAINSAW_CLIENT_ID:$CHAINSAW_CLIENT_SECRET" >> .npmrc
    echo "//chain305.com/chainproxy/repository/@default/npmjs/:always-auth=true" >> .npmrc
    npm ci
  '''
}
```

CircleCI

```
- run:
    name: Configure Chainsaw
    command: |
      echo "registry=https://chain305.com/chainproxy/repository/@default/npmjs/" >> ~/.npmrc
      echo "//chain305.com/chainproxy/repository/@default/npmjs/:_authToken=$CHAINSAW_CLIENT_ID:$CHAINSAW_CLIENT_SECRET" >> ~/.npmrc
      echo "//chain305.com/chainproxy/repository/@default/npmjs/:always-auth=true" >> ~/.npmrc
- run: npm ci
```

Azure Pipelines

```
- script: |
    echo "registry=https://chain305.com/chainproxy/repository/@default/npmjs/" >> ~/.npmrc
    echo "//chain305.com/chainproxy/repository/@default/npmjs/:_authToken=$(CHAINSAW_CLIENT_ID):$(CHAINSAW_CLIENT_SECRET)" >> ~/.npmrc
    echo "//chain305.com/chainproxy/repository/@default/npmjs/:always-auth=true" >> ~/.npmrc
    npm ci
  displayName: Install via Chainsaw
```

Buildkite

```
steps:
  - label: "Install"
    command: |
      echo "registry=https://chain305.com/chainproxy/repository/@default/npmjs/" >> .npmrc
      echo "//chain305.com/chainproxy/repository/@default/npmjs/:_authToken=$CHAINSAW_CLIENT_ID:$CHAINSAW_CLIENT_SECRET" >> .npmrc
      echo "//chain305.com/chainproxy/repository/@default/npmjs/:always-auth=true" >> .npmrc
      npm ci
```

Drone CI

```
kind: pipeline
type: docker
name: default

steps:
  - name: install
    image: node:20
    environment:
      CHAINSAW_CLIENT_ID:
        from_secret: chainsaw_client_id
      CHAINSAW_CLIENT_SECRET:
        from_secret: chainsaw_client_secret
    commands:
      - echo "registry=https://chain305.com/chainproxy/repository/@default/npmjs/" >> .npmrc
      - echo "//chain305.com/chainproxy/repository/@default/npmjs/:_authToken=$CHAINSAW_CLIENT_ID:$CHAINSAW_CLIENT_SECRET" >> .npmrc
      - echo "//chain305.com/chainproxy/repository/@default/npmjs/:always-auth=true" >> .npmrc
      - npm ci
```

Swap `@default` for your org slug. The `_authToken` is the plain `id:secret` pair; do not base64-encode it. Self-hosted: use your own base URL, ingress path included. [Full CI/CD guide →](https://docs.chain305.com/tutorials/21-integrate-chainsaw-with-cicd-pipelines/)

Package ecosystems

## Sixteen ecosystems, one proxy

No lockfile changes, no wrapper scripts.

Ecosystem

Covers

Guide

npm

Node.js · npm, pnpm, yarn, bun

[Configure your package manager](https://docs.chain305.com/tutorials/02-configure-package-manager-for-chainsaw/)

PyPI

Python · pip, poetry, uv

Maven

JVM

Gradle

JVM

Cargo

Rust

Go modules

Go

Composer

PHP

NuGet

.NET

RubyGems

Ruby

Swift

iOS / macOS

CocoaPods

iOS / macOS

Docker / OCI

Containers

Hugging Face

AI / ML models

[Secure Hugging Face downloads](https://docs.chain305.com/tutorials/28-secure-ai-ml-model-downloads-huggingface/)

APT

OS packages · CVE + hash-chain provenance only

[OS package provenance](https://docs.chain305.com/tutorials/41-os-package-hash-chain-provenance/)

Yum

OS packages · CVE + hash-chain provenance only

DNF

OS packages · CVE + hash-chain provenance only

Cargo 1.74+: chainsaw cargo-credentials reads the token from the OS keyring.

Outbound destinations

## SIEM and webhook sinks

Splunk HEC

Structured audit events. Enterprise.

Microsoft Sentinel

CEF over TLS syslog. Enterprise.

IBM QRadar

CEF over TLS syslog. Enterprise.

Prometheus / Grafana

50+ metrics at /metrics. All plans.

Slack / MS Teams / PagerDuty

Any webhook receiver. Five per user, every plan.

Generic SIEM

JSON over webhook or syslog.

Identity providers

## SSO and SCIM on Team and up

Okta

SAML 2.0 · OIDC · SCIM 2.0

Microsoft Entra

SAML 2.0 · OIDC · SCIM 2.0

Google Workspace

OIDC · SCIM 2.0

Auth0

OIDC

Keycloak

OIDC

Any SAML 2.0 / OIDC IdP

Compliant providers

Missing an integration you need?

## Tell us what you need to connect

Tell us the CI provider or SIEM you need. We scope it with you and agree a delivery date before we start.

[Talk to sales](https://cal.com/chain305/30min) [Read the CI/CD guide →](https://docs.chain305.com/tutorials/21-integrate-chainsaw-with-cicd-pipelines/)

---

## Long form

The full text behind this page, including detail the page itself leaves out.

Integrations

### Wire Chainsaw into your CI and package managers in ten lines

Chainsaw proxies the registry, so the integration surface is small: one token and one URL per package manager. Below are copy-paste snippets for the CI systems we see most often, and the full list of supported ecosystems, SIEM sinks, and identity providers.

CI providers

#### Copy-paste snippets for your pipeline

Snippets point at managed Chainsaw (`chain305.com/chainproxy`) — on a self-hosted or VPC deployment, swap in your own base URL including its ingress path. Substitute `@default` for your org slug, and store `CHAINSAW_CLIENT_ID` + `CHAINSAW_CLIENT_SECRET` in your CI's secret store. The `_authToken` value is the plaintext pair, colon-separated — do not base64-encode it. Snippets use npm; the same shape works for every package manager Chainsaw supports.

##### GitHub Actions

```
- name: Configure Chainsaw
  env:
    CHAINSAW_CLIENT_ID: ${{ secrets.CHAINSAW_CLIENT_ID }}
    CHAINSAW_CLIENT_SECRET: ${{ secrets.CHAINSAW_CLIENT_SECRET }}
  run: |
    echo "registry=https://chain305.com/chainproxy/repository/@default/npmjs/" >> .npmrc
    echo "//chain305.com/chainproxy/repository/@default/npmjs/:_authToken=$CHAINSAW_CLIENT_ID:$CHAINSAW_CLIENT_SECRET" >> .npmrc
    echo "//chain305.com/chainproxy/repository/@default/npmjs/:always-auth=true" >> .npmrc
- name: Install
  run: npm ci
```

##### GitLab CI

```
install:
  script:
    - echo "registry=https://chain305.com/chainproxy/repository/@default/npmjs/" >> ~/.npmrc
    - echo "//chain305.com/chainproxy/repository/@default/npmjs/:_authToken=$CHAINSAW_CLIENT_ID:$CHAINSAW_CLIENT_SECRET" >> ~/.npmrc
    - echo "//chain305.com/chainproxy/repository/@default/npmjs/:always-auth=true" >> ~/.npmrc
    - npm ci
```

##### Jenkins

```
withCredentials([usernamePassword(credentialsId: 'chainsaw',
  usernameVariable: 'CHAINSAW_CLIENT_ID', passwordVariable: 'CHAINSAW_CLIENT_SECRET')]) {
  sh '''
    echo "registry=https://chain305.com/chainproxy/repository/@default/npmjs/" > .npmrc
    echo "//chain305.com/chainproxy/repository/@default/npmjs/:_authToken=$CHAINSAW_CLIENT_ID:$CHAINSAW_CLIENT_SECRET" >> .npmrc
    echo "//chain305.com/chainproxy/repository/@default/npmjs/:always-auth=true" >> .npmrc
    npm ci
  '''
}
```

##### CircleCI

```
- run:
    name: Configure Chainsaw
    command: |
      echo "registry=https://chain305.com/chainproxy/repository/@default/npmjs/" >> ~/.npmrc
      echo "//chain305.com/chainproxy/repository/@default/npmjs/:_authToken=$CHAINSAW_CLIENT_ID:$CHAINSAW_CLIENT_SECRET" >> ~/.npmrc
      echo "//chain305.com/chainproxy/repository/@default/npmjs/:always-auth=true" >> ~/.npmrc
- run: npm ci
```

##### Azure Pipelines

```
- script: |
    echo "registry=https://chain305.com/chainproxy/repository/@default/npmjs/" >> ~/.npmrc
    echo "//chain305.com/chainproxy/repository/@default/npmjs/:_authToken=$(CHAINSAW_CLIENT_ID):$(CHAINSAW_CLIENT_SECRET)" >> ~/.npmrc
    echo "//chain305.com/chainproxy/repository/@default/npmjs/:always-auth=true" >> ~/.npmrc
    npm ci
  displayName: Install via Chainsaw
```

##### Buildkite

```
steps:
  - label: "Install"
    command: |
      echo "registry=https://chain305.com/chainproxy/repository/@default/npmjs/" >> .npmrc
      echo "//chain305.com/chainproxy/repository/@default/npmjs/:_authToken=$CHAINSAW_CLIENT_ID:$CHAINSAW_CLIENT_SECRET" >> .npmrc
      echo "//chain305.com/chainproxy/repository/@default/npmjs/:always-auth=true" >> .npmrc
      npm ci
```

##### Drone CI

```
kind: pipeline
type: docker
name: default

steps:
  - name: install
    image: node:20
    environment:
      CHAINSAW_CLIENT_ID:
        from_secret: chainsaw_client_id
      CHAINSAW_CLIENT_SECRET:
        from_secret: chainsaw_client_secret
    commands:
      - echo "registry=https://chain305.com/chainproxy/repository/@default/npmjs/" >> .npmrc
      - echo "//chain305.com/chainproxy/repository/@default/npmjs/:_authToken=$CHAINSAW_CLIENT_ID:$CHAINSAW_CLIENT_SECRET" >> .npmrc
      - echo "//chain305.com/chainproxy/repository/@default/npmjs/:always-auth=true" >> .npmrc
      - npm ci
```

Full guide with per-ecosystem variations: [Integrate with CI/CD pipelines →](https://docs.chain305.com/tutorials/21-integrate-chainsaw-with-cicd-pipelines/)

Package ecosystems

#### Sixteen ecosystems, one proxy

Every ecosystem runs transparently — no lockfile changes, no wrapper scripts. The sixteen supported package managers are grouped into the families below (npm/pnpm/yarn/bun share one tile, and so on); links go to the per-ecosystem how-to in the docs.

-   [**npm / pnpm / yarn / bun** Node.js](https://docs.chain305.com/tutorials/02-configure-package-manager-for-chainsaw/)
-   [**pip / poetry / uv** Python](https://docs.chain305.com/tutorials/02-configure-package-manager-for-chainsaw/)
-   [**Maven / Gradle** JVM](https://docs.chain305.com/tutorials/02-configure-package-manager-for-chainsaw/)
-   [**Cargo** Rust](https://docs.chain305.com/tutorials/02-configure-package-manager-for-chainsaw/)
-   [**Go modules** Go](https://docs.chain305.com/tutorials/02-configure-package-manager-for-chainsaw/)
-   [**Composer** PHP](https://docs.chain305.com/tutorials/02-configure-package-manager-for-chainsaw/)
-   [**NuGet** .NET](https://docs.chain305.com/tutorials/02-configure-package-manager-for-chainsaw/)
-   [**RubyGems** Ruby](https://docs.chain305.com/tutorials/02-configure-package-manager-for-chainsaw/)
-   [**Swift / CocoaPods** iOS / macOS](https://docs.chain305.com/tutorials/02-configure-package-manager-for-chainsaw/)
-   [**Docker / OCI** Containers](https://docs.chain305.com/tutorials/02-configure-package-manager-for-chainsaw/)
-   [**Hugging Face** AI / ML models](https://docs.chain305.com/tutorials/28-secure-ai-ml-model-downloads-huggingface/)
-   [**APT / Yum / DNF** OS packages · CVE + hash-chain provenance only](https://docs.chain305.com/tutorials/41-os-package-hash-chain-provenance/)

**Rust note:** Cargo gets a first-class credential-provider on cargo 1.74+ via chainsaw cargo-credentials — tokens are sourced from the OS keyring, so no plaintext lands in .cargo/config.toml.

Outbound destinations

#### SIEM and webhook sinks

Every decision leaves an audit record. Stream the record wherever your on-call, audit, or incident tooling lives.

-   **Splunk HEC** Structured audit events, per-policy routing. Enterprise.
-   **Microsoft Sentinel** CEF over TLS syslog to an AMA / CEF forwarder. Enterprise.
-   **IBM QRadar** CEF over TLS syslog to a QRadar log source. Enterprise.
-   **Prometheus / Grafana** 50+ counters, gauges, and histograms from the /metrics endpoint. All plans.
-   **Slack / MS Teams / PagerDuty** Any webhook receiver. Five webhooks per user on every plan.
-   **Generic SIEM** JSON over webhook or syslog. Pipe into your collector of choice.

Identity providers

#### SSO and SCIM on Team and up

Any SAML 2.0 or OIDC-compliant IdP works. These are the ones we see most often and have explicit setup guides for.

-   **Okta** SAML 2.0 · OIDC · SCIM 2.0
-   **Microsoft Entra** SAML 2.0 · OIDC · SCIM 2.0
-   **Google Workspace** OIDC · SCIM 2.0
-   **Auth0** OIDC
-   **Keycloak** OIDC
-   **Any SAML 2.0 / OIDC IdP** Compliant providers

Missing an integration you need?

#### Tell us what you need to connect

If you need a CI provider we haven't documented or a SIEM we don't support yet, tell us. We scope each request with you and agree a delivery date before we start.

[Talk to sales](https://cal.com/chain305/30min) [Talk to sales](https://cal.com/chain305/30min)
