How it works

Chainsaw is a firewall for your package installs.

Every npm install, pip install and docker pull meets a policy engine on its way to your machine.

  1. 01 · Your package manager

    npm install <pkg>

    registry URL points at Chainsaw

  2. 02 · Chainsaw proxy

    • CVE, CVSS, EPSS, KEV
    • license and version rules
    • provenance
    • supply-chain signals

    before any bytes reach the client

  3. Refused

    the error names the rule that fired

    Allowed

    streamed through the content-addressed cache

Unchanged: npm install, lockfiles, CI jobs, IDE tooling and registry auth.

Why this exists

Supply-chain attacks don't look like CVEs.

event-stream, xz-utils and tj-actions/changed-files reached developer machines before any scanner had a CVE to match.

01

Setup · one-time

Point one URL at Chainsaw

~/.npmrc
registry=https://registry.npmjs.org/
registry=https://CLIENT_ID:CLIENT_SECRET@chain305.com/chainproxy/repository/@default/npmjs/

One URL per ecosystem, no SDK or CI plugin. Per-ecosystem guides →

02

Every install · runtime

Rules run in parallel, then allow or refuse

Rule evaluation takes low single-digit milliseconds.

Supply-chain signals, by ecosystem
Install-script exfiltrationnpm / pip / rubygems / cargo / composer
Maintainer-account takeovernpm / pip / rubygems / nuget / maven / gradle
Publish-velocity burstsnpm / pip / rubygems / nuget
Hidden characters in packagesource-archive ecosystems
Typosquat across 15 ecosystemsnot APT / Yum / DNF
Version anomaliesevery SemVer ecosystem
Reserved-namespace dependency confusionuniversal
Container-image malware feedDocker
Per-layer image enforcementDocker
OS-package hash-chain provenanceAPT / Yum / DNF
Repo liveness + ownership matchtrust-score input
Checksum fail-closed enforcementnpm / pip / rubygems / composer / maven / gradle / nuget / cargo
03

Rollout · ongoing

Monitor first, enforce when ready

policy.yaml
name: "Block critical vulnerabilities"
mode: "monitor"  # week 1–2: just record what would fire
mode: "block"    # week 3+: block the install
conditions:
  cvssMin: 9.0
  epssMin: 0.5

Flip per rule, per repo or per team. Every decision is logged.

Where every decision lands

Every allow and refusal rolls up to Overview.

Chainsaw Overview dashboard showing blocked, allowed, and flagged install counts as sparklines, supply-chain firewall posture, and a patch-priority queue.
Overview Block, allow and flag counts, posture and the patch-priority queue. Demo org, 30 days of synthetic install traffic.

When things go wrong

By default, your builds don't break.

What failsWhat happens
Threat-intel feed or database degradedFails open and writes the gap to the audit trail. Set CHAINSAW_COVERAGE_MODE=closed and name your mandatory sources to refuse anything they could not check.
The proxy process is downRun it HA. That is a deployment question, not a policy one.
Upstream registry is downThe cache serves previously allowed versions. New ones fail with the upstream's own error.
A rule is too aggressiveOne-click exception with a reviewer, a reason and an expiry.
Read the getting-started guides →

Ready to roll out?

Put Chainsaw on the install path

Start free in monitor mode. See what would be refused, then flip to enforce when you've seen the data.