Quickstart

Your first block, the first time you run install

Three commands, about a minute. No account, no server, no registry repoint.

  1. 01

    Install the CLI

    curl -fsSL https://chain305.com/install.sh | bash

    One binary in ~/.local/bin, no sudo. Windows: irm https://chain305.com/install.ps1 | iex

  2. 02

    Turn on the guard

    chainsaw guard init --install

    The installer already did this for you, on macOS, Linux and Windows (it prints a Guard: line); run it only if that line says it was skipped. Hooks npm, pip, cargo, gem and go in your shell rc. Current shell only: eval "$(chainsaw guard init zsh)"

  3. 03

    Watch it block

    npm install crossenv

    A typosquat of cross-env. Works with the network off.

What you'll see · real output

chainsaw  offline known-malicious + typosquat active (231875 malicious packages indexed)
chainsaw  ✗ blocked  npm:crossenv — looks like a typosquat of "cross-env" (distance 1, edit-distance, target rank #1931)
chainsaw  ✗ refused at the install path — nothing was installed

Also try: pip install python3-dateutil · cargo add rustdecimal · gem install rest-clientt · go get github.com/sirupsen/logruss

First run asks once before sharing anonymous usage (defaults to yes, never from CI). Change it with chainsaw telemetry on|off. Privacy policy

Scale this to a team

Same block, enforced for everyone

Run Chainsaw as a proxy in front of your registries: shared policy, an audit trail, and blocks that hold on machines without the CLI.

  1. 01

    Sign up

    Free tier, no credit card.

    Start free →
  2. 02

    Create a client credential

    Access → Client credentials. The secret is shown once.

    Open client credentials →
  3. 03

    Point npm at Chainsaw

    npm config set registry https://CLIENT_ID:CLIENT_SECRET@chain305.com/chainproxy/repository/@default/npmjs/
    pip or Docker instead

    pip / PyPI

    pip config set global.index-url https://CLIENT_ID:CLIENT_SECRET@chain305.com/chainproxy/repository/@default/pypi/simple
    pip config set global.trusted-host chain305.com

    Two lines. pip needs trusted-host once credentials are embedded in the URL.

    Docker

    docker login chain305.com

    Username: your CLIENT_ID. Password: your CLIENT_SECRET.

  4. 04

    Run the demo install

    npm install lodahs

    Refused by the seeded demo policy.

Next: see the block in your dashboard · 16 package managers · book a 30-minute walkthrough