Refuse bad packages on the install path
Vulnerability, license and version rules plus 25 supply-chain signals beyond CVE run before a package enters a build. Depth varies by ecosystem.
For AppSec
Push one policy edit and the affected version stops installing in every repo, CI job and laptop. A scanner finds log4j after it's in six services; Chainsaw refuses it on the seventh.
The pain
What changes
Vulnerability, license and version rules plus 25 supply-chain signals beyond CVE run before a package enters a build. Depth varies by ecosystem.
One policy edit rolls out in minutes, with no upgrade PR needed to halt new spread.
The refusal names the rule, the reason and who owns the exception path.
Zero-disruption rollout
01
Point package managers at Chainsaw
One registry line per package manager. No build-script changes, no laptop agent.
02
Start in monitor mode
See what your rules would have blocked across every repo, with no build broken.
03
Flip to enforcement
Per-policy toggle. Enforce the rules you trust; keep the rest in monitor.
Ready to cut the exposure window?
See what Chainsaw would have blocked before you enforce anything.