registry=https://chain305.com/chainproxy/repository/@default/npmjs/
//chain305.com/chainproxy/repository/@default/npmjs/:_authToken=${CHAINSAW_TOKEN}
always-auth=true For developers
Your .npmrc picks up a token. The rest of your day doesn't change.
Chainsaw is a registry proxy, not a plugin and not an agent. A pass looks no different. A block tells you which rule fired and who can unblock it.
What you'll see
Same install command, one new check
-
01 · You, or CI
npm installpip, Maven, Cargo, Go, Docker: unchanged
-
02 · Chainsaw proxy
- vulnerability rules
- license and version rules
- typosquat and attack signals
-
Blocked
the error names the rule and who can unblock it
Allowed
repeat installs serve from cache
Common worries
What's actually true
| Worry | What's true |
|---|---|
| Builds get slower | Repeat installs serve from Chainsaw's cache. CI usually gets faster. |
| I can't debug a block | The error names the rule, the reason and the exception reviewer. |
| Workspaces break | It proxies the registry, so pnpm, Yarn, Nx and Turborepo work unchanged. Lockfiles stay the same. |
| A new rule breaks me | Ask for new rules in monitor first. The audit log records what would have been blocked. |
| Setup eats a day | One client credential per machine. chainsaw install-hook writes it for you. |
| My agent picks packages | It can ask Chainsaw's MCP server first, with only the scope an admin grants it. |
Agent setup: /for-agents/
Config
Point your package manager at Chainsaw
Paste one into your config, or let chainsaw install-hook write it.
pip.conf
[global]
index-url = https://${CHAINSAW_TOKEN}@chain305.com/chainproxy/repository/@default/pypi/simple/
trusted-host = chain305.com ~/.m2/settings.xml
<mirrors>
<mirror>
<id>chainsaw</id>
<url>https://chain305.com/chainproxy/repository/@default/maven-central/</url>
<mirrorOf>*</mirrorOf>
</mirror>
</mirrors> ~/.docker/config.json
{
"auths": {
"chain305.com": {
"auth": "${BASE64_TOKEN}"
}
}
} .cargo/config.toml
[source.crates-io]
replace-with = "chainsaw"
[source.chainsaw]
registry = "https://chain305.com/chainproxy/repository/@default/crates-io/"
token = "${CHAINSAW_TOKEN}" Go GOPROXY
export GOPROXY=https://${CHAINSAW_TOKEN}@chain305.com/chainproxy/repository/@default/gomod/,direct
export GOSUMDB=off Evaluating for your team?
Free plan is permanent; ten minutes to wire one repo
Point one .npmrc at Chainsaw, install a package on a CVE list, and read the error yourself.