Artifact managers host. Chainsaw decides.
A mirror serves a malicious package as faithfully as a good one. Chainsaw refuses it at install.
Cloudsmith, JFrog, Nexus, Verdaccio host packages and stop there.
Chainsaw hosts your internal artifacts and enforces install-time policy on every install routed through it.
The request path
Same URL. A decision on every install.
A registry serves whatever is published. Chainsaw decides first, then serves.
-
01 · Developer or CI
npm installone registry URL swap per package manager
-
02 · Chainsaw, on the install path
- public registries, proxied
- internal artifacts, same URL
- your policy, on every request
alongside your existing registry, or replacing it
-
Refused
never enters the build
Allowed
served, and cached
Feature matrix
What each layer actually does
| Capability | Artifact manager Cloudsmith · JFrog · Nexus · Verdaccio | Chainsaw Install-time policy proxy |
|---|---|---|
| Hosts internal artifacts | Yes | Yes |
| Mirrors / caches public packages Hosted publish + pass-through cache on the same URL. | Yes | Yes |
| Pass/fail policy decision on every install Via paid add-ons (Nexus Firewall, JFrog Curation); not in the base registry. | Partial | Yes |
| Monitoring-first rollout Same add-ons; not in the base registry. | Partial | Yes |
| Zero-migration deploy Adopt without moving artifacts into a new registry. | No | Yes |
| Works with npm, PyPI, Maven, Docker | Yes | Yes |
| Refuse the version the moment a CVE lands Org-wide, no upgrade PRs. | Partial | Yes |
| On-prem / air-gapped | Partial | Yes |
Already running an artifact manager?
Keep your registry. Put Chainsaw in front of the public-registry traffic.
Migrate your internal artifacts later if you want: same URL, no separate publish workflow.