Artifact managers host. Chainsaw decides.

A mirror serves a malicious package as faithfully as a good one. Chainsaw refuses it at install.

Cloudsmith, JFrog, Nexus, Verdaccio host packages and stop there.

Chainsaw hosts your internal artifacts and enforces install-time policy on every install routed through it.

The request path

Same URL. A decision on every install.

A registry serves whatever is published. Chainsaw decides first, then serves.

  1. 01 · Developer or CI

    npm install

    one registry URL swap per package manager

  2. 02 · Chainsaw, on the install path

    • public registries, proxied
    • internal artifacts, same URL
    • your policy, on every request

    alongside your existing registry, or replacing it

  3. Refused

    never enters the build

    Allowed

    served, and cached

Feature matrix

What each layer actually does

Capability Artifact manager Cloudsmith · JFrog · Nexus · Verdaccio Chainsaw Install-time policy proxy
Hosts internal artifacts Yes Yes
Mirrors / caches public packages Hosted publish + pass-through cache on the same URL. Yes Yes
Pass/fail policy decision on every install Via paid add-ons (Nexus Firewall, JFrog Curation); not in the base registry. Partial Yes
Monitoring-first rollout Same add-ons; not in the base registry. Partial Yes
Zero-migration deploy Adopt without moving artifacts into a new registry. No Yes
Works with npm, PyPI, Maven, Docker Yes Yes
Refuse the version the moment a CVE lands Org-wide, no upgrade PRs. Partial Yes
On-prem / air-gapped Partial Yes

Already running an artifact manager?

Keep your registry. Put Chainsaw in front of the public-registry traffic.

Migrate your internal artifacts later if you want: same URL, no separate publish workflow.