Why not just SCA?

SCA reports. Chainsaw refuses. Run both.

SCA tells you what's already inside your build. Chainsaw refuses the request on the install path, before bytes land.

How the install path works →

Decision timing

Where each tool acts on one install

Chainsaw decides before the package enters a build. SCA reports after it is in use.

  1. 01 · Developer or CI

    npm install
  2. 02 · Chainsaw decides

    • CVE, license, version
    • up to 25 supply-chain signals

    on supported ecosystems

  3. Refused

    never reaches a build

    Allowed

    in the build. SCA reports on it from here, after install

The attack-pattern signals SCA misses →

Feature matrix

Reporting vs. install-time control

Capability SCA tool Snyk · Sonatype · Mend Chainsaw Install-time policy proxy
Dependency inventory / SBOM Yes Partial
CVE reporting & alerts Yes Partial
Refuses a package before it reaches a build No Yes
License policy at install time Refuse GPL in production, for example. Partial Yes
Monitor-only mode before enforcing No Yes
Policy response to a new CVE Stop new installs without waiting on upgrade PRs. No Yes
Post-install reporting Yes Partial
Refuses supply-chain attacks beyond CVE Install-script exfiltration, maintainer takeover, worm bursts. No Yes
Checksum fail-closed on upstream fetch No Yes

Want to see it in practice?

Compare your current SCA coverage to install-time control

Start a free org in monitor mode. See what Chainsaw would have refused this week.