Stop risky packages at the registry, before they enter your supply chain
The Dependency Firewall puts your policy in front of the package registry, so the decision about what's allowed in happens when a component is requested — not in a review three weeks later.
Known-malicious and typosquatted packages are stopped at the door, based on threat research from GitLab's Vulnerability Research team.
The Dependency Firewall is part of GitLab's Software Supply Chain Security offering. Closed beta places are limited and reviewed by the product team.
Request early access
Tell us a little about you and your environment.