Dependency Proxy with Malicious Package Firewall
DevGuard includes a built-in dependency proxy that acts as a protective layer between your development environment and public package registries. It helps prevent supply chain attacks by blocking malicious packages before they reach your systems.
How It Works
- Request Interception: When you install a package, the proxy intercepts the request
- Database Check: The package is checked against the OSV dataset, which includes GitHub malware advisories — kept current via the vulndb sync
- Blocking: If flagged as malicious, the request is blocked and logged
- Caching: Safe packages are cached with SHA256 integrity verification
- Metrics: All blocked attempts are recorded in Prometheus metrics
Supported Ecosystems
| Ecosystem | Registry URL |
|---|---|
| npm | /api/v1/dependency-proxy/npm |
| Go modules | /api/v1/dependency-proxy/go |
| PyPI | /api/v1/dependency-proxy/pypi/simple |
| OCI (container images) | /v2/ — pull <your-devguard-host>/<registry>/<image>:<tag> |
For setup instructions, see the ecosystem-specific guides:
To route all CI jobs through the proxy at once, see Self-Hosted CI Runners.
Minimum Package Age
The proxy can be configured to refuse any package version published more recently than a specified number of hours. This gives the security community time to detect and flag malicious releases before they reach your teams — a simple but effective defense against attacks that rely on packages being downloaded within hours of publication.
The minimum age is configured per organization, project or repository and applies to requests using its proxy URL, which contains a secret. Versions that are too new are hidden from the package metadata, so version ranges resolve to the newest version that is old enough; a download of a too new version is rejected with 403 Forbidden.
| Ecosystem | Minimum package age |
|---|---|
| npm | Supported |
| PyPI | Supported |
| Go modules | Supported |
| OCI (container images) | Not supported — registries expose no reliable publish date, see Setup OCI Proxy |
Cache & Security
The proxy enforces security at the caching layer — malicious packages are never cached, and the database must be fully loaded before any requests are served. See Cache Management for details.