Dependency Proxy with Malicious Package Firewall

DevGuard includes a built-in dependency proxy that acts as a protective layer between your development environment and public package registries. It helps prevent supply chain attacks by blocking malicious packages before they reach your systems.

How It Works

  1. Request Interception: When you install a package, the proxy intercepts the request
  2. Database Check: The package is checked against the OSV dataset, which includes GitHub malware advisories — kept current via the vulndb sync
  3. Blocking: If flagged as malicious, the request is blocked and logged
  4. Caching: Safe packages are cached with SHA256 integrity verification
  5. Metrics: All blocked attempts are recorded in Prometheus metrics

Supported Ecosystems

EcosystemRegistry URL
npm/api/v1/dependency-proxy/npm
Go modules/api/v1/dependency-proxy/go
PyPI/api/v1/dependency-proxy/pypi/simple
OCI (container images)/v2/ — pull <your-devguard-host>/<registry>/<image>:<tag>

For setup instructions, see the ecosystem-specific guides:

To route all CI jobs through the proxy at once, see Self-Hosted CI Runners.

Minimum Package Age

The proxy can be configured to refuse any package version published more recently than a specified number of hours. This gives the security community time to detect and flag malicious releases before they reach your teams — a simple but effective defense against attacks that rely on packages being downloaded within hours of publication.

The minimum age is configured per organization, project or repository and applies to requests using its proxy URL, which contains a secret. Versions that are too new are hidden from the package metadata, so version ranges resolve to the newest version that is old enough; a download of a too new version is rejected with 403 Forbidden.

EcosystemMinimum package age
npmSupported
PyPISupported
Go modulesSupported
OCI (container images)Not supported — registries expose no reliable publish date, see Setup OCI Proxy

Cache & Security

The proxy enforces security at the caching layer — malicious packages are never cached, and the database must be fully loaded before any requests are served. See Cache Management for details.

Have feedback? We want to hear from you!

Fields marked with * are required