Introducing Supply-Chain Firewall: Protecting Developers from Malicious Open Source Packages
ID: eb11c3c0-014e-5a2c-a5b9-2680ba3cbf46
STIX ID: report--eb11c3c0-014e-5a2c-a5b9-2680ba3cbf46
Feed Name: Datadog Security Labs
Datadog Security Labs introduces Supply-Chain Firewall (scfw), an open-source Python tool that wraps pip and npm to prevent installation of known malicious or vulnerable packages by querying sources like OSV and Datadog advisories; it can block or prompt on risky installs, run transparently via shell aliases, and optionally forward detailed telemetry to Datadog Log Management, with examples shown and plans to extend support to pnpm, yarn, and poetry; the tool is available on PyPI and GitHub.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
