logo

Introducing Supply-Chain Firewall: Protecting Developers from Malicious Open Source Packages

ID: eb11c3c0-014e-5a2c-a5b9-2680ba3cbf46

STIX ID: report--eb11c3c0-014e-5a2c-a5b9-2680ba3cbf46

Feed Name: Datadog Security Labs

Date Published: 2024-12-06

Date Updated: 2026-04-27

...
...

Datadog Security Labs introduces Supply-Chain Firewall (scfw), an open-source Python tool that wraps pip and npm to prevent installation of known malicious or vulnerable packages by querying sources like OSV and Datadog advisories; it can block or prompt on risky installs, run transparently via shell aliases, and optionally forward detailed telemetry to Datadog Log Management, with examples shown and plans to extend support to pnpm, yarn, and poetry; the tool is available on PyPI and GitHub.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.