# Sonatype Repository Firewall

[Sonatype Repository Firewall](/content/products/sonatype-repository-firewall/index.html) is the first line of defense for controlling the open-source components allowed into your Software Development Lifecycle.

- **Prevent Malware** - from entering your software supply chain
- **Automatically Evaluate** - every new component against your custom governance policies
- **Automatically Quarantine** - components before they are available in your artifact repository

Sonatype's IQ Server powers the Repository Firewall. The integration connects to your artifact repository to oversee the enforcement of your open-source consumption policies.

View the latest release in the [IQ Server Release Notes](https://help.sonatype.com/en/iq-server-release-notes.html "Sonatype IQ Server Release Notes")

## Paths to Getting Started

The Repository Firewall license is available as a fully managed Cloud solution or a self-hosted deployment where you manage the service.

- ## Firewall Cloud

Firewall Cloud reduces time-to-value by skipping the time needed to provision hardware and the costs of managing the self-hosted service. Only one quick step set up your tenant and IdP (identity provider) before jumping into protecting your infrastructure.

Getting started with [Sonatype Cloud](https://help.sonatype.com/en/sonatype-cloud.html "Sonatype Cloud")

- ## Self-Hosted

The Self-Hosted solution deploys as you want; as a single-node or a multi-regional, highly available service without restrictions. Built on the same platform as Lifecycle and SBOM Manager to scale with your organizational requirements.

Getting started with [Repository Firewall](https://help.sonatype.com/en/repository-firewall-getting-started.html "Getting Started with Self-Hosted Repository Firewall")

## Repository Firewall Product Information

Repository Firewall can be used without IQ Server or an artifact repository, but some functionality is available only when those components are configured. Repository Firewall is compatible with Sonatype Nexus Repository 3 Pro and JFrog Artifactory.

**Note**

If IQ Server or an artifact repository is not configured, Repository Firewall functionality is limited.

- **IQ Server 134 or later**

Firewall Cloud is updated automatically

- **Nexus Repository Pro 3.38.1 or later**

Repository Firewall solution is included in the Nexus Repository and IQ Server codebase

- **JFrog Artifactory 7.2.6 or later**

JFrog Artifactory SaaS is not supported

- #### Requires HTTP version 1.1

Repository Firewall relies on the human-readable `errorPhrase` from the HTTP/1.1 protocol. HTTP/2 is not supported.

### [Minimal Versions for Repository Firewall Features](https://help.sonatype.com/en/repository-firewall.html#minimal-versions-for-repository-firewall-features_body)

Below is a matrix of Sonatype server product versions minimally **verified for Repository Firewall features**. This does not mean all features are supported by these versions.

The table suggests that major issues should not be encountered when running these minimal versions congruently.

If you encounter problems with any of the versions listed, we advise upgrading to the most recent version first to attempt resolution of the issue.

**Repository Firewall is powered by the IQ Server**

| IQ Server | Nexus Repository 3 | Nexus Repository 2 |
| --- | --- | --- |
| 138 | 3.58.0 |  |
| 106 | 3.30.0 |  |
| 1.46.0 | 3.12.1 | 2.14.8 |
| 1.42.0 | 3.8.0 | 2.14.6 |
| 1.33.0 | 3.7.1 | 2.14.5 |
| Not Supported | 3.4.0 | 2.14.4 |

## Repository Firewall Features

| Features | Sonatype Nexus Repository 3 | JFrog Artifactory |
| --- | :-: | :-: |
| [Quarantine](https://help.sonatype.com/en/firewall-quarantine.html "Firewall Quarantine") |  |  |
| [Namespace Confusion Protection](https://help.sonatype.com/en/namespace-confusion-protection.html "Namespace Confusion Protection") |  |  |
| [Release Integrity](https://help.sonatype.com/en/release-integrity.html "Release Integrity")<br>Available for; npm, Maven, PyPI, Hugging Face, and NuGet |  |  |
| [Automatic Quarantine Release](https://help.sonatype.com/en/automatic-quarantine-release.html "Automatic Quarantine Release") |  |  |
| [Policy Compliant Component Selection](https://help.sonatype.com/en/policy-compliant-component-selection.html "Policy Compliant Component Selection") |  |  |
| [Integrate Firewall with Zscaler](https://help.sonatype.com/en/zscaler.html "Integrate Firewall with Zscaler") |  |  |
| [Firewall for Docker](https://help.sonatype.com/en/firewall-for-docker.html "Firewall for Docker") |  |  |
| PCCS for npm | IQ.134, NX-3.44 | plugin 2.4.4 |
| PCCS for PyPI | IQ.167, NX-3.61 |  |

## Package Support for Repository Firewall

The following ecosystems and proxy URLs are the supported package repositories for the Repository Firewall.

This is not a comprehensive list of sources for Sonatype Component Intelligence.

| Package Manager | Public Repository |
| --- | --- |
| CocoaPods | https://cdn.cocoapods.org |
| Composer | https://repo.packagist.org |
| Conan | https://center.conan.io<br>_(supports Conan v1 and Conan v2)_ |
| Conda | https://repo.anaconda.com/pkgs<br>https://conda.anaconda.org/conda-forge/ |
| Docker<br>IQ 194 & Nexus Repository 3.83.0<br>not supported by Firewall for Artifactory | https://registry-1.docker.io |
| Go Modules | https://index.golang.org<br>_(detection of pre-release versions is not supported)_ |
| Hugging Face<br>IQ 191 & Nexus Repository 3.80.0 | https://huggingface.co<br>Provides enforcement on the following extensions:<br>```<br>.bin, .pt, .pth, .h5, .msgpack, .onnx, .ot, .safetensors, .gguf, .pkl, .pickle<br>``` |
| Maven | https://repo.maven.apache.org/maven2<br>https://maven.google.com<br>https://maven.repository.redhat.com/ga/ |
| npm | https://registry.npmjs.org |
| NuGet | https://nuget.org |
| PyPI | https://pypi.org |
| RubyGems | https://rubygems.org |
| Rust/Cargo<br>IQ 181, NR 3.74.0 | https://index.crates.io |
| R Language | https://cran.r-project.org |
| Raw | Any static website that's proxied |
| Yum/rpm (EPEL) | https://dl.fedoraproject.org |

## Search results

No results found

Copy as Markdown
