Sonatype Firewall for Malicious Code Protection | Sonatype
The Strongest Defense Against Malicious Code
Powered by proprietary AI and the industry’s best research, Sonatype Firewall protects repositories, edge, and endpoints — keeping only trusted code in your pipeline.
Firewall 101
Unmatched Protection From Edge to Repository
Sonatype Firewall combines proprietary AI with the industry’s leading security research to safeguard your entire development ecosystem. By blocking malicious code, quarantining suspicious packages, and stopping unsafe components at the source, it reduces exposure to zero-day risks and prevents bad code from ever entering your environment. The result: fewer disruptions, less rework, and faster, more confident delivery of innovation.
Automatically Block Components That Don't Meet Your Standards
Enforce policies at the point of download, and block malicious packages, vulnerabilities, and licensing risks before they disrupt development.
Protect Any Repository
Sonatype Firewall uses proprietary AI and industry-leading open source intelligence to protect any repository from malicious code and vulnerable packages. It automatically blocks threats before they reach developer environments and CI/CD pipelines.
Customized Component Controls
Sonatype Firewall Enterprise enforces your organization’s security, licensing, and quality standards automatically. When violations occur, unsafe components are blocked, and developers receive safe, compliant alternatives.
Malicious OSS Blocking at the Edge
Stop open source malware threats from reaching developer machines by integrating seamlessly with network security tools like Zscaler.
Automated Quarantine
Automatically quarantine suspicious or malicious open source components before they enter your repositories.
Malware Protection Across AI Models
Evaluate AI and ML models sourced from repositories like Hugging Face for malicious code or risky behavior.
Advanced Container Security
Automatically scan and secure Docker images before they enter development.
Unmatched Malicious Code Protection That Delivers Results
Choose the Right Level of Protection for Your Software Supply Chain
Choose the balance of protection and control that fits your team today with the flexibility to grow as your needs evolve. Sonatype Firewall offers malicious package protection in Pro and expanded policy control in Enterprise.
Firewall Pro
- Blocks malicious packages
- Supports npm, Maven, PyPI, and NuGet
- Fast, low-friction onboarding
- Fits existing repository and CI workflows
Firewall Enterprise
- Full policy engine with enforcement
- Broader coverage across the SDLC
- Best for organizations with formal security and compliance needs
Frequently Asked Questions
Why do I need protection from malicious packages?
Public open source repositories can be compromised, and developers are frequently targeted by malicious open source packages.
What’s the difference between malware and vulnerabilities?
Vulnerabilities are accidental flaws in trusted software. Malware is intentional code crafted by attackers to cause harm. Sonatype Firewall is purpose-built to detect and block open source malware from the start.
Does Sonatype Firewall require a repository manager?
No, Sonatype Firewall does not require a repository manager to work. It works with any repository manager, integrating directly with network security tools such as Zscaler.
Can Sonatype Firewall detect malware in AI/ML models?
Yes. Sonatype Firewall evaluates models at the point of download to determine if they violate security policies or exhibit suspicious behavior.
How quickly does Sonatype Firewall identify and block threats?
Threat detection and blocking happen automatically, in real time.
What deployment options are available for Sonatype Firewall?
Sonatype Firewall supports flexible deployment options to meet different security and infrastructure needs. It is available as a fully managed SaaS offering or can be deployed on-premises or self-hosted.