Sonatype Firewall for Malicious Code Protection | Sonatype

The Strongest Defense Against Malicious Code

Powered by proprietary AI and the industry’s best research, Sonatype Firewall protects repositories, edge, and endpoints — keeping only trusted code in your pipeline.

Firewall 101

Unmatched Protection From Edge to Repository

Sonatype Firewall combines proprietary AI with the industry’s leading security research to safeguard your entire development ecosystem. By blocking malicious code, quarantining suspicious packages, and stopping unsafe components at the source, it reduces exposure to zero-day risks and prevents bad code from ever entering your environment. The result: fewer disruptions, less rework, and faster, more confident delivery of innovation.

Automatically Block Components That Don't Meet Your Standards

Enforce policies at the point of download, and block malicious packages, vulnerabilities, and licensing risks before they disrupt development.

Protect Any Repository

Sonatype Firewall uses proprietary AI and industry-leading open source intelligence to protect any repository from malicious code and vulnerable packages. It automatically blocks threats before they reach developer environments and CI/CD pipelines.

Customized Component Controls

Sonatype Firewall Enterprise enforces your organization’s security, licensing, and quality standards automatically. When violations occur, unsafe components are blocked, and developers receive safe, compliant alternatives.

Malicious OSS Blocking at the Edge

Stop open source malware threats from reaching developer machines by integrating seamlessly with network security tools like Zscaler.

Automated Quarantine

Automatically quarantine suspicious or malicious open source components before they enter your repositories.

Malware Protection Across AI Models

Evaluate AI and ML models sourced from repositories like Hugging Face for malicious code or risky behavior.

Advanced Container Security

Automatically scan and secure Docker images before they enter development.

Unmatched Malicious Code Protection That Delivers Results

Choose the Right Level of Protection for Your Software Supply Chain

Choose the balance of protection and control that fits your team today with the flexibility to grow as your needs evolve. Sonatype Firewall offers malicious package protection in Pro and expanded policy control in Enterprise.

Firewall Pro

Firewall Enterprise

Frequently Asked Questions

Why do I need protection from malicious packages?

Public open source repositories can be compromised, and developers are frequently targeted by malicious open source packages.

What’s the difference between malware and vulnerabilities?

Vulnerabilities are accidental flaws in trusted software. Malware is intentional code crafted by attackers to cause harm. Sonatype Firewall is purpose-built to detect and block open source malware from the start.

Does Sonatype Firewall require a repository manager?

No, Sonatype Firewall does not require a repository manager to work. It works with any repository manager, integrating directly with network security tools such as Zscaler.

Can Sonatype Firewall detect malware in AI/ML models?

Yes. Sonatype Firewall evaluates models at the point of download to determine if they violate security policies or exhibit suspicious behavior.

How quickly does Sonatype Firewall identify and block threats?

Threat detection and blocking happen automatically, in real time.

What deployment options are available for Sonatype Firewall?

Sonatype Firewall supports flexible deployment options to meet different security and infrastructure needs. It is available as a fully managed SaaS offering or can be deployed on-premises or self-hosted.