Home / Companies / GitLab / Blog / Post Details
Content Deep Dive

Dependency Firewall: Block risky packages before the build

Blog post from GitLab

Post Details
Company
Date Published
Author
Alisa Ho and Amit Shalem
Word Count
970
Company Posts That Month
6
Language
English
Hacker News Points
-
Post removed?
No
Summary

GitLab has introduced Dependency Firewall in early access to prevent malicious, vulnerable, or non-compliant software packages from entering CI/CD builds before installation, addressing supply-chain risks such as typosquatted PyPI packages that can steal credentials and unreviewed dependencies added by AI coding agents. Unlike software composition analysis tools that identify issues after dependencies have been pulled, the firewall applies policies governing malware status, vulnerability severity, licenses, and package age at the point of installation. Organizations can begin with a warning-only mode before enforcing pipeline-blocking rules, while logged bypasses allow authorized exceptions. Policies can be defined centrally and inherited by groups and projects, with stricter overlapping rules taking precedence, and may also be enforced at registries. Developers can check packages in advance through the GitLab CLI for package managers including npm, pip, Poetry, Maven, Gradle, and Bundler. The feature provides dashboards and immutable audit records for warnings, blocks, and bypasses, supports GitLab Artifact Central plus Sonatype Nexus Repository and JFrog Artifactory, and is available to eligible GitLab.com and Self-Managed Premium or Ultimate customers.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
AI Agents 1 No monthly metrics for this publish month.
AI Coding Assistant 1 No monthly metrics for this publish month.
Observability 1 No monthly metrics for this publish month.
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.