Dependency Firewall: Block risky packages before the build
Blog post from GitLab
GitLab has introduced Dependency Firewall in early access to prevent malicious, vulnerable, or non-compliant software packages from entering CI/CD builds before installation, addressing supply-chain risks such as typosquatted PyPI packages that can steal credentials and unreviewed dependencies added by AI coding agents. Unlike software composition analysis tools that identify issues after dependencies have been pulled, the firewall applies policies governing malware status, vulnerability severity, licenses, and package age at the point of installation. Organizations can begin with a warning-only mode before enforcing pipeline-blocking rules, while logged bypasses allow authorized exceptions. Policies can be defined centrally and inherited by groups and projects, with stricter overlapping rules taking precedence, and may also be enforced at registries. Developers can check packages in advance through the GitLab CLI for package managers including npm, pip, Poetry, Maven, Gradle, and Bundler. The feature provides dashboards and immutable audit records for warnings, blocks, and bypasses, supports GitLab Artifact Central plus Sonatype Nexus Repository and JFrog Artifactory, and is available to eligible GitLab.com and Self-Managed Premium or Ultimate customers.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| AI Agents | 1 | No monthly metrics for this publish month. | |||
| AI Coding Assistant | 1 | No monthly metrics for this publish month. | |||
| Observability | 1 | No monthly metrics for this publish month. | |||
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.