SONATYPE FIREWALL
The Strongest Defense Against Malicious Code
Powered by proprietary AI and the industry’s best research, Sonatype Firewall protects repositories, edge, and endpoints — keeping only trusted code in your pipeline.
Unmatched Protection From Edge to Repository
Sonatype Firewall combines proprietary AI with the industry’s leading security research to safeguard your entire development ecosystem. By blocking malicious code, quarantining suspicious packages, and stopping unsafe components at the source, it reduces exposure to zero-day risks and prevents bad code from ever entering your environment. The result: fewer disruptions, less rework, and faster, more confident delivery of innovation.
Automatically Block Components That Don't Meet Your Standards
Enforce policies at the point of download, and block malicious packages, vulnerabilities, and licensing risks before they disrupt development.
Protect Any Repository
Sonatype Firewall uses proprietary AI and industry-leading open source intelligence to protect any repository from malicious code and vulnerable packages. It automatically blocks threats before they reach developer environments and CI/CD pipelines, working seamlessly with the tools you already use to prevent risk and eliminate rework. Go beyond standard repository security for protection that mitigates risk.
Customized Component Controls
Malicious OSS Blocking at the Edge
Stop open source malware threats from reaching developer machines by integrating seamlessly with network security tools like Zscaler. This proactive defense mitigates the risk of malicious code inside shadow downloads, significantly reducing security incidents and eliminating remediation efforts to boost developer productivity.
Automated Quarantine
Automatically quarantine suspicious or malicious open source components before they enter your repositories, protecting your development lifecycle. Sonatype Repository Firewall evaluates quarantined components and automatically releases them if confirmed safe, reducing manual reviews and keeping developers productive.
Malware Protection Across AI Models
Evaluate AI and ML models sourced from repositories like Hugging Face for malicious code or risky behavior and gain protection against an emerging attack vector. With a proactive approach to AI security, developers can rapidly innovate with confidence, knowing their ML pipelines are protected against malicious threats and vulnerabilities.
Advanced Container Security
Automatically scan and secure Docker images before they enter development, proactively quarantining malicious or vulnerable container layers. Sonatype Firewall Enterprise’s container scanning ensures rapid development cycles without compromising security or requiring extensive manual container security checks and rework
Unmatched Malicious Code Protection That Delivers Results
Choose the Right Level of Protection for Your Software Supply Chain
Choose the balance of protection and control that fits your team today with the flexibility to grow as your needs evolve. Sonatype Firewall offers malicious package protection in Pro and expanded policy control in Enterprise
Firewall Pro
Focused malicious code protection
- Blocks malicious packages
- Supports npm, Maven, PyPI, and NuGet
- Fast, low-friction onboarding
- Fits existing repository and CI workflows
- Best for teams starting with malicious package protection
Firewall Enterprise
Full control and governance
Everything in Firewall Pro +
- Full policy engine with enforcement
- Broader coverage across the SDLC
- Policy waivers and governance workflows
- Better fit for teams with stronger governance needs
- Expands from visibility into enforcement
- Best for organizations with formal security and compliance needs
Not Sure Which Plan is
Right for You?
Answer a few questions and we will help you choose.
Do you want to block malicious packages with the ability to set policies for deeper control?
Block malicious packages only
Block malicious packages based on a policy engine
Do you need governance controls?
Yes
No
Unsure
Do you want to waive suspicious components based on your risk threshold?
Yes
No
Unsure
Do you need an on-premise or self-hosted deployment?
Yes
No
Based on your answers,
Firewall Pro would be a good fit.
Contact Sales to get a personalized quote
Contact Sonatype Sales
Work with The Tools You Already Use
Sonatype Firewall supports all your favorite languages and formats — so you can secure any project across your ecosystem. No matter what development tools or environments you have, Sonatype Firewall has you covered.
Stop Bad Components Before They Slow You Down
Automatically detect, block, and quarantine malicious components before impacting your development.
Comprehensive Malware Intelligence
Identify and block threats others miss with proprietary AI and leading intelligence backed by the Sonatype Research team.
Edge-to-Repository Protection
Block unsafe components across edge, endpoints, and repositories before they ever reach development.
Automated Quarantine and Release
Quarantine suspicious components and automatically release safe ones, reducing delays and manual work.
Smarter Component Selection
Enforce standards automatically and guide developers toward safe, compliant alternatives.
Advanced Container Security
Quarantine unsafe Docker images before download, keeping containers and CI/CD pipelines secure.
AI and ML Safeguards
Scan AI/ML models for tampering or open source malware, securing pipelines and innovation confidently.
Why Enterprises Trust Sonatype
“As open source vulnerabilities became increasingly problematic in recent years, particularly with Log4j, monitoring and enforcing software composition took on a greater sense of urgency. USPTO turned to Repository Firewall for the ability to block malicious code from the start.”
Spence Spencer
Office of the Chief Information Officer
“We achieved our initial goals with incredible speed, moving from zero to a fully functional, secure, and scaled platform in the first quarter of the year. By May, the Sonatype Repository Firewall had actively quarantined vulnerable components, providing a clear, measurable example of risk reduction.”
Ali Syed
Senior Vice President Infrastructure
“Sonatype Repository Firewall is the first line of defense in our toolchain. It prevents our developers from downloading insecure libraries, which saves time and reduces frustration. They now have more time for productive work and spend less time on repetitive routine tasks”
Tilo Riemer
Deputy Head of Information Systems
“This proactive scanning reduces the amount of hidden work that developers were expected to perform to produce high quality secure code, and it allows that time to be reallocated and productively focused on building new features.”
Agilesh Singaraj
Cloud DevOps Engineer
Explore Sonatype Firewall Resources
The Time Saved Blocking Malicious Components
Frequently Asked Questions
Why do I need protection from malicious packages?
Public open source repositories can be compromised, and developers are frequently targeted by malicious open source packages. Proactive protection stops malicious code from sneaking into your builds and reaching production systems.
What’s the difference between malware and vulnerabilities?
Vulnerabilities are accidental flaws in trusted software like unpatched bugs. Malware is intentional code crafted by attackers to cause harm. Most Software Composition Analysis (SCA) tools only detect known vulnerabilities and miss malicious behavior entirely. Sonatype Firewall is purpose-built to detect and block open source malware from the start, solving a different problem that traditional SCA tools can't address.
Does my perimeter or endpoint solution protect me from open source malware?
No. Perimeter and endpoint solutions aren't built to detect malicious code in open source software libraries and lack specialized malware intelligence. Sonatype Firewall uses our unique open source malware intelligence to proactively identify and block malicious open source components before it enters your development environment.
Does Sonatype Firewall require a repository manager?
No, Sonatype Firewall does not require a repository manager to work. It works with any repository manager like Sonatype Nexus Repository, JFrog Artifactory, Cloudsmith, Azure Artifacts, AWS CodeArtifact, Google Artifact Registry, GitHub Package Registry, and more. Sonatype Firewall can protect your software supply chain even without a dedicated repository manager. It integrates directly with security tools such as Zscaler for network-level protection and uses flexible APIs for seamless integration into custom workflows or existing CI/CD pipelines.
Is Sonatype Firewall compatible with existing network security tools?
Yes, Sonatype Firewall connects seamlessly with network security solutions such as Zscaler, extending open source malware protection to the network edge for comprehensive coverage.
Can Sonatype Firewall detect malware in AI/ML models?
Yes. Sonatype Firewall includes support from Hugging Face. Just like open source packages, these models are evaluated at the point of download to determine if they violate security policies or exhibit suspicious or malicious behavior. That means your data science and engineering teams can innovate with the latest models — confident that every download is secure and policy-compliant.
How quickly does Sonatype Firewall identify and block threats?
Threat detection and blocking happen automatically, in real time. As soon as a developer or system tries to download a malicious or policy-violating component — whether it’s a package, container, or AI model — Sonatype Firewall steps in to block it before it ever enters your development environment. Its advanced malware intelligence minimizes false positives so only true threats are blocked. In rare cases of uncertainty, components are quarantined for further analysis, and automatically released if deemed safe – ensuring developers aren’t stuck waiting on security.
Can Sonatype Firewall help with policy enforcement and waivers?
Yes, Sonatype Firewall Enterprise automates open source governance by quarantining non-compliant components. The powerful policy engine supports flexible policy waivers, including time-based and scoped exceptions, to balance security with development speed.
How often does Sonatype Firewall update its malware database?
Sonatype Firewall continuously updates its malware database, providing real-time protection against the latest open source threats.
What deployment options are available for Sonatype Firewall?
Sonatype Firewall supports flexible deployment options to meet different security and infrastructure needs. It is available as a fully managed SaaS offering for fast setup and minimal operational overhead. Organizations can also deploy it on-premises or self-hosted for greater control within their own environment. For fully disconnected environments, Sonatype Firewall Enterprise is supported via the Sonatype Air-Gapped Environment (SAGE).
Accelerate Secure Development