Sonatype Firewall Pro

Stop Malicious Code Before it Becomes an Incident

Automatically block malicious and unwanted open source packages from entering your software supply chain. Sonatype Firewall Pro provides frictionless malicious code protection for your artifact repositories to ensure your development stays fast and secure.

Sonatype Repository Firewall protection workflow blocking malicious components at the edge.

Enhanced Security For Your Existing Repository

Sonatype Firewall Pro acts as a secure cloud gateway for public registries. As AI tools scale your development velocity and increase automated package requests, Firewall Pro acts as a critical safety net. It automatically blocks and quarantines malware before it is downloaded, eliminating risk for teams using JFrog Artifactory, Cloudsmith, and other third-party repository managers.

Block Malicious Code From Entering Your Repository

Firewall Pro is a cloud-based gateway designed to provide malicious code protection, preventing dangerous npm, Maven, PyPI, and NuGet packages from reaching your systems.

Dashboard view of active malware shown in upstream ecosystems.
Protection configuration with Sonatype Firewall Pro
AI request that has been analyzed, blocked by policy, and pending human review.
No uninterrupted workflows or slow scans.

The Strongest Defense Against Malicious Dependencies

0
M
Malicious Packages Prevented From Being Downloaded
$
0
M
Annual Savings From Prevented Malicious Code Attacks
0
x
More Malicious Packages Identified Than Competitors




Work with The Tools You Already Use

Firewall Pro offers broad support across modern development ecosystems, integrating seamlessly with the package formats and the repository managers you rely on every day.

Featured Formats and Languages

JFrog Artifactory

Bad packages don't stop at JFrog's logo. Add a critical layer of proactive malware defense to your Artifactory instances with a simple upstream URL change.

Cloudsmith

Secure your cloud-native artifact workflows with the industry's most precise malware intelligence, ensuring only safe components get through

Azure Artifacts

Instantly deploy Sonatype's premier malicious code protection directly into your Azure Artifacts npm feeds to safeguard your cloud-native pipelines.

Security That Doesn't Slow You Down

Engineering teams should not have to choose between moving fast and staying secure. Firewall Pro integrates silently into your existing workflows, providing robust malicious code protection without the overhead of traditional security tools.

Proactive Threat Mitigation

By stopping malicious code at the front door, you completely eliminate the massive engineering hours, stress, and financial costs associated with downstream incident remediation and cleanup.

Zero False Positives

Stop relying on noisy tools that disrupt engineering. Powered by Sonatype Research Labs, Firewall Pro leverages precise, human-validated intelligence to block suspicious packages.

Instant Time-to-Value

Deploy in minutes without migrating your infrastructure. Add instant protection to your existing workflows so your teams can stay focused on building great software instead of managing complex security setups.

icon-carrot_left-large
icon-carrot_right-large

Why Enterprises Trust Sonatype

electric blue glow quote glyph
USPTO logo
Danish Center for AI Innovation company logo
Muhlbauer logo white

“As open source vulnerabilities became increasingly problematic in recent years, particularly with Log4j, monitoring and enforcing software composition took on a greater sense of urgency. USPTO turned to Repository Firewall for the ability to block malicious code from the start.”

Spence Spencer

Office of the Chief Information Officer

See Full Customer Story

“Previously, the security burden was on the end-user. Now, we can pull containers and packages from our repositories with confidence, knowing every component has been vetted by Sonatype. This allows us to focus on research and AI workloads instead of on component risk analysis.”

Ali Syed

Senior Vice President Infrastructure

See Full Customer Story

“Sonatype Firewall is the first line of defense in our toolchain. It prevents our developers from downloading insecure libraries, which saves time and reduces frustration. They now have more time for productive work and spend less time on repetitive routine tasks.”

Tilo Riemer

Deputy of Information Systems

See Full Customer Story
thin chevron
thin chevron

Frequently Asked Questions

What is malicious code and why is it harmful to software development?

Malicious code is any software component or script intentionally designed to cause harm, such as stealing data, disrupting operations, or compromising a system. In software development, it often hides within open source packages, and a single download can infect an entire application and its downstream users.

How can malicious code cause damage to your CI/CD pipelines?

When a malicious package is pulled into a CI/CD pipeline, it can execute during the build or test stages. This can lead to compromised build servers, theft of sensitive credentials (like API keys and tokens), or the injection of backdoors into the final production software.

What are examples of malicious code?

Malicious code in open source software libraries usually takes the form of compromised packages that trick developers or build systems into downloading harmful payloads. Common examples include typosquatting, which exploits slight misspellings of popular libraries, and dependency confusion, which tricks package managers into pulling a public malicious package instead of a secure internal one. Once downloaded, these disguised packages execute destructive payloads like credential stealers hunting for API keys, unauthorized crypto-miners, or hidden backdoors that compromise your entire CI/CD pipeline.

What is the best malicious code protection software to secure artifact repositories?

Sonatype Firewall Pro is the premier solution for engineering-led teams using third-party managers like JFrog Artifactory, Cloudsmith, Azure Artifacts, GitLab Package Registry, and GitHub Packages. Powered by the industry's most accurate, human-verified threat intelligence database, it identifies and blocks 156 times more malicious dependencies than competitors, stopping supply chain attacks at the very edge of your network.

How can you prevent the download of malicious code with Sonatype Firewall Pro?

Firewall Pro acts as an upstream proxy. You configure your existing repository manager or build tools to point to our secure registry-specific SaaS URLs. When a package is requested, Firewall Pro runs a real-time check against Sonatype's malware database and blocks the download if the component is malicious, ensuring only safe packages reach your environment.

What is the difference between Sonatype Firewall Pro and Enterprise plans?

Firewall Pro is a cloud-only proxy designed for engineering-led teams using third-party artifact managers who need simple, zero-configuration malicious package protection out of the box. Firewall Enterprise is a full-featured repository firewall that provides advanced, customizable compliance rules, license management, waivers, and on-premises deployment options.

Can Sonatype Firewall Pro be used with any artifact repository?

Firewall Pro is built specifically for third-party repository managers like JFrog Artifactory, Cloudsmith, or AWS CodeArtifact. Because it works as a SaaS upstream proxy, you keep your existing repository layout intact. It is not designed or intended for Sonatype Nexus Repository users.

Keep Your Repository Secure

Get Started