Software Supply Chain Security
Stop risky packages at the registry, before they enter your supply chain
The Dependency Firewall puts your policy in front of the package registry, so the decision about what's allowed in happens when a component is requested — not in a review three weeks later.
- Block what never should have entered Known-malicious and typosquatted packages are stopped at the door, based on threat research from GitLab's Vulnerability Research team.
- You decide what's allowed in Set the rules once and they hold across every project that pulls through the registry — warn, block, or block with a logged bypass.
- Shape the product as a design partner Closed beta participants work directly with the product team and influence what the firewall blocks and how.
The Dependency Firewall is part of GitLab's Software Supply Chain Security offering. Closed beta places are limited and reviewed by the product team.
✓
Request received
Thanks — you're on the list to join the beta program! You will be hearing from us shortly at the email you provided.