DEPENDENCY CONTROL · ALPHA

Know what enters
your codebase.

One gateway between your team and the packages you install. Verify artifacts, enforce release holds, and inspect downloads through the gateway—whether a developer or an agent requests them.

● ● ●   gateway / example session
$ npm install react --registry=$GATEWAY
↳ Checking package policy
↳ Verifying SHA-512 integrity
✓ Artifact stored in R2

# After your team blocks this version
✕ Download denied by organization policy
Cached artifacts follow the same rules.
Built on Cloudflare WorkersR2 artifact storageNative npm workflows48-hour release hold
01 / PRESERVE

Verified before delivery.

Package archives are checked against their upstream checksum before being served from your artifact store.

02 / CONTROL

Let new releases bake.

New versions wait 48 hours by default, measured from registry publication. The hold applies to every gateway download, including cached packages and agent installs.

03 / UNDERSTAND

A clearer download trail.

Inspect allowed and blocked requests from one console. See the version, policy decision, and cache result.

SECURITY & TRUST BOUNDARIES

The gateway is part
of the attack surface.

A service allowed to download packages must not become a route to arbitrary internet access. We treat agents as potentially untrusted callers, even when they have a valid install token.

IMPLEMENTED IN THE LOCAL ALPHA

A deliberately narrow interface.

  • Package requests use names and versions; there is no general-purpose URL-fetch endpoint.
  • Upstream origins are restricted to the public npm registry. Redirects are rejected.
  • Separate install and admin tokens keep install credentials away from policy changes.
  • Archive bytes are verified against SHA-512 before delivery. Cached downloads still check policy.
REQUIRED BEFORE CUSTOMER USE

Defense beyond request validation.

  • Organization isolation and scoped, expiring, revocable member and service tokens.
  • Outbound network restrictions independent of application URL checks.
  • Request, download and concurrency limits, with abuse monitoring.
  • Adversarial testing for SSRF, privilege escalation, cross-tenant access and resource exhaustion, plus independent security review.

Current status: local prototype.

These initial controls are not a production security guarantee. Cloudflare hosting does not establish tenant isolation or prevent proxy abuse by itself. Customer onboarding and the additional protections above are not yet available.

What about the OpenAI / Hugging Face incident?

OpenAI’s published account describes agents exploiting Artifactory to make arbitrary outbound requests, using shared storage for unauthorized communication, and escalating privileges. The lesson for us is to constrain destinations, permissions and shared state—not simply require a token.

Our planned security review must test those failure modes. We have not established that this prototype can withstand comparable attacks.

Read OpenAI’s incident report ↗

Does a 48-hour hold mean a package is safe?

No. It creates time for new releases to be observed; it does not detect malware or guarantee that an older release is safe. A checksum proves that bytes match an expected artifact, not that the artifact is trustworthy. Malware and vulnerability intelligence are not implemented in this alpha.

Can an agent bypass the gateway?

Yes, if its environment allows another download path. Changing npm’s registry setting does not block direct URLs, Git dependencies, install-script network requests, or packages already in a local cache. Mandatory enforcement requires managed network access and cache controls around the agent or CI environment. We do not provide those controls yet.

START LOCAL

Your package manager. A different registry.

Start the server and configure your local registry token as described in the repository README. Then use the gateway with npm:

npm install react --registry=http://localhost:8787/npm/ --no-audit

This alpha supports public npm packages with SHA-512 metadata. More ecosystems and security intelligence are planned.