All concepts
The mental models behind the Bytesafe Dependency Firewall, prevention, rules, upstreams, exceptions, access, observability, and deployment.
Background reading for how the firewall works. No steps here, see how-to guides for tasks.
Rules and enforcement
Prevention model
The preventive control model. How a dependency firewall differs from scanners and from repository managers.
Rule evaluation
The mental model behind firewall rules. Execution phases, selectors, effects, and where exceptions fit in.
Exception model
Why waivers in the firewall are scoped to one rule, carry a reason, and expire on their own.
Execution phases
What each execution phase sees during an install, and why filtering versions keeps builds running while download rules are the hard stop.
Access
Operations
Upstreams and caching
How a firewall resolves packages from multiple registries, why internal upstreams win, and what the cache flag does.
Observability
The four records a firewall keeps, firewall log, audit log, metrics, and observations, and which question each one answers.
Deployment models
The two ways to run the Bytesafe Dependency Firewall, SaaS or self-hosted on your own infrastructure, and what changes between them.