Containers (OCI)
Q3 2026Container firewall for OCI registries, with vulnerability blocking, content scanning, rules, and pull logging.
We are currently working on container image (OCI) firewalling. This page summarizes the planned scope and will become the setup guide at launch.
Expected capabilities
Like the package firewalls, the container firewall will use a registry proxy in front of image sources. It will evaluate each pull against your rules before the image reaches a build agent or node.
- Registry proxy in front of Docker Hub, GitHub Container Registry, AWS ECR, Google Artifact Registry, and private OCI registries.
- Vulnerability blocking for images with known CVEs in base layers or bundled packages, with CVSS and EPSS thresholds like the package equivalent.
- Malware and secrets scanning of image contents.
- Rules by image name, tag pattern, registry source, and age, with block or log effects and time-limited exceptions, following the same rule model.
- Logging and audit of every pull, block, and exception.
Details may change before launch. The design carries over concepts from the package firewalls: rules and evaluation, upstreams, and exceptions.
If container firewalling matters for your adoption, tell us at support@bytesafe.dev; we can notify you when it is available.