Quickstart

Create an npm firewall, install through it, and see a rule hold back a brand-new version. A few minutes.

Get an npm firewall running and watch it hold back a version published in the last few days. Every ecosystem works the same way; npm keeps the steps concrete.

Sign up and start a 14-day trial, or open the dashboard if you have an account. You also need npm.

Create a firewall

In a new namespace, the dashboard opens a setup wizard:

  1. Choose npm.
  2. Keep the recommended protections. One of them, Let new releases mature, holds back versions published in the last 7 days. You will see it work in step 4.
  3. Name the firewall and select Create firewall.

The dashboard opens the firewall's Setup tab.

No wizard?

It opens only in a namespace with no firewalls. If you closed it, select Create your first firewall on the Firewalls page. If the namespace already has firewalls, select Create on the Firewalls page, choose npm, and name the firewall. Then add the rule: Rules → Add Rule → Let new releases mature → Continue. Check that Max Age is 7 days, and save.

Create an access token

Open the user menu in the lower-left corner and select Access Tokens. Create a personal access token and copy it. It is shown only once. For CI, use a Service Access Token instead; see Access tokens.

Point npm at the firewall

Put the token in an environment variable:

export BYTESAFE_TOKEN=<your token>

Then copy the .npmrc snippet from the Setup tab into your project. It reads the token from that variable, and looks like this with your IDs filled in:

.npmrc
registry=https://eu-sov-1.bytesafecloud.eu/v1/<namespace-id>/npm/<firewall-id>/
//eu-sov-1.bytesafecloud.eu/v1/<namespace-id>/npm/<firewall-id>/:_authToken=${BYTESAFE_TOKEN}

Install through the firewall and see the rule work

npm install lodash

An established package installs as before. Now pick a package with a version published in the last few days, and ask for exactly that version:

npm install <package>@<version>

It fails with No matching version found, because the firewall hid that version from npm. Without an exact version, npm gets the newest version older than 7 days, so builds keep working.

See it in the logs

Open Logs on the firewall. The held-back request is there, with the rule that matched.

Next steps