Quickstart
Create an npm firewall, install through it, and see a rule hold back a brand-new version. A few minutes.
Get an npm firewall running and watch it hold back a version published in the last few days. Every ecosystem works the same way; npm keeps the steps concrete.
Sign up and start a 14-day trial, or open the dashboard if you have an account. You also need npm.
Create a firewall
In a new namespace, the dashboard opens a setup wizard:
- Choose npm.
- Keep the recommended protections. One of them, Let new releases mature, holds back versions published in the last 7 days. You will see it work in step 4.
- Name the firewall and select Create firewall.
The dashboard opens the firewall's Setup tab.
No wizard?
It opens only in a namespace with no firewalls. If you closed it, select Create your first firewall on the Firewalls page. If the namespace already has firewalls, select Create on the Firewalls page, choose npm, and name the firewall. Then add the rule: Rules → Add Rule → Let new releases mature → Continue. Check that Max Age is 7 days, and save.
Create an access token
Open the user menu in the lower-left corner and select Access Tokens. Create a personal access token and copy it. It is shown only once. For CI, use a Service Access Token instead; see Access tokens.
Point npm at the firewall
Put the token in an environment variable:
export BYTESAFE_TOKEN=<your token>Then copy the .npmrc snippet from the Setup tab into your project. It reads the token from that variable, and looks like this with your IDs filled in:
registry=https://eu-sov-1.bytesafecloud.eu/v1/<namespace-id>/npm/<firewall-id>/
//eu-sov-1.bytesafecloud.eu/v1/<namespace-id>/npm/<firewall-id>/:_authToken=${BYTESAFE_TOKEN}Install through the firewall and see the rule work
npm install lodashAn established package installs as before. Now pick a package with a version published in the last few days, and ask for exactly that version:
npm install <package>@<version>It fails with No matching version found, because the firewall hid that version from npm. Without an exact version, npm gets the newest version older than 7 days, so builds keep working.
See it in the logs
Open Logs on the firewall. The held-back request is there, with the rule that matched.
Next steps
- Let one version through with an exception, for example a security patch younger than 7 days.
- Set up npm for your team and CI, including yarn, pnpm, and Bun.
- Block vulnerable packages with your own CVSS and EPSS thresholds.
- Rule evaluation explains how phases, selectors, and exceptions fit together.
- Migrate from previous-generation Bytesafe if you use the previous product.
What is a dependency firewall?
How the Bytesafe Dependency Firewall works, what it protects against, and where it fits next to SCA tools and repository managers.
Access tokens
Personal Access Tokens (PAT), Service Access Tokens (SAT), and Trusted Builders with OpenID Connect (OIDC). Which one to use where, and how to create them.