Firewall Pro
Sonatype Firewall Pro (https://firewall.sonatype.app) is a cloud-based service that protects your software supply chain by blocking malicious open-source packages before they reach your artifact repository.
Firewall Pro sits between your repository manager and the public internet. When a developer or CI pipeline requests a package, Firewall Pro evaluates it against Sonatype Research threat intelligence and blocks any package identified as potentially malicious — before it is cached or served by your repository manager.
No additional software needs to be installed. You configure your existing repository manager proxy repositories to route traffic through Firewall Pro.
Key Capabilities
Sonatype Repository Pro provides the following key capabilities:
Blocks packages identified by Sonatype Research as potentially containing malicious code; this can include credential harvesters, backdoors, code injectors, and typosquatting attacks
Protects npm, PyPI, NuGet, and Maven package ecosystems
Provides a real-time view of active malware detected across monitored ecosystems
Requires no software installation or infrastructure management
Sonatype's Original Repository Firewall vs. Firewall Pro
While Repository Firewall and Firewall Pro may share a name, they do not share a codebase. The original Repository Firewall is Sonatype's most robust, fully-featured solution for protecting your repositories and controlling the open-source components allowed into your Software Development Lifecycle.
Firewall Pro is a light-weight, SaaS-only solution appropriate for leveraging Sonatype's intelligence to protect to your non-Sonatype repository manager. With Firewall Pro, a component is either allowed or blocked; there is no quarantine or review state as in Sonatype's original Firewall solution.
The table below provides a breakdown of some of the differences and similarities between the original Repository Firewall and new Firewall Pro:
Feature | Firewall Pro | Original Repository Firewall |
|---|---|---|
Protected package ecosystems |
|
|
Leverages Sonatype Intelligence / Data |
|
|
Dependency Range Filtering | Available for npm and PyPI |
|
Quarantine |
| |
Automatic Quarantine Release |
| |
Waivers |
| |
Namespace Confusion Protection |
| |
Integration with Zscaler |
| |
Enterprise Reporting Section |
|
