Veracode Package Firewall: Why & How to Use
Why use Veracode Package Firewall?
- Block threats before they land in your codebase. Intercept risky packages at install time—malware, typosquats, dependency confusion, license issues, and more.
- Enforce organization-wide policies consistently. Start with common controls and tailor rules to your risk profile; apply them across teams and projects.
- Works where you work. Support for major ecosystems (e.g., npm, PyPI, Maven, NuGet, Go modules, RubyGems, Cargo) and proxy/repo setups.
- Reduce friction, not velocity. Run in warn/audit mode first, provide clear feedback to developers, and streamline exceptions when business-critical.
- Gain visibility and auditability. Logging, notifications, and review workflows help Security & Compliance track decisions and outcomes.
What does this unlock for me & my team?
- Proactive supply-chain defense. Gate unsafe components before they enter repos or pipelines, reducing downstream risk.
- Developer-friendly governance. Real-time, actionable guidance in the install path; fast, trackable exceptions when needed.
- Cleaner SCA/ASPM signals later. Fewer surprise findings post-merge—less rework and fewer emergency patches.
- Policy coverage on day one. Toggle common safeguards (malware indicators, suspicious publishing patterns, license constraints, package age, etc.).
- One control plane, many ecosystems. Apply consistent rules across multiple languages and repositories to standardize practices.
How: Paths to Success
How-To: Generate an API Token for Authentication
- Log in to the Phylum application at https://app.phylum.io.
- Click on your profile picture in the top-right corner of the UI.
- Select 'API Token Generator' from the dropdown menu.
- Provide a token name and select an appropriate lifespan (e.g., 30 days).
- Click 'Generate Token' and save the token securely for authentication.
- Create the Firewall Instance (Group)
- Click ‘Firewall’ then ‘+ New Instance’
- Name your Instance and click ‘Submit’
Instructions for configuring Phylum for artifact repositories and package registries:
Artifactory - Documentation Link
Nexus Repository - Documentation Link
Cargo - Doc Link
Golang - Doc Link
Maven - Doc Link
NPM - Doc Link
NuGet - Doc Link
PyPI - Doc Link
RubyGems - Doc Link
Notification API
Veracode Package Firewall supports sending out notifications whenever a package fails analysis.
To receive those notifications, you can setup webhooks.
FAQ:
Supported Ecosystems List (NPM, Rubygems etc)
What happens if the package has not been pre-processed by the Package Firewall?
The installation is aborted and the user is notified. This action prompts the Veracode Package Firewall pipeline to begin analysis on any packages that were not already processed and the user can attempt the installation again after the pipeline has had time to process the requests.
Guide Links:
- 🏁 Getting Started Guide (Start here)
- 🧭 Secure the SDLC with Veracode (where we fit, end-to-end)
- 🧑💻 Application Security Testing Developer Workflow (scan → fix → verify)
- 🧩 IDE Scanning (find flaws while you code)
- 🔁 Repo / CI Scanning (automate scans in your pipelines)
- 🛡️ Package Firewall (block risky open-source dependencies)
- 📊 Veracode Risk Management (VRM) (prioritize, track, report)
.png)