Veracode Package Firewall: Why & How to Use

Why use Veracode Package Firewall?


  • Block threats before they land in your codebase. Intercept risky packages at install time—malware, typosquats, dependency confusion, license issues, and more.
  • Enforce organization-wide policies consistently. Start with common controls and tailor rules to your risk profile; apply them across teams and projects.
  • Works where you work. Support for major ecosystems (e.g., npm, PyPI, Maven, NuGet, Go modules, RubyGems, Cargo) and proxy/repo setups.
  • Reduce friction, not velocity. Run in warn/audit mode first, provide clear feedback to developers, and streamline exceptions when business-critical.
  • Gain visibility and auditability. Logging, notifications, and review workflows help Security & Compliance track decisions and outcomes.


 

What does this unlock for me & my team?


  • Proactive supply-chain defense. Gate unsafe components before they enter repos or pipelines, reducing downstream risk.
  • Developer-friendly governance. Real-time, actionable guidance in the install path; fast, trackable exceptions when needed.
  • Cleaner SCA/ASPM signals later. Fewer surprise findings post-merge—less rework and fewer emergency patches.
  • Policy coverage on day one. Toggle common safeguards (malware indicators, suspicious publishing patterns, license constraints, package age, etc.).
  • One control plane, many ecosystems. Apply consistent rules across multiple languages and repositories to standardize practices.

How: Paths to Success




How-To: Generate an API Token for Authentication

  1. Log in to the Phylum application at https://app.phylum.io.
  2. Click on your profile picture in the top-right corner of the UI.
  3. Select 'API Token Generator' from the dropdown menu.
  4. Provide a token name and select an appropriate lifespan (e.g., 30 days). 
  5. Click 'Generate Token' and save the token securely for authentication.
  6. Create the Firewall Instance (Group)
  7. Click ‘Firewall’ then ‘+ New Instance’
  8. Name your Instance and click ‘Submit’


Instructions for configuring Phylum for artifact repositories and package registries:

Artifactory - Documentation Link

Nexus Repository - Documentation Link


Cargo - Doc Link

Golang - Doc Link

Maven - Doc Link

NPM - Doc Link

NuGet - Doc Link

PyPI - Doc Link

RubyGems - Doc Link



Notification API

Veracode Package Firewall supports sending out notifications whenever a package fails analysis.

To receive those notifications, you can setup webhooks.




FAQ:

Supported Ecosystems List (NPM, Rubygems etc)



What happens if the package has not been pre-processed by the Package Firewall?

The installation is aborted and the user is notified. This action prompts the Veracode Package Firewall pipeline to begin analysis on any packages that were not already processed and the user can attempt the installation again after the pipeline has had time to process the requests.










Guide Links: