The package was malware. Your proxy should never have served it — Sonatype Repository Firewall checks every open-source package at the proxy — blocking malware before it is cached or served, and on the self-hosted edition quarantining suspicious packages until they are cleared.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Sonatype Repository Firewall — Firewall Pro and the self-hosted edition. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
A check at the proxy that decides, per request, whether an open-source package may be downloaded into your organisation at all.
What consolidation actually replaces, dimension by dimension.
| Dimension | Alerts after the package is in | Sonatype Repository Firewall |
|---|---|---|
| When malware is caught | After it is cached and built | At the proxy, before it is served |
| A suspicious package | Served until an advisory lands | Quarantined until cleared (self-hosted) |
| Internal package names | Open to namespace confusion | Public look-alikes quarantined |
| Exceptions | Allow-lists nobody reviews | Scoped, time-based waivers |
| Disconnected networks | Manual copies, unchecked | Air-gapped support via SAGE |
| What it is NOT | — | Not SCA for what is already in your apps |
The cheapest test: route one proxy repository through the firewall for two weeks and count what it would have stopped.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Every decision checks Sonatype’s own malicious-package data — the research behind its quarterly Malware Index, which logged 21,764 new malicious packages in Q1 2026 alone.
Your repository manager’s proxy repositories fetch through the firewall instead of the public registry. A package is checked on request, before it is cached or served.
The self-hosted edition applies configurable policy on security, licence and quality at the point of download, and audits components already in the repository.
Suspicious components are held, not served. They are released by a waiver, an automatic release policy or a manual approval — or automatically once confirmed safe.
Malware research, an upstream proxy and quarantine — every package checked before your registry ever serves it.
Sonatype Repository Firewall stops malicious packages at the proxy — before your repository manager caches them or a build ever pulls them.
Blocks credential harvesters, backdoors, code injectors and typosquats before your repository manager caches or serves them.
Sonatype lists Artifactory, Cloudsmith, Azure Artifacts, GitLab, GitHub Packages and CodeArtifact. No software to install.
Sonatype says the firewall evaluates AI and ML models from repositories such as Hugging Face for malicious code or risky behaviour.
The self-hosted edition quarantines suspicious components before they enter, and releases them automatically if they are confirmed safe.
It learns your internal namespaces from hosted repositories and quarantines any public package that claims the same name.
Container protection on the self-hosted edition checks images and quarantines risky ones before a pull completes.
Security, licence and quality standards are enforced at the point of download, with policy configured by risk level on the self-hosted edition.
Waivers can be time-based or scoped, so an exception for one team or one release does not quietly become a permanent hole.
The self-hosted edition supports internet-connected and air-gapped repositories; SAGE is Sonatype’s bundle for disconnected sites.
Where the firewall sits in your pipeline, how evaluation and quarantine work, and best practice for waivers.
Where the firewall sits in the pipeline.
Scoping and timing exceptions.
Evaluate, quarantine and release.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Most package gates are quote-only add-ons to a larger platform. Firewall Pro lists at $4,800 a year and sits in front of the registry you already run — Artifactory, Cloudsmith, Azure Artifacts, GitLab, GitHub Packages or CodeArtifact — so a malware block does not wait for a platform migration.
The self-hosted edition holds suspicious components — not only known malware — and releases them automatically once confirmed safe, or through a scoped, timed waiver. It audits what is already in the repository and quarantines only new arrivals, so switching it on does not break existing builds.
The self-hosted edition runs on your own servers and supports air-gapped repositories through SAGE, so policy, quarantine and audit data stay inside your perimeter. For an Indian bank or a defence supplier that cannot send traffic to a foreign cloud, that is the route to local control.
Firewall Pro covers four ecosystems, needs internet-connected repositories and is not for Nexus; quarantine, containers and air-gap are self-hosted only, and that edition is quote-only. Firewall Cloud hosting regions are not documented. It gates what enters — finding risk already in your apps is Sonatype Guide’s job.
List your repository manager and ecosystems. Non-Nexus and only npm, Maven, PyPI or NuGet points to Pro; else self-hosted.
Point one proxy repository at the firewall and pull real traffic through it. Log what is blocked and who asked for it.
On the self-hosted edition, audit what is already cached, then quarantine only new components so existing builds keep working.
Decide who approves waivers and for how long, and register internal namespaces so public look-alikes are quarantined.
Route every remaining proxy repository through the firewall, add containers and AI models if licensed, and review the blocks.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“We run Artifactory, not Nexus. Firewall Pro was a new upstream URL on four proxy repositories and an afternoon of testing.”
“Audit-first was the right call. It flagged what was already cached without breaking a single existing build on day one.”
“Namespace-confusion protection caught a public package squatting on one of our internal scopes within the first fortnight.”
“Our build network has no internet route. The self-hosted edition with SAGE was the only firewall on our shortlist that fitted.”
“Pro covers npm, Maven, PyPI and NuGet only. Our Go and Docker traffic needed the self-hosted edition, which meant a quote.”
“Quarantine released most held packages on its own once they cleared. The manual queue stayed small enough for one reviewer.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the package-security market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
An established repository firewall whose entry tier is listed at $4,800 a year; deepest on Nexus.
The grid nobody publishes — how early a tool stops a risky package vs how much control you get over where it runs.
Blocks at the proxy; the self-hosted edition quarantines and runs air-gapped.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against JFrog Curation, Socket, Snyk Open Source, Mend.io and GitHub Dependabot — on when risk is stopped, coverage, deployment, price and India.
| Dimension | Sonatype Repository Firewall | JFrog Curation | Socket | Snyk Open Source | Mend.io | GitHub Dependabot + Code Security |
|---|---|---|---|---|---|---|
| What it is | Repository firewall | Pre-entry package gate | Scanner + firewall | Scan after declaration | SCA + update bot | Alerts after the fact |
| Deployment | Cloud to air-gapped | SaaS or self-managed | SaaS; self-host on Ent. | SaaS only | Not published | GitHub.com or GHES |
| Ecosystems covered | 4 on Pro, 15+ self-host | Languages, OS, AI, IDE | 3 free, more on Ent. | Major languages | Code deps + containers | 8 malware ecosystems |
| Pricing model | Annual, or by quote | Quote-only add-on | Per developer / month | Flat or credits | Per contributing dev | Free + per committer |
| Published entry price | $4,800 a year | Not published | $0 free tier | $0 free tier | Ceiling, not floor | $0 for Dependabot |
| Included vs add-on | Two editions | Add-on to the platform | Firewall by tier | Per-product credits | Bundled platform | Alerts free, depth paid |
| Scale limits | Not published | Follows the tier | Scan quotas | Test limits | No GB or scan fees | Per repository |
| Security depth | Malware + quarantine | Malware, CVE, licence | 70+ risk types | Vulns + licences | Vulns + licences | Advisory-based alerts |
| Integrations | Six registries + Nexus | Registries, SASE, agents | GitHub, CLI, Slack | IDE, CLI, SCM, CI | SCM + Renovate | GitHub only |
| Governance & SSO | Policy on self-hosted | Waivers, audit, SSO | SSO from Business | Enterprise-level | Not published | Team or Enterprise |
| India storage region | Self-host in India | Mumbai · Pune | Not published | US, EU, AU only | Not published | Via GHES |
| Support | Not published | 24/7 SLA from Ent X | By tier | Next business day | Dedicated (Renovate) | Follows the plan |
| Lock-in / exit | Edition-dependent | Tied to Artifactory | Light to remove | Scanner only | Scanner + free Renovate | Tied to GitHub |
| Best fit | Nexus or mixed repos | Artifactory estates | JS/Python-heavy teams | Developer-first SCA | SCA + updates bundle | The baseline |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Sonatype Repository Firewall is one of 35 developer tools products TechBag carries. The Developer Tools guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (developers; loaded developer-hour cost). Estimates model the time lost to malicious or risky packages found after they were downloaded — triage, cache purges, rebuilds and credential rotation — at an assumed 1.5 hours per developer a year, with 70% avoided by blocking at the proxy. Both figures are illustrative assumptions, not Sonatype data. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Firewall Pro lists from $4,800 a year (country and local taxes excluded) for npm, Maven, PyPI and NuGet, on repositories other than Nexus and internet-connected only. The self-hosted Repository Firewall — 15+ formats, quarantine, container protection and air-gap — is quote-only. TechBag prices both against your registry and formats, then quotes in INR with GST.
Best for non-Nexus registries
Best for a broader rollout
Best for Nexus and offline sites
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Which repository manager do you run? Firewall Pro is for repositories other than Nexus; Nexus shops need the self-hosted edition.
Are all your ecosystems in npm, Maven, PyPI and NuGet? Go, Docker, Cargo and others need the self-hosted edition.
Is any build network air-gapped? Pro serves internet-connected repositories only; offline sites need self-hosted and SAGE.
Do you need suspicious packages held for review, or is blocking known malware enough? Quarantine is self-hosted only.
On self-managed Artifactory, will you use Pro or the self-hosted plugin? Sonatype’s docs say Artifactory SaaS is not supported by the plugin.
Who approves a waiver, how fast, and for how long? When waivers drag, developers tend to find a way around the gate.
Where does Firewall Cloud store logs and decisions? Sonatype does not document the region — get it in writing, or self-host.
Sonatype’s malware counts are its own research. Will the pilot measure blocks on your real traffic instead?
Match your registry and formats to the right edition, price Pro against the self-hosted quote, or let a TechBag advisor pilot it on one proxy repository.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.