GitLab’s Dependency Firewall is designed to stop malicious, vulnerable, and non-compliant packages before they are installed in a build.
Attackers can disguise malicious packages as trusted ones, and in June 2026 GitLab researchers identified five malicious PyPI packages, four of which were typosquats of Flask, Requests, and NumPy, that could run at install time and steal CI/CD credentials.
With this early-access feature, teams can enforce policy-driven controls at install time rather than chasing issues after a pipeline runs.
WHAT THE POLICY BLOCKS AND HOW IT WORKS
Policies can flag packages by malicious status, set minimum required vulnerability severities, control allowed licenses by full name, and specify minimum ages for packages. TechStaged has also covered GitLab Artifact Central brings organization-level artifact governance to beta, consolidating hundreds of project registries.
Two operational modes exist: warn, which logs potential matches and lets builds proceed, and block, which stops the pipeline on a match. A bypass option allows approved exceptions.
Policies can be defined at the top-level group and inherited by projects, with registry-level enforcement to ensure every pull is checked.
- Malicious status
- Vulnerability severity (critical, high, medium, or low) and the number of findings allowed
- License type by full name and handling for indeterminate licenses
- Package age (minimum age before entry)
- Policy inheritance from group to project
- Registry-level enforcement for uniform checks
GOVERNANCE, AUDITING, AND DEVELOPER WORKFLOW
All decisions and outcomes are recorded in an immutable audit trail accessible via the Dependency Firewall dashboard, supporting security reviews and audits.
Without policy enforcement at install time, software composition analysis (SCA) can only flag issues after a package is already pulled into the build, potentially triggering costly rework.
GitLab CLI support lets developers verify whether a package will pass or be blocked, without needing to open a separate console.
Dependency Firewall is compatible with GitLab Artifact Central and external registries, including Sonatype Nexus Repository and JFrog Artifactory.
- Immutable audit events for each decision
- Pre-install blocking to reduce rebuilds
- CLI-based pre-checks for developers
- Compatibility with Artifact Central and external registries
AVAILABILITY AND GETTING STARTED
GitLab Dependency Firewall is in early access for GitLab.com and GitLab Self-Managed customers in the Premium or Ultimate tier.
Organizations can request early access and watch a replay of the Transcend event to see demonstrations and further details.
- Early access on GitLab.com and Self-Managed (Premium/Ultimate)
- Transcend event replay for demonstrations
RELATED COVERAGE
- GitLab Artifact Central brings organization-level artifact governance to beta, consolidating hundreds of project registries
- GitHub Copilot Cloud Agent Adds Planning Before Pull Requests
- Xcode 27 Adds Agentic Coding: What Apple Developers Need to Control
- Stripe Projects Brings “Vibe Deploying” Into a Single Developer Workflow
- Developer Tools articles
SOURCES
- GitLab: Dependency Firewall: Block risky packages before the build Published · Primary source




