How to Review and Manage Quarantined Packages

Intermediate 15 minutes Security Engineers Monitoring & Compliance

Understand the quarantine workflow, review flagged packages, approve or reject quarantined items, and transition from quarantine to blocking policies.

Overview

Quarantine is Chainsaw’s middle ground between allowing and blocking. When a policy uses the Quarantine action, the package is still served to the client but flagged for review. This lets security teams evaluate potentially risky packages without disrupting developer workflows — then make an informed decision to allow or block.

Prerequisites

  • At least one policy with Quarantine action configured
  • Manager role or above

Step 1: Understand Quarantine vs Block vs Allow

ActionPackage Served?Developer ImpactSecurity Team Action
AllowYesNoneNo review needed
QuarantineYes (flagged)None (transparent)Review required
BlockNoInstall failsException needed to override
Quarantine vs block comparison
Quarantine flags packages for review without disrupting developers
Quarantine is ideal when rolling out new policies. Start with Quarantine to measure impact, then switch to Block once you’re confident in the policy’s accuracy.

Step 2: Create a Quarantine Policy

Navigate to Policies and create a policy with the Quarantine action:

  1. Name: Quarantine Medium-Risk Packages
  2. Action: Quarantine
  3. Condition: Trust Score between 30 and 60
  4. Scope: All repositories
Creating a quarantine policy
Set the action to Quarantine to flag packages without blocking them

Common Quarantine Scenarios

PolicyConditionRationale
New packagesAge < 14 daysReview before broad adoption
Unknown licensesLicense = emptyLegal review needed
Moderate trust scoreScore 30-60Risk assessment needed
Missing provenanceProvenance = missing (npm/PyPI)Verify package source
Suspected typosquatsTyposquat = suspectedName verification needed

Step 3: Identify Quarantined Packages

From the Dashboard

Quarantined requests appear in the violation metrics with a flagged outcome (distinct from blocked).

Flagged items on the dashboard
Quarantined packages appear as flagged items in the dashboard metrics

From the Traffic Page

Filter the Traffic page by outcome = flagged to see all quarantined requests:

Traffic filtered by flagged outcome
Filter traffic to see only quarantined/flagged package requests

From the Bill of Materials

In the BOM, check the Last Outcome column for flagged entries.

BOM showing flagged packages
Flagged packages in the BOM indicate quarantined items awaiting review

Step 4: Review a Quarantined Package

For each quarantined package, review:

  1. Why it was quarantined — Check which policy condition triggered
  2. Trust score breakdown — What signals are concerning?
  3. Package details — License, provenance, age, vulnerability status
  4. Usage context — Who requested it and from which pipeline?
Reviewing quarantined package details
Review all available signals before making a decision

Decision Matrix

FindingAction
Legitimate package, false positiveCreate an Allow exception
Suspicious but no evidence of maliceKeep quarantined, monitor
Confirmed riskUpgrade to Block policy
MaliciousBlock immediately, purge from cache

Step 5: Approve a Quarantined Package

If the package passes review, create an exception to clear it:

  1. Navigate to Policies
  2. Create an Allow policy for the specific package
  3. Set appropriate precedence (above the quarantine policy)
  4. Optionally set an expiry for periodic re-review
Creating an allow exception for a quarantined package
Approve a quarantined package by creating an Allow exception

Step 6: Reject a Quarantined Package

If the package fails review, escalate from quarantine to block:

  1. Create a Block policy for the specific package (or version range)
  2. Set high precedence to override the quarantine
  3. Notify teams that the package is now blocked
  4. Purge the package from cache if already downloaded
Escalating a quarantined package to blocked
Block a quarantined package that fails security review

Step 7: Transition from Quarantine to Block

As you build confidence in a policy, transition from Quarantine to Block:

Staged Rollout

  1. Week 1-2: Deploy policy with Quarantine action
  2. Week 2-3: Review all quarantined packages, create exceptions for false positives
  3. Week 3-4: Switch to Block action
  4. Ongoing: Monitor violations, adjust exceptions as needed
Staged rollout from quarantine to block
Transition gradually from quarantine to blocking
Track your false positive rate during the quarantine phase. If more than 20% of quarantined packages are approved, the policy conditions may be too aggressive.

Step 8: Use Billy to Manage Quarantine Review

Ask Billy to help triage quarantined packages:

"Show me all packages flagged by quarantine policies this week"
"What's the trust score breakdown for packages with flagged outcomes?"
"Which quarantined packages have been requested by more than 3 clients?"
Billy helping with quarantine review
Use Billy to prioritize quarantine reviews

Best Practices

PracticeReason
Start new policies in QuarantineMeasure impact before blocking
Set a review cadenceDon’t let quarantined items pile up
Track false positive rateTune policies based on data
Document review decisionsAudit trail for compliance
Automate where possibleUse trust score thresholds to auto-approve high-trust packages

Next Steps