Malware
4 tutorials in this category.
01
Known-malicious blocks
Why Chainsaw blocks known-malicious package installs at the proxy before policy evaluation, what data backs the gate, and the supported false-positive path.
01
How to Detect Known Malware in Your Supply Chain
Understand Chainsaw's malware index powered by OpenSSF data, review malware detections, and configure automatic blocking of malicious packages.
04
How to Block Malicious and Typosquatted Packages at Install Time with the Chainsaw CLI
Run npm, pip, or go through the free Chainsaw CLI so malicious and typosquatted packages are refused before they enter your build — entirely on your machine, no server, nothing leaves the box.
09
How to Scan Container Image Layers and the Docker Malware Feed
Catch vulnerabilities hidden beneath a clean manifest with per-layer Trivy scanning, and close the OpenSSF index gap for containers with the Docker-specific feed.