Create and test a firewall
Use Package Firewall to detect and block harmful open-source packages, vulnerabilities, malware, and policy violations to stop threats before they reach your development pipelines.
Create a firewall
Create a firewall to block harmful open source packages.
Before you begin:
- You must have a Veracode account in the Commercial region with the Policy Administrator or Security Lead role. Package Firewall currently doesn't support accounts in the United States Federal region.
To complete this task:
- Sign in to the Veracode Platform.
- Select Policies > Firewall.
- Select NEW FIREWALL.
- Add a name for the firewall, then select ADD FIREWALL.
- To test the firewall and verify it is working correctly, use demo packages.
Test the firewall
To test the firewall, use the demo packages available for supported ecosystems. These packages are intentionally marked as malicious and help you verify firewall behavior without introducing risk.
To avoid security risks, don't test the firewall with actual malicious packages, which can introduce security vulnerabilities and cause problems, such as data loss or unreliable test results. To test safely, use the provided demo packages for controlled validation.
To validate firewall behavior, create a new firewall and install a demo package. The installation should fail because the firewall blocks the package by default.
You can also use the demo packages to test policy changes by adding an exception to the firewall. For example, during customer onboarding, organizations often configure policies to generate warnings instead of blocking packages. In this scenario, installing the demo package should produce a warning instead of blocking the installation.
Demo packages for testing
You can use the following demo packages for testing:
Remove a firewall
Remove firewalls you no longer need.
Before you begin:
- You must have a Veracode account in the Commercial region with the Policy Administrator or Security Lead role. Package Firewall currently doesn't support accounts in the United States Federal region.
To complete this task:
- Sign in to the Veracode Platform.
- Select Policies > Firewall.
- Locate the firewall you want to remove and select DELETE.
- In the warning dialog that opens, select DELETE.