Back to the registry
Agent passport

Artifact Firewall - Pro (50 users)

Varnish Software AB · Cybersecurity & IT

No attestation published

Certification per AWS Marketplace.

Provenance reach4 of 12 layers traced

Evidence tier Source Confirmed · 4 captures on record

User ratingNot rated0 reviews on the listing
Runs onUnknownSaaS
ProvenanceUnknown44% of the provenance layers this product can disclose
Evidence riskHighSign in to see the basis for this band.

What the publisher says

As described on AWS Marketplace.

Modern software delivery has fundamentally changed. Today's engineering organizations pull thousands of packages automatically, across dozens of CI/CD pipelines, running continuously across distributed Kubernetes clusters and GPU-driven AI environments. The velocity that makes this possible is also what makes it dangerous. Supply chain attacks have grown in both frequency and sophistication, not because attackers have become more sophisticated, but because they have learned to exploit the trust and automation that modern development depends on. A compromised package published to a public registry can propagate into hundreds of production environments within minutes, before any human has had a chance to review it. Varnish Artifact Firewall is built for this environment. It is a dedicated runtime security layer that sits in the artifact request path and evaluates every dependency before it enters your infrastructure whether that request originates from a developer workstation, a CI/CD pipeline, a Kubernetes cluster, or an AI training job. Unlike traditional repository-based scanners that evaluate artifacts after ingestion, Varnish Artifact Firewall enforces security policy at the moment of request, before known vulnerable or non-compliant artifacts are allowed to propagate. Newly published and unknown threats can be held in quarantine long enough for the community to flag malicious uploads. It can also be deployed alongside Varnish Virtual Registry, to combine policy enforcement with high-performance artifact caching and routing to dramatically reduce artifact latency and dependency resolution time.

Highlights

Highlighted by the publisher on AWS Marketplace.

Secure the platform: Enforce runtime security across your entire software supply chain: block known vulnerable or compromised packages, quarantine newly published versions until they can be reviewed, and prevent dependency confusion attacks, governing every artifact request before it reaches your environment.

Vendor-neutral by design: Varnish Artifact Firewall sits in front of the registries and repository managers you already run, with no lock-in to a backend platform and no changes to developer workflow. Secure your entire software supply chain, regardless of your existing architecture and vendors.

Policy as code, zero-risk rollout: Manage dependency policy as declarative YAML rulesets, versioned and distributed through Git. Prebuilt OSV.dev rules give you a maintained baseline to extend with your own policies, and rulesets reload at runtime without service interruption. Start in report mode to see exactly what would have been blocked before enforcing anything, then deploy as a Docker image, Helm chart, or Linux package.

Agent build and provenance

See the full provenance

The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.

Plans and pricing as listed

1 listed
Active Developers
  • Units
$20,000.00
P12M

Refund terms

As stated by the publisher on AWS Marketplace.

All fees are non-cancellable and non-refundable except as required by law.

Sources

Marketplace listingaws.amazon.comSource
App certificationaws.amazon.comSource
StandardEulaStandardEulaSource

Linked repositories

RepositoriesUnknownUnknown

Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.

Pricing
Paid
1 plan listed
Delivery
SaaS
Varnish Virtual Registry Pro includes Standard Support which includes: * Up to 20 support requests per year * Availability during business hours (8 am to 5 pm) * Email support, with telephone support for critical issues Access to the Varnish knowledgebase and software repositories Support reviews and on-site consultancy are available as paid options. Premium Support, with 24/7/365 availability, unlimited support requests, faster response times, and guaranteed SLAs for critical issues, is available as an add-on or as part of the Enterprise tier.
Open the source listing ↗

Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.