BlogPartners

Block the packages you can't trust.

NetRise Provenance® blocks malicious and policy-violating packages wherever they're pulled — editor, CLI, CI/CD, and AI coding assistants — and maps how far any risk reaches.

Other tools list your dependencies. Provenance stops the dangerous ones.

A dependency graph shows you the components you rely on. Provenance blocks malicious and policy-violating packages before they're installed — in the editor, the CLI, CI/CD, and AI coding assistants.

The Problem

When a package turns, how far does it spread?

A malicious version ships, a dependency is compromised, or a trusted package turns risky. Most teams can't answer the first question that matters: how far did it propagate into what we build, buy, and run?

Software Builders:

By the time a CVE is assigned, the compromised package has already resolved into your builds — and everything downstream of them.

Software Buyers:

You inherit that package through vendor software too, and their attestation won't tell you you're exposed.

The Gap

Seeing it isn't stopping it.

Packages get pulled constantly — by developers, CI/CD jobs, and AI assistants installing on their own — with no policy check in between. SCA scanners and dependency graphs can't stop a malicious package from resolving into your build.

Software Builders:

An AI assistant will happily install a package no one vetted — and by the time a CVE is assigned, it's already in your build, with nothing to block it.

Software Buyers:

A clean scan says nothing about a decaying repo or an anonymous maintainer, and gives you no way to act on it.

The Solution

Trust enforced, Never assumed.

Provenance enforces one trust standard wherever a package enters — scoring each on maintainer, origin, and repository facts, and stopping those that fail before they reach your build. When something does turn risky, you already know how far it reached and who's accountable.

Software Builders:

Package trust enforced where packages get pulled — editor, command line, CI/CD. Including AI coding assistants, which will happily install a package no one vetted.

Software Buyers:

Assess vendor software on maintainer and repository facts, not vendor self-attestation.

Ready to See Your Real Risk?

Featured Solutions

Where Provenance Fits in Your Workflows

One judgment about a dependency carries across three programs: tracing how far a compromised package reaches, securing the software your organization builds and buys, and keeping risky packages out of what you ship.

Blind Trust in Open Source Software? Not Anymore.

Provenance Intelligence

When a package turns, the damage rarely stops at one product. Provenance traces how far it reaches, and back to the maintainers and organizations behind it.

Learn more
How Do you Secure Software Your Team Didn't Write

Software Supply Chain Security

Open-source enters whether your organization builds software or buys it. Provenance holds every dependency to one trust standard, wherever it came from.

Learn more
Product Security

Product Security

A release goes out under your name whether or not you know what's in it. Turbine confirms what the build compiled, and what to fix first.

Learn more

PRODUCT FEATURES

From Upstream Maintainer to Your Product

Provenance works from the open-source ecosystem itself, so one standard follows a dependency from the repository it came from to the products it ends up in.

  • Blast Radius

    When a component is compromised, map how far it reaches — which dependencies inherit it, and which of your products contain it — so you scope impact in minutes.

  • Malicious Package Detection & Blocking

    Catch malicious packages as they publish, and block what fails — in the editor, the command line, CI/CD, and when an AI assistant runs the install.

  • Package Firewall Manager

    Enforce one trust standard on every dependency — sanctions, geography, repository posture, maintenance thresholds — flagging policy violations at intake and in CI/CD, even when nothing's malicious yet.

  • Repository Health & Security Signals

    Surface repository hygiene, activity, and maintainer churn to flag fragile or declining dependencies before they become a liability. A clean CVE scan isn't a healthy dependency.

  • Contributor & Organization Attribution

    Identify the contributors, organizations, and regions behind the components you inherit — replacing vendor claims and manual investigation with evidence.

  • Advisory Impact Analysis

    Search a published advisory and see your exposure directly — the contributors, packages, and repositories it touches, direct and transitive, without tracing it by hand.

Provenance Works Before and After a Compromise

Before a compromiseAfter a compromise
The questionCan we trust this dependency?Did it reach us — and how far?
What Provenance doesScores each dependency and enforces one trust standard before it reaches your buildMaps how far a compromised component spread across your products and assets — in minutes
The outcomeRisky packages caught before they reach your buildIncident scoped in minutes, not days

Stop risky packages. Scope the rest.

See how Provenance blocks malicious and policy-violating packages before they reach your build — and maps how far any risk reaches when a dependency turns malicious.

Frequently Asked Questions

What is software supply chain provenance?

Software supply chain provenance is the origin and history of the components inside your software — who wrote each dependency, which project maintains it, and where it came from. NetRise Provenance maps every dependency back to its source, so a name in your manifest becomes a trust decision you can defend.

What is malicious package detection?

Malicious package detection identifies dependencies that are actively harmful — typosquats, compromised releases, and packages that turn malicious after publishing. NetRise Provenance evaluates packages as they publish to public registries and flags what fails, in the editor, the command line, CI/CD, and when an AI coding assistant runs the install.

What is a package firewall?

A package firewall enforces trust policy on every dependency before it enters your build. NetRise Provenance's Package Firewall Manager evaluates each package against your standards — sanctions, geography, repository posture, maintenance thresholds — and flags or blocks policy violations at intake and in CI/CD, even when a package isn't malicious.

How do you assess open-source repository health?

Repository health measures whether the project behind a dependency is sound — its activity, maintainer concentration, security posture, and hygiene. NetRise Provenance surfaces these signals to flag fragile or declining dependencies before they become a liability. A clean CVE scan is not the same as a healthy dependency.

How far does a compromised dependency reach?

When a package or maintainer is compromised, the risk propagates through every component that inherits it. NetRise Provenance maps that reach — the dependencies that carry the compromised component, and which of your products and assets contain them — so you can scope impact in minutes instead of days.

Who maintains the open-source components in my software?

Most open-source dependencies are maintained by contributors you've never vetted. NetRise Provenance identifies the contributors, organizations, and regions behind the components you inherit, so you can judge whether the people responsible for your code are trustworthy — replacing vendor claims with evidence.

How does Provenance secure packages installed by AI coding assistants?

AI coding assistants install packages on machines no one treated as a build environment. NetRise Provenance enforces the same trust policy wherever a dependency enters — including when an AI assistant runs the install — so agent-pulled packages meet the same standard a person's would.