Features
Real-time supply chain defense with actionable intelligence
ShieldedStack combines a package proxy, continuous vulnerability intelligence, and a collaborative security console. It enforces policy before vulnerable package versions reach your repositories and gives security and engineering teams the context to respond.
New triage controls
Reduce noise without losing policy control
Workspace-level controls let teams tune repeated vulnerability signals and document narrowly scoped risk decisions.
Alert cooldown
Choose how many days ShieldedStack waits before signaling the same advisory for the same package version again. Set the workspace cooldown to 0 when every observation should signal.
Vulnerability exceptions
Accept one advisory for one exact package version. While active, the exception suppresses matching alerts and excludes that vulnerability from severity-based proxy blocking.
Secure Package Proxy
A drop-in proxy for 10 package ecosystems that sits between developers and package registries, enforcing security policy without breaking package-manager workflows.
- Registry-compatible operation with no developer tooling changes required.
- Low-latency package delivery with intelligent caching inside your own deployment.
- Complete audit trails and real-time telemetry for every package request.
- Automatic vulnerability scanning against the CVE database on every package install attempt.
Proxy Modes: Trust-Then-Verify & Verify-Then-Trust
Choose the security posture that matches your risk tolerance and development velocity.
Trust-Then-Verify
Allow packages through immediately while scanning in the background. This mode provides visibility without blocking the initial workflow.
Alerts are raised after download if vulnerabilities are discovered.
Verify-Then-Trust
Block packages until they pass security validation, querying vulnerability and license metadata inline for unknown versions.
Only packages that meet policy requirements are allowed through the proxy.
Package Download Traceability
When a vulnerability is disclosed after a package was allowed through, ShieldedStack helps answer the urgent question: where did this package version actually go?
- Trace allowed and blocked requests by timestamp, ecosystem, package, version, project, API key, and correlation ID.
- Identify the environments, CI runners, gateways, or service users that pulled a vulnerable package version.
- Capture trusted context added by F5, NGINX, Envoy, HAProxy, ingress controllers, or internal platform proxies.
- Use metadata headers such as
ShieldedStack-Source,ShieldedStack-Environment,ShieldedStack-User, andX-Forwarded-Forto narrow the blast radius. - Filter by package, version, project, event type, correlation ID, context key, or context value.

Policy Engine
Define which packages are allowed, blocked, or require additional scrutiny for each workspace. The checks run in a fixed order and the first verdict wins: allow list, deny list, vulnerability threshold, license policy, release age, and finally the proxy mode. Every decision is written to the request log with the reason it was reached.
- Allow and deny lists: Explicit package rules that override default policies. An allow-list match permits the install regardless of the checks that follow, so an explicit allow is the strongest statement you can make about a package.
- Closed catalogue mode: Require an allow-list match and everything outside the list is blocked, for regulated or air-gapped environments where the approved set defines what exists.
- Severity or CVSS thresholds: Block on a minimum severity, or switch to CVSS and block at or above a score from 0 to 10, with a severity fallback that applies only to advisories carrying no valid score.
- License enforcement: Deny SPDX identifiers and the proxy evaluates the whole expression, so
MIT OR GPL-3.0-onlystays available whileMIT AND GPL-3.0-onlyis blocked. Deprecated identifiers are matched against their current spelling, and identifier families such as BSD select in bulk. - Package release grace period: Require new package versions to age for a configurable period before allowing installation.
- Unresolved license evidence: When a license cannot be resolved for the exact version requested, Trust-Then-Verify allows the install pending collection and Verify-Then-Trust blocks it. A known denied license blocks in either mode.
- Vulnerability exceptions: Accept a specific advisory for an exact package version. Active exceptions are excluded from severity, CVSS, and fallback blocking, and suppress matching alerts, while license and release-age policy continue to apply.
- Controlled lifecycle: Add a reason and optional expiration, then revoke an exception without removing its history.

Package Filter Rules & Policy Portability
Allow and deny rules live in one searchable table per workspace, with an action column, ecosystem and status filters, and a banner stating which lists are currently enforced. Rules and enforcement are independent, so a rule set can be written or imported, reviewed in place, and switched on once it reads the way you intended.
- Glob patterns per ecosystem: Match a single package, a scope with
@scope/*, a group prefix withcom.example.*, or the whole ecosystem with*. A catch-all has to be confirmed explicitly. - Version ranges you already know: Write comparators, caret and tilde ranges, or NuGet bracket notation. A saved rule reads back as comparators, and the displayed form is valid input to paste straight back in.
- Reasons and expiry: Record why a rule exists and when it should stop applying. Expired rules stop being enforced, stay listed for review, and can be filtered to and removed together.
- Predictable precedence: Within each list, exact matches are checked first, then wildcards from most specific to least. Precedence comes from the rules themselves, not from the order they were created in.
- Check a package before you trust it: Enter an ecosystem, package, and optional version to see which rule decides it and why, evaluated exactly the way a real request is. The check downloads nothing, changes nothing, and records nothing.
- Import and export: Move a reviewed rule set between workspaces as JSON, in merge, replace, or validate mode. Imports are all-or-nothing, and validate reports every problem while changing nothing.
- Risk acceptance stays where it was reviewed: Vulnerability exceptions are never carried by an import or export, so accepting an advisory in one environment never accepts it in another.
Package Scanner
A standalone console application for discovering dependencies in deployed systems, CI/CD pipelines, or environments that cannot use the proxy.
- Scan project directories, lock files, and package manifests to inventory dependencies.
- Run on demand or schedule scans for continuous monitoring of production systems.
- Use it in air-gapped environments or alongside the proxy for broader coverage.
- Report findings to the ShieldedStack console for centralized visibility.
- Support the same 10 package ecosystems as the proxy.
Real-Time CVE Alerts
Continuous vulnerability intelligence monitors your dependency inventory and raises alerts when new advisories affect package versions in use.
- Event-driven enrichment updates package intelligence after new vulnerability disclosures.
- An aggregated alert feed surfaces CVEs affecting your inventory in one prioritized view.
- Severity filtering and acknowledgement workflows support security triage.
- Workspace alert cooldown: Wait from 0 to 365 days before signaling the same advisory for the same package version again. A value of 0 disables the cooldown.
- Affected versions, first patched versions, plain-language guidance, and ecosystem-specific upgrade commands support remediation.

License Change Detection
Track license changes across package versions to catch compliance risks before they affect your organization.
- Automatic detection when packages change licenses between versions.
- Alerts for transitions to restrictive or incompatible licenses.
- SPDX-based license intelligence mapped to business-friendly risk categories.
- Historical license tracking for audit and compliance reporting.
- Denied SPDX identifiers are enforced at install time by the policy engine, so a restrictive license blocks the package rather than only raising an alert.
Notification Channels
Route alerts from ShieldedStack into your team's existing workflows.
- Microsoft Teams: Send CVE alerts, license changes, and policy violations to dedicated channels.
- Slack: Post the same alerts into a Slack channel, laid out with severity, advisory, and the version that fixes it.
- PagerDuty: Raise an incident against the service that pages your on-call, with repeat alerts for one advisory grouped onto the open incident.
- Webhooks: Call other systems when ShieldedStack dispatches a notification.
- Configure multiple channels per workspace with independent filtering rules.
- Include severity, affected packages, and direct console links in notification messages.

Data Export & SBOM Generation
Export dependency inventories and Software Bills of Materials for compliance, governance, and incident response.
- SBOM export in CycloneDX format, per project or for every project at once.
- CSV and JSON exports for custom reporting and GRC integrations.
- Vulnerability reports with advisory details, severity ratings, and affected package versions.
- License data and risk classification included in package exports and the license inventory.
Risk Scoring & Intelligence
A context-aware risk engine quantifies package safety across security, compliance, and maintainability dimensions.
- A unified 0-10 risk score blends vulnerability severity, version age, license posture, and maintenance signals.
- Security, compliance, and maintainability dimensions help teams identify remediation priorities.
- Repository health metrics highlight engineering maturity and maintenance risks.
- Advisory collection from GitHub Security Advisories and OSV feeds continuous vulnerability intelligence.
- Interactive dashboards surface risky, outdated, and newly vulnerable packages.

MCP Server for AI Security Assistants
Connect AI coding agents and security assistants to ShieldedStack through a read-only Model Context Protocol server with workspace-scoped dependency and vulnerability intelligence.
- Query which projects use a package, where high or critical CVEs exist, or which dependencies rank highest by risk score.
- Use read-only tools for vulnerability search, risky package ranking, outdated package discovery, and project inventory lookup.
- Connect over Streamable HTTP at
/mcpwith bearer API-key authentication. - Use dedicated, workspace-scoped API keys for broad analysis with clear access boundaries.
- Prevent repository edits, policy changes, alert acknowledgements, and package-manager configuration changes through MCP tools.
Collaborative Security Console
A centralized workspace aligns security, platform, and development teams around shared dependency intelligence.
- Unified package inventory with CVE status and license posture.
- Self-service policy management for filters, severity and CVSS gates, denied licenses, grace periods, cooldowns, and vulnerability exceptions.
- Granular API key rotation and environment-specific access controls.
- Shared dependency-risk visibility for security analysts, platform engineers, and application developers.
- Guided onboarding and package-manager connection instructions.