Install Safe Chain
Get up and running in under a minute with a single install command
How it works
Learn how the proxy intercepts package downloads and detects threats
Configure
Tune logging, package age thresholds, and custom registries
Use in CI/CD
Protect GitHub Actions, GitLab, CircleCI, Jenkins, and more
Supported package managers
Safe Chain protects all major JavaScript and Python package managers:JavaScript / Node.js
npm, npx, yarn, pnpm, pnpx, bun, bunx
Python
pip, pip3, uv, poetry, pipx, python, python3
Key features
Real-time malware detection
Packages are checked against Aikido Intel threat intelligence before they reach your machine
Minimum package age
Newly published packages (under 48 hours old by default) are blocked during the highest-risk window
Shell integration
Works transparently with bash, zsh, fish, PowerShell, and PowerShell Core — no changes to your workflow
Private registry support
Scan packages from custom or private npm and PyPI registries