Yellow Jack

Your firewall never sees what your developers install.

Yellow Jack does.

Get in touch

Your software supply chain has an open door

Every npm install, pip install, anddocker pull reaches straight past your perimeter and runs third-party code on your developers' machines and in your builds. Your network firewall never sees it, and a scanner that reports after the fact has already let the code run.

A quarantine checkpoint for every package

  1. 01

    Point your package manager at us

    Your developers' npm, PyPI, Maven and Docker clients are configured to fetch through Yellow Jack. It runs as a container on your own infrastructure — not a service you sign up for, and nothing to install on a developer's machine.

  2. 02

    We inspect every package at the moment it's pulled

    Before a package reaches a developer or a build it is checked against your policy: published malware advisories, a release-age cooldown, your own allow and deny lists, and the health of the repository it claims to come from.

  3. 03

    Allow or block — deterministically

    Trusted packages stream straight through. Risky ones are stopped with a clear reason. Every dependency, including transitive ones, passes through the same gate.

It runs where your code does

Yellow Jack runs entirely on your own infrastructure. Every address it connects to comes from your configuration — the registry you point it at, the scanner you choose. None of them is ours.

So there is no vendor dashboard holding a copy of your dependency list, and no meter on your traffic: we do not receive that data, because nothing is sent to us. It is asserted by a test that fails the build, not promised in a policy document.

It complements the tools your team already runs — no registry to rip out, nothing to migrate.

The team

Building Yellow Jack, with Georgia Tech roots.

  • Vineet

    Vineet

    AI Engineering

  • D

    Dylan

    DevOps Engineering

Building in the open

Yellow Jack is in active development. We'll be sharing progress — and write-ups on real-world supply-chain attacks — on our blog soon.

To follow our progress or get in touch, emailvineet@yellowjack.io.