← Blog

Hello, and what we're building

Sep 8, 2026 · The Yellow Jack team

Every npm install, pip install, and docker pull reaches past your perimeter and runs third-party code on your developers’ machines and in your builds. Your network firewall never sees it, and a scanner that reports after the fact has already let the code run.

Yellow Jack closes that gap. It’s a package firewall: a deterministic gate that inspects open-source packages at the moment they’re pulled and either allows them through or blocks them, based on a policy you set.

Where we are

We’re early, and we’re building in the open. Yellow Jack runs as a container on your own infrastructure and proxies npm, PyPI, Maven and Docker/OCI: point your package manager at it, and every package — including transitive dependencies — passes through the same checkpoint.

What’s next

  • Write-ups here on real-world supply-chain attacks and what would have stopped them.
  • A clear, public view of our roadmap as it firms up.

If you’d like to follow along or get in touch, email vineet@yellowjack.io.