Advisories
Published malware, refused locally
Every package is checked against published malware advisories — the OpenSSF Malicious Packages data, via OSV — held on your own server and consulted before any network call is made.
npm and PyPI in practice — public advisories barely cover Maven or Docker
Yellow Jack