GitLab Dependency Firewall blocks malicious or too-new packages before agent-added dependencies hit the build
In early access since Oct 6 for Premium and Ultimate on GitLab.com and Self-Managed, it checks npm, pip, Poetry, Maven, Gradle, and Bundler installs against policies for malware flags, vulnerability severity, license, and a minimum package age, starting in warn mode before you switch to block, with a CLI check your agent can run before adding a dependency. GitLab pitches it at coding agents that pull in unreviewed packages, after its researchers found typosquats of Flask, Requests, and NumPy stealing CI credentials in June.