New threat. Already matched.
Cordon reads every new release as it is published, signs what it confirms into a feed every scanner pulls, and checks everything you already run. No rescan, no waiting for the next build.
- 01PublishedA release lands on npm, PyPI, crates, RubyGems, NuGet, Go or Maven.
- 02ReadThe watcher reads it as it lands; what static reading cannot settle is detonated in a sandbox.
- 03SignedA confirmed verdict enters the feed as a signed, serial-numbered delta.
- 04MatchedEvery organisation's stored inventory is checked at once. No rescan.
- 05RefusedFirewalls refuse the install, owners hear in chat, pagers and trackers.
npm
PyPI
Cargo
RubyGems
NuGet
Go
Maven
Read as it is published, signed within seconds.
A malicious release is most dangerous in its first hours, before any advisory exists. The watcher reads every release the moment it lands, detonates what reading cannot settle, and publishes what it confirms, so the second install anywhere is refused.
More than a list of bad names.
The intel answers the questions an attacker counts on nobody asking: would this range install the bad release, is the package itself recorded, did anything change since the version you trusted.
Every feed worth having, merged once.
Records arriving from more than one source are kept once, and a record its publisher withdrew is gone from the next delta.
Fresh by default, and it says nothing about you.
Asking a service about your dependencies tells it what you run. The feed works the other way round: everyone pulls the same signed files, and every match happens on your side.
New intel, checked against everything you already run.
Every complete scan leaves an inventory behind. When a package is flagged, Cordon finds it in your repositories, images and repository-manager caches within minutes, with no rescan, and names who owns each.
cordon-scanner scan .cordon-scanner scan . --offlinecordon-scanner scan . --online