{"id":986978,"date":"2026-07-30T06:05:22","date_gmt":"2026-07-30T10:05:22","guid":{"rendered":"https:\/\/www.marketnewsdesk.com\/index.php\/netrise-extends-provenance-to-developer-workflows-stopping-malicious-packages-before-they-reach-the-build-pipeline\/"},"modified":"2026-07-30T06:05:22","modified_gmt":"2026-07-30T10:05:22","slug":"netrise-extends-provenance-to-developer-workflows-stopping-malicious-packages-before-they-reach-the-build-pipeline","status":"publish","type":"post","link":"https:\/\/www.marketnewsdesk.com\/index.php\/netrise-extends-provenance-to-developer-workflows-stopping-malicious-packages-before-they-reach-the-build-pipeline\/","title":{"rendered":"NetRise Extends Provenance to Developer Workflows, Stopping Malicious Packages Before They Reach The Build Pipeline"},"content":{"rendered":"<div class=\"xn-newslines\">\n<p class=\"xn-distributor\">PR Newswire<\/p>\n<\/p><\/div>\n<div class=\"xn-content\">\n<p>\n        <i>New Package Firewall CLI, VS Code extension, and AI coding assistant plugins enforce package trust before malicious or policy-violating dependencies are installed.<\/i>\n      <\/p>\n<p>\n        <span class=\"legendSpanClass\">AUSTIN, Texas<\/span>, <span class=\"legendSpanClass\">July 30, 2026<\/span> \/PRNewswire\/ &#8212; <a href=\"https:\/\/edge.prnewswire.com\/c\/link\/?t=0&amp;l=en&amp;o=4739759-1&amp;h=470634387&amp;u=https%3A%2F%2Fwww.netrise.io%2F&amp;a=NetRise\" target=\"_blank\" rel=\"nofollow\">NetRise<\/a><a href=\"https:\/\/edge.prnewswire.com\/c\/link\/?t=0&amp;l=en&amp;o=4739759-1&amp;h=4167814176&amp;u=https%3A%2F%2Fwww.netrise.io%2F&amp;a=%C2%AE\" target=\"_blank\" rel=\"nofollow\"><sup>\u00ae<\/sup><\/a>, the software supply chain security company that exists to eliminate blind trust in software, today announced enhancements to NetRise Provenance<sup>\u00ae<\/sup>, bringing package trust enforcement into the developer workflow via Visual Studio Code, the command line, and AI coding assistants. The release enables organizations to detect and block malicious or policy-violating open source packages before they enter software projects.<\/p>\n<div class=\"PRN_ImbeddedAssetReference\" id=\"DivAssetPlaceHolder1\">\n<p>\n          <img decoding=\"async\" src=\"https:\/\/mmx.prnewswire.com\/media\/MS1476765\/New-NetRise-Logo-Horz-RGB-Blk-2024-Logo.jpg?id=OA2796112\" title=\"2024 NetRise Logo\" alt=\"2024 NetRise Logo\" \/>\n        <\/p>\n<\/p><\/div>\n<p>The release introduces three new enforcement mechanisms that extend Provenance&#8217;s package trust decisions across developer workflows:<\/p>\n<ul type=\"disc\">\n<li>\n          <b>Provenance Package Firewall CLI:<\/b>\u00a0Enforces organizational policy at package install time in the command line interface (CLI), blocking malicious or non-compliant packages before they are downloaded.<\/li>\n<li>\n          <b>Provenance Extension for Visual Studio Code:<\/b>\u00a0Evaluates dependency manifests as developers write them, identifying malicious or non-compliant packages directly in the editor with contextual guidance and one-click remediation.<\/li>\n<li>\n          <b>AI Coding Assistant Plugins:<\/b>\u00a0Extends Provenance enforcement to AI coding assistants, including Claude Code, Gemini, and Codex, applying the same package trust decisions and policy enforcement to AI-initiated dependency installs.<\/li>\n<\/ul>\n<p>Modern software supply chain attacks, such as the recent LiteLLM and Axios compromises, share similar characteristics: a package or one of its dependencies is compromised. The malicious release stays published and is pulled into every project that requests it, until it is detected. Each compromise was quickly discovered and fixed, with the window of exposure being merely hours.\u00a0<\/p>\n<p>&#8220;The problem is everything that happens while it&#8217;s still up,&#8221; said Michael Scott, Co-Founder and CTO of NetRise. &#8220;Builds run, releases go out, containers deploy, all automatically.\u00a0 AI tools pull dependencies into projects for people who aren&#8217;t even developers. By the time an advisory is published and the package is quarantined, the compromised version has already spread.&#8221;\u00a0<\/p>\n<p>&#8220;Provenance is built for that window. It blocks the package at every point of install &#8211; the developer machine, the software and firmware build pipeline, the AI assistant working on a user&#8217;s behalf.\u00a0 It shifts the approach of CISOs and Product Security leaders into one of proactive defense rather than reactive response.\u00a0 When the next attack makes headlines, they have the confidence that the affected packages never got in.&#8221;<\/p>\n<p>The new mechanisms move package trust decisions earlier in the software development lifecycle by evaluating dependencies as they are introduced into a project and enforcing the same policy at install time. A shared policy engine ensures the same trust decision is applied in the editor, at the command line, in AI coding assistants, and in continuous integration (CI).<\/p>\n<p>Developers receive immediate feedback while they edit dependency manifests, including plain-language explanations for flagged packages, one-click remediation, and options to record policy exceptions. The Package Firewall enforces those same decisions during package installation.<\/p>\n<p>&#8220;The oldest problem in cybersecurity isn&#8217;t malicious code\u2014it&#8217;s trusting software before you know where it came from or whether it deserves that trust,&#8221; said Thomas Pace, Co-founder and CEO of NetRise. &#8220;Malicious packages are just the latest example of a much older problem: organizations continue to rely on software and components they haven&#8217;t truly validated. That model has to end. Software should prove its origin, integrity, and lineage before it ever runs, and when something does slip through, you should immediately understand where it came from and everywhere it exists. With Provenance integrated into the developer workflow and Turbine continuously validating software in production, that becomes the foundation of how software is built and trusted.&#8221;<\/p>\n<p>The new enforcement capabilities build on Provenance&#8217;s existing software supply chain intelligence, extending the same package trust decisions from dependency authoring through software delivery. Learn more about NetRise Provenance at <a href=\"https:\/\/edge.prnewswire.com\/c\/link\/?t=0&amp;l=en&amp;o=4739759-1&amp;h=430564398&amp;u=http%3A%2F%2Fnetrise.io%2Fproducts%2Fprovenance&amp;a=netrise.io%2Fproducts%2Fprovenance\" target=\"_blank\" rel=\"nofollow\">netrise.io\/products\/provenance<\/a>.<\/p>\n<p>The Provenance Package Firewall CLI, the AI coding assistant plugins, and the Provenance extension for Visual Studio Code are available to Provenance customers, with initial support for the Python (PyPI) ecosystem and additional ecosystems planned.<\/p>\n<p>\n        <b>Resources<\/b>\n      <\/p>\n<ul type=\"disc\">\n<li>Schedule a demo: To see Provenance enforce trust from the editor through the pipeline, request a demo at<a href=\"https:\/\/edge.prnewswire.com\/c\/link\/?t=0&amp;l=en&amp;o=4739759-1&amp;h=2757476882&amp;u=https%3A%2F%2Fwww.netrise.io%2Fdemo-request&amp;a=%C2%A0\" target=\"_blank\" rel=\"nofollow\">\u00a0<\/a><a href=\"https:\/\/edge.prnewswire.com\/c\/link\/?t=0&amp;l=en&amp;o=4739759-1&amp;h=408468447&amp;u=https%3A%2F%2Fwww.netrise.io%2Fdemo-request&amp;a=https%3A%2F%2Fwww.netrise.io%2Fdemo-request\" target=\"_blank\" rel=\"nofollow\">https:\/\/www.netrise.io\/demo-request<\/a>.<\/li>\n<li>For more information about NetRise Provenance, visit:<a href=\"https:\/\/edge.prnewswire.com\/c\/link\/?t=0&amp;l=en&amp;o=4739759-1&amp;h=4239565297&amp;u=https%3A%2F%2Fwww.netrise.io%2Fproducts%2Fprovenance&amp;a=%C2%A0\" target=\"_blank\" rel=\"nofollow\">\u00a0<\/a><a href=\"https:\/\/edge.prnewswire.com\/c\/link\/?t=0&amp;l=en&amp;o=4739759-1&amp;h=2594705919&amp;u=https%3A%2F%2Fwww.netrise.io%2Fproducts%2Fprovenance&amp;a=https%3A%2F%2Fwww.netrise.io%2Fproducts%2Fprovenance\" target=\"_blank\" rel=\"nofollow\">https:\/\/www.netrise.io\/products\/provenance<\/a>.<\/li>\n<li>Meet with us at Black Hat USA 2026: Visit Booth #5547 or schedule a private meeting with the NetRise team: <a href=\"https:\/\/edge.prnewswire.com\/c\/link\/?t=0&amp;l=en&amp;o=4739759-1&amp;h=1301999276&amp;u=https%3A%2F%2Fwww.netrise.io%2Fcompany%2Fevents%2Fnetrise-black-hat-usa-2026&amp;a=https%3A%2F%2Fwww.netrise.io%2Fcompany%2Fevents%2Fnetrise-black-hat-usa-2026\" target=\"_blank\" rel=\"nofollow\">https:\/\/www.netrise.io\/company\/events\/netrise-black-hat-usa-2026<\/a><\/li>\n<\/ul>\n<p>For more information or to request a demonstration, visit netrise.io or contact <a href=\"mailto:info@netrise.io\" target=\"_blank\" rel=\"nofollow\">info@netrise.io<\/a>.<\/p>\n<p>\n        <b>About NetRise<\/b>\n      <\/p>\n<p>NetRise is the software supply chain security company that exists to eliminate blind trust in software forever. By identifying every component in each binary image across firmware, kernels, operating systems, containers, and applications, NetRise exposes the full stack of inherited risk that source-based tools, vendor SBOMs, and questionnaires cannot see. Non-code related risk uncovered includes hidden dependencies, cryptographic artifacts, misconfigurations, secrets, among others. Global enterprises that produce and consume software, including government agencies, rely on NetRise to validate what they ship and what they run. When the software supply chain is compromised by bad actors, NetRise answers the questions, &#8220;how far do these compromises extend?&#8221; and &#8220;where am I exposed?&#8221; enabling rapid identification, prioritization, mitigation, and policy updates, reducing material risk to the business. NetRise has entered into an agreement to be acquired by Accenture (NYSE: ACN), which is also taking a majority investment in Dragos. Upon close of the transactions, NetRise will operate under Dragos.<br \/><a href=\"https:\/\/edge.prnewswire.com\/c\/link\/?t=0&amp;l=en&amp;o=4739759-1&amp;h=4281099900&amp;u=https%3A%2F%2Fwww.netrise.io%2F&amp;a=https%3A%2F%2Fwww.netrise.io\" target=\"_blank\" rel=\"nofollow\">https:\/\/www.netrise.io<\/a><\/p>\n<p>\n        <b>Press &amp; Media Contact<\/b>\n      <\/p>\n<p>Danielle Ostrovsky<br \/>Hi-TouchPR<br \/><a href=\"mailto:Ostrovsky@Hi-TouchPR.com\" target=\"_blank\" rel=\"nofollow\">Ostrovsky@Hi-TouchPR.com<\/a>\u00a0<\/p>\n<p id=\"PURL\">\n        <img loading=\"lazy\" decoding=\"async\" title=\"Cision\" width=\"12\" height=\"12\" alt=\"Cision\" src=\"https:\/\/edge.prnewswire.com\/c\/img\/favicon.png?sn=NE13048&amp;sd=2026-07-30\" \/> View original content to download multimedia:<a id=\"PRNURL\" rel=\"nofollow\" href=\"https:\/\/www.prnewswire.com\/news-releases\/netrise-extends-provenance-to-developer-workflows-stopping-malicious-packages-before-they-reach-the-build-pipeline-302836570.html\" target=\"_blank\">https:\/\/www.prnewswire.com\/news-releases\/netrise-extends-provenance-to-developer-workflows-stopping-malicious-packages-before-they-reach-the-build-pipeline-302836570.html<\/a><\/p>\n<p>SOURCE NetRise<\/p>\n<\/p><\/div>\n<p>    <img decoding=\"async\" alt=\"\" src=\"https:\/\/rt.prnewswire.com\/rt.gif?NewsItemId=NE13048&amp;Transmission_Id=202607300600PR_NEWS_USPR_____NE13048&amp;DateId=20260730\" style=\"border:0px;width:1px;height:1px\" \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>PR Newswire New Package Firewall CLI, VS Code extension, and AI coding assistant plugins enforce package trust before malicious or policy-violating dependencies are installed. AUSTIN, Texas, July 30, 2026 \/PRNewswire\/ &#8212; NetRise\u00ae, the software supply chain security company that exists to eliminate blind trust in software, today announced enhancements to NetRise Provenance\u00ae, bringing package trust enforcement into the developer workflow via Visual Studio Code, the command line, and AI coding assistants. The release enables organizations to detect and block malicious or policy-violating open source packages before they enter software projects. The release introduces three new enforcement mechanisms that extend Provenance&#8217;s package trust decisions across developer workflows: Provenance Package Firewall CLI:\u00a0Enforces organizational policy at package install time in the command line &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/www.marketnewsdesk.com\/index.php\/netrise-extends-provenance-to-developer-workflows-stopping-malicious-packages-before-they-reach-the-build-pipeline\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;NetRise Extends Provenance to Developer Workflows, Stopping Malicious Packages Before They Reach The Build Pipeline&#8221;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[],"class_list":["post-986978","post","type-post","status-publish","format-standard","hentry"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>NetRise Extends Provenance to Developer Workflows, Stopping Malicious Packages Before They Reach The Build Pipeline - Market Newsdesk<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.marketnewsdesk.com\/index.php\/netrise-extends-provenance-to-developer-workflows-stopping-malicious-packages-before-they-reach-the-build-pipeline\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"NetRise Extends Provenance to Developer Workflows, Stopping Malicious Packages Before They Reach The Build Pipeline - Market Newsdesk\" \/>\n<meta property=\"og:description\" content=\"PR Newswire New Package Firewall CLI, VS Code extension, and AI coding assistant plugins enforce package trust before malicious or policy-violating dependencies are installed. AUSTIN, Texas, July 30, 2026 \/PRNewswire\/ &#8212; NetRise\u00ae, the software supply chain security company that exists to eliminate blind trust in software, today announced enhancements to NetRise Provenance\u00ae, bringing package trust enforcement into the developer workflow via Visual Studio Code, the command line, and AI coding assistants. The release enables organizations to detect and block malicious or policy-violating open source packages before they enter software projects. The release introduces three new enforcement mechanisms that extend Provenance&#8217;s package trust decisions across developer workflows: Provenance Package Firewall CLI:\u00a0Enforces organizational policy at package install time in the command line &hellip; Continue reading &quot;NetRise Extends Provenance to Developer Workflows, Stopping Malicious Packages Before They Reach The Build Pipeline&quot;\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.marketnewsdesk.com\/index.php\/netrise-extends-provenance-to-developer-workflows-stopping-malicious-packages-before-they-reach-the-build-pipeline\/\" \/>\n<meta property=\"og:site_name\" content=\"Market Newsdesk\" \/>\n<meta property=\"article:published_time\" content=\"2026-07-30T10:05:22+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/mmx.prnewswire.com\/media\/MS1476765\/New-NetRise-Logo-Horz-RGB-Blk-2024-Logo.jpg?id=OA2796112\" \/>\n<meta name=\"author\" content=\"Newsdesk\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Newsdesk\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.marketnewsdesk.com\\\/index.php\\\/netrise-extends-provenance-to-developer-workflows-stopping-malicious-packages-before-they-reach-the-build-pipeline\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.marketnewsdesk.com\\\/index.php\\\/netrise-extends-provenance-to-developer-workflows-stopping-malicious-packages-before-they-reach-the-build-pipeline\\\/\"},\"author\":{\"name\":\"Newsdesk\",\"@id\":\"https:\\\/\\\/www.marketnewsdesk.com\\\/#\\\/schema\\\/person\\\/482f27a394d4fda80ecb5499e519d979\"},\"headline\":\"NetRise Extends Provenance to Developer Workflows, Stopping Malicious Packages Before They Reach The Build Pipeline\",\"datePublished\":\"2026-07-30T10:05:22+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.marketnewsdesk.com\\\/index.php\\\/netrise-extends-provenance-to-developer-workflows-stopping-malicious-packages-before-they-reach-the-build-pipeline\\\/\"},\"wordCount\":927,\"image\":{\"@id\":\"https:\\\/\\\/www.marketnewsdesk.com\\\/index.php\\\/netrise-extends-provenance-to-developer-workflows-stopping-malicious-packages-before-they-reach-the-build-pipeline\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/mmx.prnewswire.com\\\/media\\\/MS1476765\\\/New-NetRise-Logo-Horz-RGB-Blk-2024-Logo.jpg?id=OA2796112\",\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.marketnewsdesk.com\\\/index.php\\\/netrise-extends-provenance-to-developer-workflows-stopping-malicious-packages-before-they-reach-the-build-pipeline\\\/\",\"url\":\"https:\\\/\\\/www.marketnewsdesk.com\\\/index.php\\\/netrise-extends-provenance-to-developer-workflows-stopping-malicious-packages-before-they-reach-the-build-pipeline\\\/\",\"name\":\"NetRise Extends Provenance to Developer Workflows, Stopping Malicious Packages Before They Reach The Build Pipeline - Market Newsdesk\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.marketnewsdesk.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.marketnewsdesk.com\\\/index.php\\\/netrise-extends-provenance-to-developer-workflows-stopping-malicious-packages-before-they-reach-the-build-pipeline\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.marketnewsdesk.com\\\/index.php\\\/netrise-extends-provenance-to-developer-workflows-stopping-malicious-packages-before-they-reach-the-build-pipeline\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/mmx.prnewswire.com\\\/media\\\/MS1476765\\\/New-NetRise-Logo-Horz-RGB-Blk-2024-Logo.jpg?id=OA2796112\",\"datePublished\":\"2026-07-30T10:05:22+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.marketnewsdesk.com\\\/#\\\/schema\\\/person\\\/482f27a394d4fda80ecb5499e519d979\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.marketnewsdesk.com\\\/index.php\\\/netrise-extends-provenance-to-developer-workflows-stopping-malicious-packages-before-they-reach-the-build-pipeline\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.marketnewsdesk.com\\\/index.php\\\/netrise-extends-provenance-to-developer-workflows-stopping-malicious-packages-before-they-reach-the-build-pipeline\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.marketnewsdesk.com\\\/index.php\\\/netrise-extends-provenance-to-developer-workflows-stopping-malicious-packages-before-they-reach-the-build-pipeline\\\/#primaryimage\",\"url\":\"https:\\\/\\\/mmx.prnewswire.com\\\/media\\\/MS1476765\\\/New-NetRise-Logo-Horz-RGB-Blk-2024-Logo.jpg?id=OA2796112\",\"contentUrl\":\"https:\\\/\\\/mmx.prnewswire.com\\\/media\\\/MS1476765\\\/New-NetRise-Logo-Horz-RGB-Blk-2024-Logo.jpg?id=OA2796112\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.marketnewsdesk.com\\\/index.php\\\/netrise-extends-provenance-to-developer-workflows-stopping-malicious-packages-before-they-reach-the-build-pipeline\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.marketnewsdesk.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"NetRise Extends Provenance to Developer Workflows, Stopping Malicious Packages Before They Reach The Build Pipeline\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.marketnewsdesk.com\\\/#website\",\"url\":\"https:\\\/\\\/www.marketnewsdesk.com\\\/\",\"name\":\"Market Newsdesk\",\"description\":\"Latest Business News in Real Time\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.marketnewsdesk.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.marketnewsdesk.com\\\/#\\\/schema\\\/person\\\/482f27a394d4fda80ecb5499e519d979\",\"name\":\"Newsdesk\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a0d0bd5b0f0ca12a265a459b13169dac35f33776d8501eda5e68844a366f2f46?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a0d0bd5b0f0ca12a265a459b13169dac35f33776d8501eda5e68844a366f2f46?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a0d0bd5b0f0ca12a265a459b13169dac35f33776d8501eda5e68844a366f2f46?s=96&d=mm&r=g\",\"caption\":\"Newsdesk\"},\"url\":\"https:\\\/\\\/www.marketnewsdesk.com\\\/index.php\\\/author\\\/newsdesk\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"NetRise Extends Provenance to Developer Workflows, Stopping Malicious Packages Before They Reach The Build Pipeline - Market Newsdesk","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.marketnewsdesk.com\/index.php\/netrise-extends-provenance-to-developer-workflows-stopping-malicious-packages-before-they-reach-the-build-pipeline\/","og_locale":"en_US","og_type":"article","og_title":"NetRise Extends Provenance to Developer Workflows, Stopping Malicious Packages Before They Reach The Build Pipeline - Market Newsdesk","og_description":"PR Newswire New Package Firewall CLI, VS Code extension, and AI coding assistant plugins enforce package trust before malicious or policy-violating dependencies are installed. AUSTIN, Texas, July 30, 2026 \/PRNewswire\/ &#8212; NetRise\u00ae, the software supply chain security company that exists to eliminate blind trust in software, today announced enhancements to NetRise Provenance\u00ae, bringing package trust enforcement into the developer workflow via Visual Studio Code, the command line, and AI coding assistants. The release enables organizations to detect and block malicious or policy-violating open source packages before they enter software projects. The release introduces three new enforcement mechanisms that extend Provenance&#8217;s package trust decisions across developer workflows: Provenance Package Firewall CLI:\u00a0Enforces organizational policy at package install time in the command line &hellip; Continue reading \"NetRise Extends Provenance to Developer Workflows, Stopping Malicious Packages Before They Reach The Build Pipeline\"","og_url":"https:\/\/www.marketnewsdesk.com\/index.php\/netrise-extends-provenance-to-developer-workflows-stopping-malicious-packages-before-they-reach-the-build-pipeline\/","og_site_name":"Market Newsdesk","article_published_time":"2026-07-30T10:05:22+00:00","og_image":[{"url":"https:\/\/mmx.prnewswire.com\/media\/MS1476765\/New-NetRise-Logo-Horz-RGB-Blk-2024-Logo.jpg?id=OA2796112","type":"","width":"","height":""}],"author":"Newsdesk","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Newsdesk","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.marketnewsdesk.com\/index.php\/netrise-extends-provenance-to-developer-workflows-stopping-malicious-packages-before-they-reach-the-build-pipeline\/#article","isPartOf":{"@id":"https:\/\/www.marketnewsdesk.com\/index.php\/netrise-extends-provenance-to-developer-workflows-stopping-malicious-packages-before-they-reach-the-build-pipeline\/"},"author":{"name":"Newsdesk","@id":"https:\/\/www.marketnewsdesk.com\/#\/schema\/person\/482f27a394d4fda80ecb5499e519d979"},"headline":"NetRise Extends Provenance to Developer Workflows, Stopping Malicious Packages Before They Reach The Build Pipeline","datePublished":"2026-07-30T10:05:22+00:00","mainEntityOfPage":{"@id":"https:\/\/www.marketnewsdesk.com\/index.php\/netrise-extends-provenance-to-developer-workflows-stopping-malicious-packages-before-they-reach-the-build-pipeline\/"},"wordCount":927,"image":{"@id":"https:\/\/www.marketnewsdesk.com\/index.php\/netrise-extends-provenance-to-developer-workflows-stopping-malicious-packages-before-they-reach-the-build-pipeline\/#primaryimage"},"thumbnailUrl":"https:\/\/mmx.prnewswire.com\/media\/MS1476765\/New-NetRise-Logo-Horz-RGB-Blk-2024-Logo.jpg?id=OA2796112","inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.marketnewsdesk.com\/index.php\/netrise-extends-provenance-to-developer-workflows-stopping-malicious-packages-before-they-reach-the-build-pipeline\/","url":"https:\/\/www.marketnewsdesk.com\/index.php\/netrise-extends-provenance-to-developer-workflows-stopping-malicious-packages-before-they-reach-the-build-pipeline\/","name":"NetRise Extends Provenance to Developer Workflows, Stopping Malicious Packages Before They Reach The Build Pipeline - Market Newsdesk","isPartOf":{"@id":"https:\/\/www.marketnewsdesk.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.marketnewsdesk.com\/index.php\/netrise-extends-provenance-to-developer-workflows-stopping-malicious-packages-before-they-reach-the-build-pipeline\/#primaryimage"},"image":{"@id":"https:\/\/www.marketnewsdesk.com\/index.php\/netrise-extends-provenance-to-developer-workflows-stopping-malicious-packages-before-they-reach-the-build-pipeline\/#primaryimage"},"thumbnailUrl":"https:\/\/mmx.prnewswire.com\/media\/MS1476765\/New-NetRise-Logo-Horz-RGB-Blk-2024-Logo.jpg?id=OA2796112","datePublished":"2026-07-30T10:05:22+00:00","author":{"@id":"https:\/\/www.marketnewsdesk.com\/#\/schema\/person\/482f27a394d4fda80ecb5499e519d979"},"breadcrumb":{"@id":"https:\/\/www.marketnewsdesk.com\/index.php\/netrise-extends-provenance-to-developer-workflows-stopping-malicious-packages-before-they-reach-the-build-pipeline\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.marketnewsdesk.com\/index.php\/netrise-extends-provenance-to-developer-workflows-stopping-malicious-packages-before-they-reach-the-build-pipeline\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.marketnewsdesk.com\/index.php\/netrise-extends-provenance-to-developer-workflows-stopping-malicious-packages-before-they-reach-the-build-pipeline\/#primaryimage","url":"https:\/\/mmx.prnewswire.com\/media\/MS1476765\/New-NetRise-Logo-Horz-RGB-Blk-2024-Logo.jpg?id=OA2796112","contentUrl":"https:\/\/mmx.prnewswire.com\/media\/MS1476765\/New-NetRise-Logo-Horz-RGB-Blk-2024-Logo.jpg?id=OA2796112"},{"@type":"BreadcrumbList","@id":"https:\/\/www.marketnewsdesk.com\/index.php\/netrise-extends-provenance-to-developer-workflows-stopping-malicious-packages-before-they-reach-the-build-pipeline\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.marketnewsdesk.com\/"},{"@type":"ListItem","position":2,"name":"NetRise Extends Provenance to Developer Workflows, Stopping Malicious Packages Before They Reach The Build Pipeline"}]},{"@type":"WebSite","@id":"https:\/\/www.marketnewsdesk.com\/#website","url":"https:\/\/www.marketnewsdesk.com\/","name":"Market Newsdesk","description":"Latest Business News in Real Time","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.marketnewsdesk.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.marketnewsdesk.com\/#\/schema\/person\/482f27a394d4fda80ecb5499e519d979","name":"Newsdesk","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/a0d0bd5b0f0ca12a265a459b13169dac35f33776d8501eda5e68844a366f2f46?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/a0d0bd5b0f0ca12a265a459b13169dac35f33776d8501eda5e68844a366f2f46?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a0d0bd5b0f0ca12a265a459b13169dac35f33776d8501eda5e68844a366f2f46?s=96&d=mm&r=g","caption":"Newsdesk"},"url":"https:\/\/www.marketnewsdesk.com\/index.php\/author\/newsdesk\/"}]}},"_links":{"self":[{"href":"https:\/\/www.marketnewsdesk.com\/index.php\/wp-json\/wp\/v2\/posts\/986978","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.marketnewsdesk.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.marketnewsdesk.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.marketnewsdesk.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.marketnewsdesk.com\/index.php\/wp-json\/wp\/v2\/comments?post=986978"}],"version-history":[{"count":0,"href":"https:\/\/www.marketnewsdesk.com\/index.php\/wp-json\/wp\/v2\/posts\/986978\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.marketnewsdesk.com\/index.php\/wp-json\/wp\/v2\/media?parent=986978"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.marketnewsdesk.com\/index.php\/wp-json\/wp\/v2\/categories?post=986978"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.marketnewsdesk.com\/index.php\/wp-json\/wp\/v2\/tags?post=986978"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}