Observed arrival · 2026-10-03
SlowShield puts a waiting period in front of new packages
A free, open-source proxy for PyPI and npm that delays brand-new package releases, blocks known malware, and verifies downloads.
- For
- Developers and small teams using PyPI or npm
- Worth noticing
- A local Docker trial binds the proxy to 127.0.0.1 and refuses known malware with HTTP 451.
Field notes
The homepage gives a runnable Docker command bound to localhost, then shows how to route pip, uv, and npm through its local endpoints. It says releases younger than a week are withheld and known-malware requests return HTTP 451; the broader description also says downloads are verified. Team deployment options include Docker Compose, Podman, and Kubernetes, while the homepage labels Python and JavaScript support as available today and broader coverage as future.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
One card from the complete issue