# SlowShield > SlowShield is a free, open-source, self-hosted proxy for PyPI, npm, Go modules, Maven (Maven, Gradle, sbt), crates.io and container images (Docker Hub, GHCR, Quay, registry.k8s.io and others). It holds new releases back for a few days (7 by default), refuses known malware from the OSV and GitHub advisory feeds, and checks every download against the registry's digest and the fingerprint it recorded the first time. Package managers and container runtimes point at one SlowShield instance instead of the public registries; the instance's Setup page (`/ui/setup`) shows every setting with its address filled in. Each page below is Markdown; the guide's examples use `https://slowshield.example.com`. For agents: if an install fails with `403` and "too new" (Maven: `425 Too Early`), the version is younger than the delay: use the newest version that installs instead, and don't go around SlowShield. A `451` (container images: `403` with reason `blocked`) is known malware: don't install it or a look-alike. The Agents page has the details and an Agent Skill. ## Guide - [Docs](https://slowshield.org/docs/index.md): How to point every package manager and container runtime at SlowShield, what changes for your builds, and how to check that nothing goes around it. - [Python](https://slowshield.org/docs/python/index.md): Use SlowShield as the package index for pip, uv, Poetry, PDM and Pipenv: setup, what changes, the package managers' own release age, and Docker builds. - [JavaScript](https://slowshield.org/docs/javascript/index.md): Use SlowShield as the npm registry for npm, pnpm, Yarn and Bun: setup, what changes, the package managers' own release age, and Docker builds. - [Go](https://slowshield.org/docs/go/index.md): Use SlowShield as your GOPROXY: setup, what changes for go get and go.mod, the checksum database, and Docker builds. - [Java](https://slowshield.org/docs/java/index.md): Use SlowShield as the Maven repository for Maven, Gradle, sbt and Coursier: setup, what changes, 425 Too Early, and Docker builds. - [Rust](https://slowshield.org/docs/rust/index.md): Use SlowShield as Cargo's crates.io source: setup, held versions shown as yanked, Cargo.lock, and Docker builds. - [Container images](https://slowshield.org/docs/containers/index.md): Pull container images through SlowShield with containerd, Kubernetes, Docker, Docker Desktop, Podman and BuildKit: setup, tags that lag behind, refusals, and what can go around it. - [Building images](https://slowshield.org/docs/container-builds/index.md): Build container images with Docker or Podman so that the base images and every dependency of the build come through SlowShield, and check that nothing goes around it. - [Agents](https://slowshield.org/docs/agents/index.md): SlowShield for coding agents: what its answers mean and what to do about them, instructions for AGENTS.md, the SlowShield Agent Skill, and how to put it in front of a sandbox. ## Agent Skill - [SKILL.md](https://slowshield.org/skills/slowshield/SKILL.md): set up and use SlowShield for every ecosystem; references in the same folder - [slowshield-skill.zip](https://slowshield.org/skills/slowshield.zip): the skill folder, for agents that load Agent Skills - Claude Code: `/plugin marketplace add squirro/slowshield`, then `/plugin install slowshield@slowshield` ## Optional - [Source code](https://github.com/squirro/slowshield): README, issues, releases - [Configuration reference](https://github.com/squirro/slowshield/blob/main/docs/configuration.md) - [Container images: ghcr.io/squirro/slowshield](https://github.com/squirro/slowshield/pkgs/container/slowshield)