Talk to us
by JFrogTechBag Intel Page

JFrog Curation

The package was malicious. It never should have been downloaded — JFrog Curation checks every package, AI model and IDE extension at the point of request — blocking what fails policy and serving the highest compliant version, before anything reaches a developer, a build or an AI agent.

Stop it at the doorThe next safe versionRerouted at the edge

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
add-on on Enterprise X/+
Quote-only
Gartner 2026
JFrog, first SSCS MQ
Leader
Catalog
components, JFrog’s figure
15M+
India
SaaS regions on status page
Mumbai · Pune

Quick answer

JFrog Curation is a paid add-on to the JFrog Platform (Enterprise X and Enterprise+) that checks every open-source package, AI model and IDE extension at the point of request — before it reaches a developer, a build or an AI agent. Out-of-policy versions are blocked and the highest compliant version is served in their place. Since August 2026 it includes Package Traffic Controller, which reroutes direct registry downloads through JFrog via Zscaler, Netskope or Cloudflare. Price is quote-only. Read more ↓ Show less ↑
Part 01 · Orient

The JFrog platform family

This page covers JFrog Curation — the pre-entry gate, sold as an add-on. The rest:

Quick facts

30-second orientation
Product
Pre-entry gate for open-source and AI components
How it is bought
Paid add-on on Enterprise X / Enterprise+
Also inside
Unified and Ultimate Security bundles
What it gates
OSS packages, AI models, IDE extensions
When it acts
At the point of request, before first use
When a version fails
Serves the highest compliant version
New in 2026
Package Traffic Controller (Zscaler, Netskope, Cloudflare)
Gartner 2026
JFrog: Leader, first SSCS Magic Quadrant
India
Status page lists Mumbai and Pune SaaS regions
In India via
TechBag — INR/GST, scoping and support
Part 02 · Learn

Understand package curation before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is JFrog Curation?

A gate in the registry path that decides, per request, whether an open-source package, AI model or IDE extension may enter the organisation at all.

Alerting after entry vs gating at the door — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionScan-after-entry dependency alertsJFrog Curation
When risk is caughtAfter it is in the lockfileAt the point of request
A bad versionAn alert and a ticketBlocked; the safe version served
New releasesPulled the minute they shipHeld until they have aged
AI agentsPull straight from public registriesRerouted through JFrog at the edge
ExceptionsAllow-lists that never expireWaivers with an owner and an end date
What it is NOT—Not a scanner for what is already inside

The cheapest test of the core claim: run the policies in dry-run mode for two weeks and count what would have been blocked.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
The intelligence

Catalog

JFrog Catalog

The component database behind every decision — JFrog says 15M+ components and 97.1% of Hugging Face models. It is not sold alone; Curation and the security products read from it.

02
The enforcement point

Remote repos

Artifactory remote repositories

Package managers resolve through Artifactory, not the public registry. Curation checks each request there, so the gate needs no agent on developer laptops or build runners.

03
The decision

Policies

Curation policies and waivers

Conditions on malicious packages, CVE severity, licence and package age. A blocked version is swapped for the highest compliant one; a waiver covers the rest, and it expires.

04
The bypass fix

Traffic Controller

Package Traffic Controller

Works with Zscaler, Netskope or Cloudflare to reroute direct pulls from public registries through JFrog — the path AI agents and misconfigured machines take around the proxy.

Catalog intelligence, registry-path policy and edge rerouting — one decision per package, made before it ever enters.

Part 03 · Evaluate

Nine capabilities. Intercept, decide, govern.

JFrog Curation decides at the door — one check per request, in the registry path, before a package, model or extension ever reaches a developer or an agent.

Intercept
Pre-entry

Blocked at the point of request

A package is checked when it is first requested, before it is cached, built or installed — not reported after it is already in a lockfile.

Intercept
Network edge

Package Traffic Controller

Zscaler Internet Access, Cloudflare Gateway or Netskope One SSE reroute direct public-registry downloads through JFrog, so a bypass still meets policy.

Intercept
AI & IDE

Models and extensions, too

Hugging Face models, NVIDIA NIM and VS Code extensions sit on JFrog’s supported list beside npm, PyPI, Maven, Go, NuGet, Cargo and Docker.

Decide
Malicious

Known-bad never lands

Packages flagged malicious in the Catalog are refused at request. JFrog claims 99% of malicious components blocked at the point of request.

Decide
Immaturity

A cooling-off period for new releases

An age condition holds brand-new versions — JFrog’s example is 14 days — giving the community time to flag a poisoned release first.

Decide
Compliant

The next safe version, served

When a version fails, Curation serves the highest compliant version across direct and transitive dependencies, so most builds keep running.

Govern
Waivers

Exceptions that expire

A developer requests access from the workflow; it is approved at once or routed to an approver. Waivers lapse, so exceptions never go permanent.

Govern
Federation

One policy, every site

Curation Federation sets a policy once and enforces it at every JFrog site and region — useful where India and overseas teams share one supply chain.

Govern
Audit

Every request on record

Each request, block and approval is logged — the evidence an auditor asks for when the question is what entered the organisation, and when.

See it, don’t just read it

Watch JFrog Curation in action

Traffic Controller with Zscaler, the case for shifting left, and a full Curation walkthrough.

JFrog (official)·Traffic Controller

Route package traffic through JFrog PTC with Zscaler

Setup and policy, step by step.

JFrog (official)·Overview

The Power of JFrog Curation and Shift Left

Why the gate sits before the build.

JFrog (official)·Walkthrough

Curation Walkthrough

Policies, blocks and waivers in the UI.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why JFrog Curation

Most tools tell you a bad package got in. Curation stops it at the door.

Here’s what genuinely sets it apart — and exactly where it stops.

01

It stops the package instead of reporting it

Most dependency tools raise an alert once a risky version is already declared, cached and built. Curation decides at the point of request, in the registry path, so a malicious or out-of-policy version never lands — and there is nothing to clean out of caches, images and lockfiles afterwards.

02

Blocking without breaking the build

A hard block alone teaches developers to route around the proxy. Curation serves the highest compliant version in place of the failed one, across transitive dependencies, and the rest go through a waiver that expires. The gate holds because it rarely leaves anyone stuck.

03

It covers the path around the proxy

AI coding agents and misconfigured machines pull straight from public registries. Package Traffic Controller uses the Zscaler, Netskope or Cloudflare service you may already run to reroute those downloads through JFrog, so the same policy applies to agents, laptops and CI.

04

Where it stops

Curation is an add-on to Artifactory on Enterprise X or Enterprise+ — not a standalone firewall for another registry, and not on SaaS Pro. Its price is quote-only. It gates what enters; it does not find what is already inside, which is Xray’s job, and its coverage figures are JFrog’s own.

The idea
Stop it at the door
The fallback
The next safe version
The bypass
Rerouted at the edge
Proof, not promises

The numbers behind the platform

99%
of malicious components blocked at point of request — JFrog’s claim
— JFrog
15M+
components in the JFrog Catalog behind each decision — JFrog’s figure
— JFrog
14 days
JFrog’s example immaturity hold on brand-new versions
— JFrog
451%
year-on-year rise in malicious packages, JFrog’s 2026 report
— JFrog research
171K+
unique malicious package instances counted in that report
— JFrog research
3 SASE partners
Zscaler, Cloudflare and Netskope for Traffic Controller at launch
— JFrog, Aug 2026

What your Curation rollout looks like

Week 1Scope

Confirm the tier and route the traffic

Curation needs Artifactory on Enterprise X or Enterprise+. List which package managers still resolve from public registries.

Week 2Pilot

Run the policies in dry mode

Start with the malicious-package condition only, on remote repositories, and see what real requests would have been blocked.

Week 3–4Enforce

Add CVE, licence and age conditions

Tighten one condition at a time. Check that the compliant-version fallback resolves cleanly before switching on enforcement.

Month 2Govern

Set the waiver path and owners

Decide who approves waivers and how long they last, so exceptions carry an owner and an end date from the start.

Month 3Extend

Close the bypass at the edge

If Zscaler, Netskope or Cloudflare is in place, turn on Traffic Controller for agents and machines that ignore the proxy.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.3
130+ reviews*
87% would recommend
Blocking before entry4.6
Compliant-version fallback4.4
Waiver workflow4.2
Setup effort3.7
Price transparency3.3
5★
54%
4★
31%
3★
10%
2★
3%
1★
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
Fintech
“A typosquatted npm package was requested twice in the first month. Both requests were refused before anything reached a laptop.”
DevSecOps Lead
Fintech
SaaS
“The compliant-version fallback is why developers accepted it. A blocked minor release quietly resolved to the previous patch.”
Platform Engineering Manager
SaaS
BFSI
“Waivers expiring by default ended our permanent-exception list. Every exception now has an owner and an end date.”
Application Security Manager
BFSI
E-commerce
“The 14-day hold on new versions annoyed two teams for a week, then caught a compromised release we would have pulled.”
Head of Engineering
E-commerce
Manufacturing
“We were on SaaS Pro. Curation meant moving to Enterprise X first, so budget the tier change, not just the add-on.”
IT Procurement Lead
Manufacturing
IT Services
“Traffic Controller closed the gap our coding agents opened — they ignored the proxy settings until Zscaler rerouted them.”
CISO
IT Services
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the package-security market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Package Security Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
JFrog CurationThis page

Registry-path gate with compliant-version fallback and a network-edge bypass fix; quote-only, Artifactory-bound.

Grid 02 · The architecture

Pre-entry Enforcement × Ecosystem Coverage

The grid nobody publishes — how early a tool stops a risky package vs how many ecosystems and asset types it covers.

Broad scannersGatekeepersAlert-only basicsInstall-time specialists
JFrog CurationThis page

Blocks at request, reroutes bypasses at the edge, and covers AI models and IDE extensions.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

JFrog Curation vs the package-security field

Against Sonatype Repository Firewall, Socket, Snyk Open Source, Mend.io and GitHub Dependabot — on when risk is stopped, coverage, price and India.

DimensionJFrog CurationSonatype Repository FirewallSocketSnyk Open SourceMend.ioGitHub Dependabot + Code Security
What it isPre-entry package gateRepository firewallScanner + firewallScan after declarationSCA + update botAlerts after the fact
DeploymentSaaS or self-managedConnected or air-gappedSaaS; firewall self-hostSaaS, four regionsNot publishedGitHub.com or GHES
Ecosystems coveredLanguages, OS, AI, IDE4, or 15+ formatsJS, Python, Go and moreMajor languagesCode deps + containers8 malware ecosystems
Pricing modelQuote-only add-onAnnual, published entryPer developer / monthFlat or creditsPer contributing devFree + per committer
Published entry priceNot published$4,800 a year$0 free tier$0 free tierCeiling, not floor$0 for Dependabot
Included vs add-onAdd-on to the platformSeparate productFree firewall; SSO paidPer-product creditsBundled platformAlerts free, depth paid
Scale limitsFollows the tierNot publishedScan quotasTest limitsNo GB or scan feesPer repository
Security depthMalware, CVE, licenceMalware + quarantine70+ risk typesVulns + licencesVulns + licencesAdvisory-based alerts
IntegrationsRegistries, SASE, agentsRepository proxiesGitHub, CLI, SlackIDE, CLI, SCM, CISCM + RenovateGitHub only
Governance & SSOWaivers, audit, SSORisk-level policySSO from BusinessEnterprise-levelNot publishedTeam or Enterprise
India storage regionMumbai · PuneSelf-host in IndiaNot publishedUS, EU, AU onlyNot publishedVia GHES
Support24/7 SLA from Ent XEnterprise supportBy tierNext business dayDedicated (Renovate)Follows the plan
Lock-in / exitTied to ArtifactoryEdition-dependentLight to removeScanner onlyScanner + free RenovateTied to GitHub
Best fitArtifactory estatesNexus or mixed reposJS/Python-heavy teamsDeveloper-first SCASCA + updates bundleThe baseline
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose JFrog Curation if…

  • ✓You already run Artifactory on Enterprise X or Enterprise+
  • ✓Risky packages must be stopped before first use, not reported after
  • ✓AI coding agents and laptops pull straight from public registries
  • ✓You want blocks that fall back to a compliant version, not a broken build

Compare alternatives if…

  • ✓Your registry is Nexus or a cloud-native one, not Artifactory
  • ✓You need a published price or per-developer billing to start
  • ✓You are on SaaS Pro and the tier change is not in the budget

Pair it with…

  • ✓Xray or another SCA tool for what is already inside
  • ✓Dependabot or Renovate to keep allowed versions current
  • ✓Your SASE service, if you turn on Traffic Controller

Do not expect…

  • ✓A list price — Curation is quote-only
  • ✓JFrog’s 99% and 15M+ figures to be independent measurements
  • ✓A Mumbai or Pune region to be a written storage commitment

JFrog Curation is one of 35 developer tools products TechBag carries. The Developer Tools guide narrows them to a shortlist and shows the reasoning. →

Do the math

What do risky packages cost you once they are in?

Drag the sliders (developers; loaded developer-hour cost). Estimates model the time lost to risky packages found after they are already in — triage, rollback, rebuilds and exception chasing — at an assumed ~1.5 hours per developer per year, with ~70% avoided by blocking at the point of request. Both figures are illustrative assumptions, not JFrog data. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual dependency-cleanup cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Quote-only: JFrog does not publish Curation’s price. It is a “$” add-on on Enterprise X — SaaS from $950/month, self-managed from $51,000/year — and Enterprise+, or part of the Unified and Ultimate Security bundles. TechBag prices the add-on against the bundle, then quotes in INR with GST.

Curation add-on

Best if you need only the gate

  • Quote-only, on Enterprise X or Enterprise+
  • Blocks at the point of request
  • Includes Package Traffic Controller

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

Security bundle

Best with Advanced Security too

  • Unified or Ultimate Security, quoted
  • 200 base developers, add more as needed
  • Curation plus Advanced Security

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Tier

Are you on Enterprise X or Enterprise+? Curation is not offered on SaaS Pro or self-managed Pro X, so price the tier change too.

2
Bundle

Is Curation cheaper inside the Unified or Ultimate Security bundle than as a standalone add-on for your developer count?

3
Coverage

Are all your ecosystems on JFrog’s supported list — including OS packages, AI models and IDE extensions you actually use?

4
Bypass

Which machines and AI agents pull straight from public registries? That is the gap Traffic Controller is for.

5
Fallback

When a version is blocked, does the compliant version resolve cleanly for your transitive dependencies? Test it in the pilot.

6
Waivers

Who approves a waiver, how fast, and for how long? A slow waiver path is the usual reason developers route around a gate.

7
Storage

Is the SaaS region, plus log retention, written into the contract rather than implied by a status page?

8
Claims

The 99% and 15M+ figures are JFrog’s own. Will the trial measure blocks on your real traffic instead?

FAQ

Questions buyers ask

A paid add-on to the JFrog Platform that checks open-source packages, AI models and IDE extensions at the point of request — before they reach a developer, a build or an AI agent. Out-of-policy versions are blocked, the highest compliant version is served instead, and every request, block and approval is logged.

Ready to evaluate JFrog Curation?

Check your tier, price the add-on against the security bundles, or let a TechBag advisor run a dry-run pilot on your real package traffic.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.