The package was malicious. It never should have been downloaded — JFrog Curation checks every package, AI model and IDE extension at the point of request — blocking what fails policy and serving the highest compliant version, before anything reaches a developer, a build or an AI agent.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers JFrog Curation — the pre-entry gate, sold as an add-on. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
A gate in the registry path that decides, per request, whether an open-source package, AI model or IDE extension may enter the organisation at all.
What consolidation actually replaces, dimension by dimension.
| Dimension | Scan-after-entry dependency alerts | JFrog Curation |
|---|---|---|
| When risk is caught | After it is in the lockfile | At the point of request |
| A bad version | An alert and a ticket | Blocked; the safe version served |
| New releases | Pulled the minute they ship | Held until they have aged |
| AI agents | Pull straight from public registries | Rerouted through JFrog at the edge |
| Exceptions | Allow-lists that never expire | Waivers with an owner and an end date |
| What it is NOT | — | Not a scanner for what is already inside |
The cheapest test of the core claim: run the policies in dry-run mode for two weeks and count what would have been blocked.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
The component database behind every decision — JFrog says 15M+ components and 97.1% of Hugging Face models. It is not sold alone; Curation and the security products read from it.
Package managers resolve through Artifactory, not the public registry. Curation checks each request there, so the gate needs no agent on developer laptops or build runners.
Conditions on malicious packages, CVE severity, licence and package age. A blocked version is swapped for the highest compliant one; a waiver covers the rest, and it expires.
Works with Zscaler, Netskope or Cloudflare to reroute direct pulls from public registries through JFrog — the path AI agents and misconfigured machines take around the proxy.
Catalog intelligence, registry-path policy and edge rerouting — one decision per package, made before it ever enters.
JFrog Curation decides at the door — one check per request, in the registry path, before a package, model or extension ever reaches a developer or an agent.
A package is checked when it is first requested, before it is cached, built or installed — not reported after it is already in a lockfile.
Zscaler Internet Access, Cloudflare Gateway or Netskope One SSE reroute direct public-registry downloads through JFrog, so a bypass still meets policy.
Hugging Face models, NVIDIA NIM and VS Code extensions sit on JFrog’s supported list beside npm, PyPI, Maven, Go, NuGet, Cargo and Docker.
Packages flagged malicious in the Catalog are refused at request. JFrog claims 99% of malicious components blocked at the point of request.
An age condition holds brand-new versions — JFrog’s example is 14 days — giving the community time to flag a poisoned release first.
When a version fails, Curation serves the highest compliant version across direct and transitive dependencies, so most builds keep running.
A developer requests access from the workflow; it is approved at once or routed to an approver. Waivers lapse, so exceptions never go permanent.
Curation Federation sets a policy once and enforces it at every JFrog site and region — useful where India and overseas teams share one supply chain.
Each request, block and approval is logged — the evidence an auditor asks for when the question is what entered the organisation, and when.
Traffic Controller with Zscaler, the case for shifting left, and a full Curation walkthrough.
Setup and policy, step by step.
Why the gate sits before the build.
Policies, blocks and waivers in the UI.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Most dependency tools raise an alert once a risky version is already declared, cached and built. Curation decides at the point of request, in the registry path, so a malicious or out-of-policy version never lands — and there is nothing to clean out of caches, images and lockfiles afterwards.
A hard block alone teaches developers to route around the proxy. Curation serves the highest compliant version in place of the failed one, across transitive dependencies, and the rest go through a waiver that expires. The gate holds because it rarely leaves anyone stuck.
AI coding agents and misconfigured machines pull straight from public registries. Package Traffic Controller uses the Zscaler, Netskope or Cloudflare service you may already run to reroute those downloads through JFrog, so the same policy applies to agents, laptops and CI.
Curation is an add-on to Artifactory on Enterprise X or Enterprise+ — not a standalone firewall for another registry, and not on SaaS Pro. Its price is quote-only. It gates what enters; it does not find what is already inside, which is Xray’s job, and its coverage figures are JFrog’s own.
Curation needs Artifactory on Enterprise X or Enterprise+. List which package managers still resolve from public registries.
Start with the malicious-package condition only, on remote repositories, and see what real requests would have been blocked.
Tighten one condition at a time. Check that the compliant-version fallback resolves cleanly before switching on enforcement.
Decide who approves waivers and how long they last, so exceptions carry an owner and an end date from the start.
If Zscaler, Netskope or Cloudflare is in place, turn on Traffic Controller for agents and machines that ignore the proxy.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“A typosquatted npm package was requested twice in the first month. Both requests were refused before anything reached a laptop.”
“The compliant-version fallback is why developers accepted it. A blocked minor release quietly resolved to the previous patch.”
“Waivers expiring by default ended our permanent-exception list. Every exception now has an owner and an end date.”
“The 14-day hold on new versions annoyed two teams for a week, then caught a compromised release we would have pulled.”
“We were on SaaS Pro. Curation meant moving to Enterprise X first, so budget the tier change, not just the add-on.”
“Traffic Controller closed the gap our coding agents opened — they ignored the proxy settings until Zscaler rerouted them.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the package-security market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Registry-path gate with compliant-version fallback and a network-edge bypass fix; quote-only, Artifactory-bound.
The grid nobody publishes — how early a tool stops a risky package vs how many ecosystems and asset types it covers.
Blocks at request, reroutes bypasses at the edge, and covers AI models and IDE extensions.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Sonatype Repository Firewall, Socket, Snyk Open Source, Mend.io and GitHub Dependabot — on when risk is stopped, coverage, price and India.
| Dimension | JFrog Curation | Sonatype Repository Firewall | Socket | Snyk Open Source | Mend.io | GitHub Dependabot + Code Security |
|---|---|---|---|---|---|---|
| What it is | Pre-entry package gate | Repository firewall | Scanner + firewall | Scan after declaration | SCA + update bot | Alerts after the fact |
| Deployment | SaaS or self-managed | Connected or air-gapped | SaaS; firewall self-host | SaaS, four regions | Not published | GitHub.com or GHES |
| Ecosystems covered | Languages, OS, AI, IDE | 4, or 15+ formats | JS, Python, Go and more | Major languages | Code deps + containers | 8 malware ecosystems |
| Pricing model | Quote-only add-on | Annual, published entry | Per developer / month | Flat or credits | Per contributing dev | Free + per committer |
| Published entry price | Not published | $4,800 a year | $0 free tier | $0 free tier | Ceiling, not floor | $0 for Dependabot |
| Included vs add-on | Add-on to the platform | Separate product | Free firewall; SSO paid | Per-product credits | Bundled platform | Alerts free, depth paid |
| Scale limits | Follows the tier | Not published | Scan quotas | Test limits | No GB or scan fees | Per repository |
| Security depth | Malware, CVE, licence | Malware + quarantine | 70+ risk types | Vulns + licences | Vulns + licences | Advisory-based alerts |
| Integrations | Registries, SASE, agents | Repository proxies | GitHub, CLI, Slack | IDE, CLI, SCM, CI | SCM + Renovate | GitHub only |
| Governance & SSO | Waivers, audit, SSO | Risk-level policy | SSO from Business | Enterprise-level | Not published | Team or Enterprise |
| India storage region | Mumbai · Pune | Self-host in India | Not published | US, EU, AU only | Not published | Via GHES |
| Support | 24/7 SLA from Ent X | Enterprise support | By tier | Next business day | Dedicated (Renovate) | Follows the plan |
| Lock-in / exit | Tied to Artifactory | Edition-dependent | Light to remove | Scanner only | Scanner + free Renovate | Tied to GitHub |
| Best fit | Artifactory estates | Nexus or mixed repos | JS/Python-heavy teams | Developer-first SCA | SCA + updates bundle | The baseline |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
JFrog Curation is one of 35 developer tools products TechBag carries. The Developer Tools guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (developers; loaded developer-hour cost). Estimates model the time lost to risky packages found after they are already in — triage, rollback, rebuilds and exception chasing — at an assumed ~1.5 hours per developer per year, with ~70% avoided by blocking at the point of request. Both figures are illustrative assumptions, not JFrog data. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Quote-only: JFrog does not publish Curation’s price. It is a “$” add-on on Enterprise X — SaaS from $950/month, self-managed from $51,000/year — and Enterprise+, or part of the Unified and Ultimate Security bundles. TechBag prices the add-on against the bundle, then quotes in INR with GST.
Best if you need only the gate
Best for a broader rollout
Best with Advanced Security too
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Are you on Enterprise X or Enterprise+? Curation is not offered on SaaS Pro or self-managed Pro X, so price the tier change too.
Is Curation cheaper inside the Unified or Ultimate Security bundle than as a standalone add-on for your developer count?
Are all your ecosystems on JFrog’s supported list — including OS packages, AI models and IDE extensions you actually use?
Which machines and AI agents pull straight from public registries? That is the gap Traffic Controller is for.
When a version is blocked, does the compliant version resolve cleanly for your transitive dependencies? Test it in the pilot.
Who approves a waiver, how fast, and for how long? A slow waiver path is the usual reason developers route around a gate.
Is the SaaS region, plus log retention, written into the contract rather than implied by a status page?
The 99% and 15M+ figures are JFrog’s own. Will the trial measure blocks on your real traffic instead?
Check your tier, price the add-on against the security bundles, or let a TechBag advisor run a dry-run pilot on your real package traffic.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.