Stop Risky Components Entering Your Software Supply Chain
Every package, AI model, and IDE extension vetted at the point of request. Risky ones blocked, policy-compliant versions served automatically.
What is JFrog Curation?
JFrog Curation automatically stops risky open-source packages, AI models, IDE extensions, and other third-party components before they ever reach your developers. Every component is vetted automatically, enforcing your security, compliance, and operational policies across every team, site, and region. When a component violates policy, JFrog automatically delivers the next safe, compliant version instead. Developers keep building. Security teams stop fighting fires.
Block Threats Before They're Reported
Attackers hide malicious code in trusted packages through typosquatting and maintainer hijacking. JFrog's research team flags these threats, often before public databases do. An immaturity policy then holds new versions for 14 days, giving the community time to flag a poisoned release.You set the policy on severity, license, or package age, and Curation enforces it.
No Broken Builds
When a package violates policy, Curation’s Compliant Version Selection automatically and transparently serves the highest compliant version in its place, across direct and transitive dependencies, so the build never breaks and the developer stays in flow. It is unique to JFrog.
Policy-Governed Waivers, Full Audit Log
Waivers let developers request access from within their workflow when a package is blocked and no compliant version exists. If your policy allows it, the request is approved instantly or sent to an approver. Waivers expire, so exceptions never become permanent, and every request, block, and approval is logged for audit.
Govern Every AI-Driven Request
AI agents pull dependencies at machine speed. Through JFrog's MCP server, every agent is governed by the same Curation policies as your developers, blocked the moment it reaches for a risky package and handed a compliant version instead. The code your agents pull is vetted and logged, the same as everything else your teams consume.
Global Enforcement, Zero Gaps
Curation enforces your policies at the point of request, on every site and in every region. Package Traffic Controller catches requests that try to skip Artifactory and pull straight from a public registry. Curation Federation allows you to set policy once and it is enforced at every site, in every region. Nothing routes around the gate.
across every component type.
Proven at Enterprise Scale
Deliver measurable business impact with automated upstream package governance that blocks threats instantly.
Global Enterprises Trust JFrog Curation to Make Open Source Consumption Safe by Default
“JFrog Curation is a firewall for open-source packages. It's about how we can help developers continue their work without disrupting their workflow. We enable development, we don't block it."
"With JFrog Curation and Xray, we have a genuine firewall for our dependencies. Developers can pull what they need, but every package has already been audited, verified, and cleared before they ever touch it. Security becomes a property of the environment, not a step they have to remember."
“Adding JFrog Curation and Advanced Security to our pipelines allowed us to enhance our security throughout the lifecycle of our products.”
“With JFrog Curation, we're truly shifting left because we're now able to block malicious packages and risky components before they even enter our cloud instance, easing the minds of our security leadership team.”
“Our Curation deployment provides very effective and efficient supply chain protection. We were able to shut down recent provider attacks in mere minutes once discovered and the control has proven 100% successful since.”
-
Traditional SCA relies on vulnerability databases, meaning it cannot block unknown or immature packages before they enter your organization. This leaves developer workstations exposed to attacks the moment an unvetted package is downloaded. Curation prevents this by enforcing immaturity policies at intake, stopping new vulnerabilities at the front door rather than reacting after a breach.
-
Both the Executive Order 14028 and the EU Cyber Resilience Act require verifying open-source components before integration, not after. Curation enforces policy at the moment a component is requested and logs every request, block, and approval automatically. That immutable record is the documented evidence both frameworks require, produced as a byproduct of how your developers already work.
-
Curation treats AI models as first-class components, applying the same policy enforcement to models from Hugging Face and NVIDIA NIM as it does to packages. Every model is evaluated against your policies before it enters your environment, with verified intelligence across 97.1% of Hugging Face models and 15M+ components in the Catalog.
-
When a developer, CI pipeline, or AI agent requests a package, JFrog Curation checks it against the JFrog Catalog, a ready-made record of millions of packages, instead of downloading and scanning the file. If the package is malicious, vulnerable, or breaks your policy on things like license or package age, Curation blocks. Because it checks the JFrog Catalog instead of downloading each file, without delay even when a pipeline is resolving hundreds of packages at once. Risky packages never reach your developers.
-
JFrog’s security research team runs automated scanners that flag malicious behavior, like data exfiltration, dependency confusion, and typosquatting, and builds a maliciousness score before any CVE is filed. JFrog Catalog continuously analyzes each component’s metadata, behavior, and provenance, so Curation can block a threat on JFrog’s own intelligence, ahead of public databases.
-
Usually a developer never notices: Curation serves a compliant version and the build continues. If none exists, the developer requests a waiver from their workflow, no ticket needed, and it clears instantly or routes to an approver per your policy. Waivers can expire, so access never becomes a permanent exception.
-
Yes, when Enforce Policy on Cached Packages is enabled. Curation’s default is to stop risky packages at the point of request, but a package that was safe when downloaded can later be discovered as malicious. With this setting on, Curation applies current policy to cached packages and blocks any whose security posture has changed.