| Allow and block rules by name and version |
★★★★★ |
★★★★★ |
★★★★★ |
★★★★★ |
ForgeRepo™ takes exact names, scopes, wildcards and npm or pip version ranges, scoped to an application or environment, and strips blocked versions from metadata so clients resolve around them. JFrog Curation and Sonatype Firewall both have rich policy engines that do this and more. Cloudsmith has deny policies built in and does allow lists as policy as code in Rego, on its Ultra and Enterprise plans. |
| Malware blocked before download |
★★★★★ behind |
★★★★★ |
★★★★★ |
★★★★★ |
ForgeRepo™ scans every file with ClamAV, a hash blocklist or a scanner of your own, and holds any version the OpenSSF malicious packages feed names before anybody gets it. A package reported malicious after it was cached goes on the kill switch by itself. It also looks at how a release behaves: a new version that suddenly runs code at install time is flagged or held, an npm listing that disagrees with the package.json in its tarball is held, and a version with less provenance than the ones before it is held. JFrog and Sonatype both run research teams and machine learning that read new packages as they are published, and block on that intelligence. That is still a real difference, which is why we score one below them. Cloudsmith uses ClamAV and the OpenSSF malicious packages feed, with block until scan in early access. |
| Its own malicious package research |
★★★★★ behind |
★★★★★ |
★★★★★ |
★★★★★ |
ForgeRepo™ has no research of its own. There is no team behind it reading npm all day. What it has is the public OpenSSF malicious packages feed, read through osv.dev, which only knows what somebody has already reported. JFrog publishes its research and Sonatype rates every release with its Release Integrity service. Cloudsmith draws on the same public data we do, which is why we both get one star. |
| Typosquat detection |
★★★★★ |
★★★★★ |
★★★★★ |
★★★★★ |
ForgeRepo™ compares every name against well known npm and PyPI names and catches swaps, homoglyphs, moved separators, added words and flattened scopes, then warns or refuses. JFrog and Sonatype catch typosquats through their research data, which knows about ones a name comparison would miss. Cloudsmith relies on the OpenSSF feed. |
| Dependency confusion protection |
★★★★★ |
★★★★★ |
★★★★★ |
★★★★★ |
ForgeRepo™ reserves names so they are never fetched from outside, and routes every scope to exactly one upstream with no silent fallback. Sonatype's Namespace Confusion Protection in Firewall does the same job well. JFrog has priority resolution and exclude patterns. Cloudsmith's upstream trust is in early access. |
| Cooling off period for new releases |
★★★★★ |
★★★★★ |
★★★★★ |
★★★★★ |
Everybody has this now and we are not going to pretend otherwise. ForgeRepo™ measures from the registry's publish time, trims young versions from metadata, has exemptions and waivers, and is free. JFrog Curation measures from publish time, as an add-on, and not for Docker. Sonatype measures from when it first cataloged the version and adds Release Integrity. Cloudsmith measures from publish time, as a policy as code add-on, with no exemptions. |
| Resolve around vulnerable versions |
★★★★★ |
★★★★★ |
★★★★★ |
★★★★★ |
With safe version resolution on, ForgeRepo™ leaves versions with serious advisories out of the metadata, so a range settles on the newest safe version and nothing outside the range is swapped in. Sonatype does the same thing in Firewall and calls it Policy Compliant Component Selection. JFrog Curation blocks the version. We have not tested any of theirs side by side, so we have given them the benefit of the doubt. |
| License policy |
★★★★★ behind |
★★★★★ |
★★★★★ |
★★★★★ |
ForgeRepo™ reads npm, PyPI, NuGet, Maven, RubyGems, Composer, CocoaPods and RPM licenses into SPDX expressions and enforces allowed, review and blocked lists. Xray and Sonatype's policy engine have years of license data and obligations behind them, and handle more formats. Cloudsmith has an SPDX deny list, with no license detection for Docker. |
| Verifies Sigstore provenance on proxied packages |
★★★★★ ahead
|
★★★★★ |
★★★★★ |
★★★★★ |
ForgeRepo™ checks npm SLSA provenance and PyPI PEP 740 attestations against a pinned Sigstore root on the server, holds a file whose provenance is invalid, and holds a new version built with less provenance than the ones before it, or built somewhere else. For images, a trust policy can require a cosign signature from your keys or from a keyless signer, checked against Fulcio and Rekor, and refuse unsigned pulls. JFrog passes npm attestations through so npm audit signatures works, and has an Evidence service. We could not find server side verification of proxied packages for Sonatype or Cloudsmith. If it is there, tell us and this row changes. |
| Quarantine and integrity |
★★★★★ behind |
★★★★★ |
★★★★★ |
★★★★★ |
ForgeRepo™ holds files for malware, licenses, provenance, fresh publishes and upstream bytes that changed, in permissive or strict mode. Sonatype Firewall quarantine is the benchmark, and it fails safe if the service is down. Cloudsmith quarantines from the UI, API or a policy. JFrog's model blocks at request time rather than holding files in a quarantine state. |