Product

Overview

How it works Watch it work All 35 features Screenshots How ForgeRepo™ is secured

Keep bad packages out

Malware scanning Typosquat detection Dependency confusion protection Cooling off new releases Allow lists and block lists

When something goes wrong

Kill switch Who has it Lockdown and degraded modes Vulnerability monitoring

Developers and approvals

Requests and auto approve Check, walk and review Waivers Dry run
Formats

Languages

Private npm registry PyPI proxy and private index Private NuGet feed and proxy Maven repository proxy RubyGems mirror Composer and Packagist proxy

Apple, containers and Linux

CocoaPods CDN mirror Swift package registry Docker registry mirror RPM mirror for dnf and yum APT mirror for Debian and Ubuntu

Use it as

An npm firewall Artifacts, SBOMs and lifecycle More than one node SSO, roles and allow lists
Learn

Guides

Learn secure development Secure coding Secure pipelines Unsafe vs safe Security and development

Supply chain

Supply chain attacks, 2016 to 2026 Software supply chain security
Compare Side by side, all four ForgeRepo™ vs JFrog ForgeRepo™ vs Sonatype ForgeRepo™ vs Cloudsmith
Docs

Start

Getting started Download All documentation Questions

For developers

npm setup pip setup docker login Push a Docker image CI basics

For administrators

First setup Rules and their order Six incidents, walked through Backup and upgrade
Pricing Install it

Rules and approvals

Auto approve

Let clean requests approve themselves, and keep anything risky for a person.

Every request is checked as soon as it arrives: its files are downloaded, which caches them, scanned for malware, and looked up in the advisory feeds. On Requests each one says what the check found, like "checked: malware scan clean, no advisories", so you can decide at a glance.

With Auto approve on, a request that passes is approved by itself. Switch it on or off on the Dashboard, under Auto approve. Only admins can change it, a reason is required, admins are emailed, and the change goes into the audit trail.

The check findsAuto approve does
Every file scans clean for malware, and the worst advisory is below HighApproves it, pinned to the exact versions checked. The files are already cached.
A High or Critical advisoryLeaves it in Requests for a person, naming the advisories.
No malware answer: scanning off, a scanner down, or a file too big to scanLeaves it for a person, saying why.
A kill switch, a deny rule, a lookalike name, a reserved name, or a license held by the license rulesLeaves it for a person.
A version still cooling off, a scan still running, or the registry in degraded or lockdown modeWaits, and looks again every 5 minutes.
  • A request that names versions is approved for exactly those. A request with no version, which is what a blocked install makes, is approved for the whole package when Scan before serving is on, because every later version is still scanned before it is served. With Scan before serving off, it is pinned to the newest version that finished cooling off.
  • For an image, every platform image, config and layer is downloaded and scanned, and the packages inside are checked. When Only count what has a fix is on, only advisories that have a fix count toward High and Critical.
  • Malware scanning must be on with a content scanner such as ClamAV. A hash blocklist alone is not a scan.
  • On Requests, a request auto approve would not take says needs a person and why, like "high advisories (CVE-2021-23337)". Approved rules say "auto approved" in their note, and the audit trail records request.approve.auto.
  • While auto approve is on, an install refused for want of a rule tells the developer it is being checked and to try again in up to 10 minutes, or 30 for an image.

Careful

Auto approve takes a person out of the loop for clean packages. Keep Cooling off on, so a brand new malicious release is not approved in its first hours, before scanners and advisory feeds know about it.