Product

Overview

How it works Watch it work All 35 features Screenshots How ForgeRepo™ is secured

Keep bad packages out

Malware scanning Typosquat detection Dependency confusion protection Cooling off new releases Allow lists and block lists

When something goes wrong

Kill switch Who has it Lockdown and degraded modes Vulnerability monitoring

Developers and approvals

Requests and auto approve Check, walk and review Waivers Dry run
Formats

Languages

Private npm registry PyPI proxy and private index Private NuGet feed and proxy Maven repository proxy RubyGems mirror Composer and Packagist proxy

Apple, containers and Linux

CocoaPods CDN mirror Swift package registry Docker registry mirror RPM mirror for dnf and yum APT mirror for Debian and Ubuntu

Use it as

An npm firewall Artifacts, SBOMs and lifecycle More than one node SSO, roles and allow lists
Learn

Guides

Learn secure development Secure coding Secure pipelines Unsafe vs safe Security and development

Supply chain

Supply chain attacks, 2016 to 2026 Software supply chain security
Compare Side by side, all four ForgeRepo™ vs JFrog ForgeRepo™ vs Sonatype ForgeRepo™ vs Cloudsmith
Docs

Start

Getting started Download All documentation Questions

For developers

npm setup pip setup docker login Push a Docker image CI basics

For administrators

First setup Rules and their order Six incidents, walked through Backup and upgrade
Pricing Install it

Keep bad packages out

Cooling off period for new package releases

Hijacked and malicious releases usually get noticed and pulled within a few days. Cooling off, in hours keeps brand new versions away from your builds for that long. 72 is a sensible start.

A version published more recently than the cooling off period is left out of the metadata the client reads, so a range like ^1.2.0 or >=1.2 quietly settles on the newest version that is old enough, and latest moves back with it. Asking for the young version by name, the way a lockfile does, gets a 403 that says when it will be served.

The publish time comes from the registry: npm's time field, and for PyPI the first upload of the release. A late wheel added to an old release does not make it young again. NuGet, Maven (for the newest few versions of a package), RubyGems, Composer and RPM give publish times too. CocoaPods, Swift and APT give none, so for those the A version with no publish time setting decides, and it lets them through unless you change it. The same setting covers a private registry that gives no times. Container images are not cooled off: a tag has no publish time to trust.

Your own builds are not held up. Never cooled off takes names and patterns like @yourcompany/*, and an allow rule pinned to one exact version skips the wait, since somebody already looked at it. A cooling off waiver can be granted for one package, scoped to one application or environment, with an end date.

This is not unique to ForgeRepo™, and we will not pretend otherwise: JFrog Curation, Sonatype Firewall and Cloudsmith all offer a package age policy in their paid tiers. Here it is simply on the Settings page of the free one.

packages.example.com/_admin/
Cooling off, safe version resolution and quarantine mode all sit on the Policy tab.

In short

  • Measured from the registry's own publish time, not when the box first saw it
  • Applies to every package type that has a publish time, images excepted
  • Ranges step back to the newest version that is old enough
  • Lockfiles asking for a young version get a 403 that says when
  • Exemptions for your own packages, and pinned allow rules skip the wait
  • Every left out version is logged under Resolutions

In the documentation

Goes well with

  • Safe version resolution Versions with serious advisories are left out, so a range quietly settles on the newest safe one.
  • Malware scanning ClamAV, a hash blocklist, your own scanner and the OpenSSF known malicious feed, on every cached file. Optionally before the first download.
  • Waivers A written down, time boxed yes for one finding on one package, scoped to an app or environment.

One container, about two minutes

A Linux box with Docker, or one without it, and a reverse proxy for TLS. The installer does the rest and it is safe to run twice. Free, MIT licensed, nothing to sign up for.