Product

Overview

How it works Watch it work All 35 features Screenshots How ForgeRepo™ is secured

Keep bad packages out

Malware scanning Typosquat detection Dependency confusion protection Cooling off new releases Allow lists and block lists

When something goes wrong

Kill switch Who has it Lockdown and degraded modes Vulnerability monitoring

Developers and approvals

Requests and auto approve Check, walk and review Waivers Dry run
Formats

Languages

Private npm registry PyPI proxy and private index Private NuGet feed and proxy Maven repository proxy RubyGems mirror Composer and Packagist proxy

Apple, containers and Linux

CocoaPods CDN mirror Swift package registry Docker registry mirror RPM mirror for dnf and yum APT mirror for Debian and Ubuntu

Use it as

An npm firewall Artifacts, SBOMs and lifecycle More than one node SSO, roles and allow lists
Learn

Guides

Learn secure development Secure coding Secure pipelines Unsafe vs safe Security and development

Supply chain

Supply chain attacks, 2016 to 2026 Software supply chain security
Compare Side by side, all four ForgeRepo™ vs JFrog ForgeRepo™ vs Sonatype ForgeRepo™ vs Cloudsmith
Docs

Start

Getting started Download All documentation Questions

For developers

npm setup pip setup docker login Push a Docker image CI basics

For administrators

First setup Rules and their order Six incidents, walked through Backup and upgrade
Pricing Install it

Developers and approvals

Package requests, approvals and auto approve

A developer who hits a block sees the reason and a link. The request is already waiting for an approver, and it is already checked.

Blocked installs open a request on their own, for npm, pip, docker, dotnet, mvn, Bundler, pod, SwiftPM, Composer, dnf and apt alike, so approvers see what people are actually reaching for. Developers can also ask in the portal with a reason, or tick everything a reviewed lockfile needs and ask for it in one go. Repeats fold into one row.

Every request is checked the moment it arrives: its files are downloaded (which caches them), scanned for malware, and looked up in the advisory feeds. Each row says what was found, like "checked: malware scan clean, no advisories", so the decision takes a glance.

The four things you can do are on the row: approve writes the allow rule, block writes a deny rule at priority 1000, clear removes it without writing anything, and check deps walks the dependency tree first. Approving can also approve the request's clean dependencies, each pinned to the version the walk resolved.

Auto approve

With auto approve on, a request of any type whose every file scans clean and whose worst advisory is below High approves itself, pinned to the versions checked. A High or Critical advisory, no malware answer, a kill, a deny rule, a lookalike, a reserved name or a held license leaves it for a person, and the row says why. Cooling off and running scans make it wait and look again. Only admins can switch it, with a reason, and it is audited.

Developers get an hourly digest, never one mail per request, about what happened to theirs.

packages.example.com/_admin/
Requests, as an approver sees them, with what the checks found on each.

In short

  • Blocked installs open requests automatically
  • Scanned and advisory checked on arrival
  • Approve, block, clear or check deps on the row
  • Auto approve for clean requests, a person for risky ones
  • Digests instead of a mail per event

In the documentation

Goes well with

  • Check, walk and review See what the rules say before you install. Walk a dependency tree. Review a lockfile or an SBOM.
  • Allow lists and block lists Whitelist or blacklist by name, scope, wildcard or version range, for every type. A blocked version is not even listed to the client.
  • Waivers A written down, time boxed yes for one finding on one package, scoped to an app or environment.

One container, about two minutes

A Linux box with Docker, or one without it, and a reverse proxy for TLS. The installer does the rest and it is safe to run twice. Free, MIT licensed, nothing to sign up for.