Product

Overview

How it works Watch it work All 35 features Screenshots How ForgeRepo™ is secured

Keep bad packages out

Malware scanning Typosquat detection Dependency confusion protection Cooling off new releases Allow lists and block lists

When something goes wrong

Kill switch Who has it Lockdown and degraded modes Vulnerability monitoring

Developers and approvals

Requests and auto approve Check, walk and review Waivers Dry run
Formats

Languages

Private npm registry PyPI proxy and private index Private NuGet feed and proxy Maven repository proxy RubyGems mirror Composer and Packagist proxy

Apple, containers and Linux

CocoaPods CDN mirror Swift package registry Docker registry mirror RPM mirror for dnf and yum APT mirror for Debian and Ubuntu

Use it as

An npm firewall Artifacts, SBOMs and lifecycle More than one node SSO, roles and allow lists
Learn

Guides

Learn secure development Secure coding Secure pipelines Unsafe vs safe Security and development

Supply chain

Supply chain attacks, 2016 to 2026 Software supply chain security
Compare Side by side, all four ForgeRepo™ vs JFrog ForgeRepo™ vs Sonatype ForgeRepo™ vs Cloudsmith
Docs

Start

Getting started Download All documentation Questions

For developers

npm setup pip setup docker login Push a Docker image CI basics

For administrators

First setup Rules and their order Six incidents, walked through Backup and upgrade
Pricing Install it

Keep bad packages out

Safe version resolution

npm and pip pick a version themselves from the list the registry hands them. Safe version resolution changes the list, so they pick a safe one without anybody editing a lockfile.

With it on, any version with a known advisory at or above the chosen severity (HIGH by default) is left out of the npm packument, the PyPI project page and the JSON API, and the version lists of every other type with an OSV feed: NuGet, Maven, RubyGems, Swift, Composer, RPM and APT. It is refused with a 403 when something asks for it directly. The client then picks normally from what is left. CocoaPods has no advisory feed, so nothing is left out there.

Nothing outside the range the developer asked for is ever swapped in. If every version inside ^4.17.0 is excluded, the install fails and says so, rather than quietly getting something else. That is the right way round: a surprise major version is its own kind of outage.

Every answer that left something out is logged under Activity, Resolutions: the package, the token's application and environment, how many versions were offered, what was excluded and why, and the version the client then downloaded.

For container images, an image with serious advisories that an upgrade fixes is refused, naming the advisories. Only count what has a fix keeps unfixable operating system CVEs from blocking everything.

A team that needs a vulnerable version for a while asks for a waiver: it names the advisory ids, so a new advisory published later is never covered by an old waiver.

packages.example.com/_admin/
Vulnerabilities. What the rules allow and the cache holds, with the advisories against it.

In short

  • Pick the lowest severity that gets a version left out
  • Metadata is trimmed, so ranges resolve to the newest safe version
  • Exact downloads of an excluded version get a 403 with the advisory
  • Never swaps in a version outside the requested range
  • Every exclusion logged with the version that was chosen instead

In the documentation

Goes well with

  • Vulnerability monitoring OSV, CISA KEV and FIRST EPSS against everything allowed and cached. npm audit answered locally.
  • Waivers A written down, time boxed yes for one finding on one package, scoped to an app or environment.
  • Cooling off new releases Brand new versions wait a few days before your builds see them, which is when hijacks get caught.

One container, about two minutes

A Linux box with Docker, or one without it, and a reverse proxy for TLS. The installer does the rest and it is safe to run twice. Free, MIT licensed, nothing to sign up for.