Go Back

JFrog Curation

jfrog.com

JFrog Curation is a DevSecOps tool that helps organizations secure their software supply chain by curating and blocking malicious or risky open-source packages and ML models. It provides centralized visibility and control over third-party package downloads, automates policy enforcement, and offers a catalog of open-source package metadata for security and compliance.

Features
0/12
See all

No common features found

Pricing
Tiered
See all

Pro

$150.00 monthly
  • Universal Binary Repository
  • Release Lifecycle Management
  • Unlimited Docker Hub Pulls
  • Complete Container Registry
  • Cloud-native Managed Platform

Enterprise X

$950.00 monthly
Popular
  • Everything in Pro, plus:
  • Globally Federated Repositories
  • Enterprise Access Control (SSO)
  • Enhanced SCA & Model Security
  • AI/ML Lifecycle Management
  • AI/ML Serving
  • One Platform Experience with GitHub

Enterprise +

Custom
  • Everything in Enterprise X, plus:
  • Global Access Federation
  • Software Distribution
  • Distributed Edge Nodes
  • Advanced Traffic Management
  • Third Party Evidence Collection
  • Multi-cloud and Shadow AI/ML Deployments
  • Streaming Feature Store for ML

Pro X

$27,000.00 yearly
  • Universal Binary Repository
  • Release Lifecycle Management
  • Enhanced SCA & Model Security
  • Complete Container Registry

Enterprise X

$48,000.00 yearly
Popular
  • Everything in Pro, plus:
  • High Availability
  • Globally Federated Repositories
  • Enterprise Access Control (SSO)
  • AI/ML Lifecycle Management
  • AI/ML Serving
  • One Platform Experience with GitHub

Enterprise +

Custom
  • Everything in Enterprise X, plus:
  • Global Access Federation
  • Software Distribution
  • Distributed Edge Nodes
  • Private CDN
  • Third Party Evidence Collection
  • Multi-cloud and Shadow AI/ML Deployments
  • Streaming Feature Store for ML
Rationale

JFrog Curation is a software supply chain security tool that focuses on curating and blocking malicious or risky open-source packages and ML models. It is designed for DevSecOps teams to manage software dependencies and ensure compliance and security within development pipelines. This is fundamentally different from URList, which is a minimalist web app for curating, organizing, and sharing collections of URLs for general knowledge management and content creation. There are no matching features between the two concepts.