What problem does it solve?
Set up JFrog Curation governance on an existing JFrog Platform instance by verifying that Curation is enabled, collecting a notification email, and creating a suite of security, license, and operational risk policies across remote repositories. The Block Malicious policy blocks downloads; all other policies run in dry-run (audit) mode to log violations without blocking. This workflow supports both standalone interactive onboarding and automated manifest-driven onboarding for multi-project environments.
Core Features & Use Cases
- Validates Curation status, collects a notification email, and configures policy protection across remote repositories.
- Creates eight curation policies (one block + seven dry-run) with either global or project-scoped applicability.
- Supports two operating modes: Standalone Interactive onboarding and Automated Manifest-Driven onboarding, including per-project scope and policy updates.
- Use cases include onboarding curation, enabling curation protection, or blocking malicious packages across platforms and repositories.
Quick Start
Start by providing your JFrog Platform URL and credentials to begin onboarding curation.