Comparison
Free forever · no contractXray scans what's already in your registry. Curation blocks risky packages before they enter. Both are paid products on top of a paid platform. OrbitalReg Free does both jobs — CVE scanning with Trivy and Grype, curated proxies with quarantine, and verify-on-pull gates — self-hosted on your hardware, with no contract and no cost.
What Xray does
JFrog Xray is software-composition analysis for artifacts already in Artifactory: known CVEs, licence conflicts, policy violations. In OrbitalReg, that role is covered by Trivy + Grype scanning on every artifact at upload and on demand, with pull-gate policies that block by severity, CVE-ID, format or tag — and auto-quarantine when a new CVE lands on something you already host.
What Curation does
JFrog Curation gates your remote repositories so risky open-source packages never enter your pipeline. In OrbitalReg, that role is covered by curated remote proxies with patch-version quarantine: new upstream versions are held for N hours before they're served, and advisory-listed versions get a 403 fleet-wide from one policy change. It's the control that would have kept the 90-minute Rust crates backdoor and the keyv npm worm out of your builds.
Feature by feature
"Paid" below means the capability requires a commercial JFrog subscription or add-on tier. Vendor packaging changes over time — verify current JFrog tiers against their pricing page.
| Capability | JFrog Xray / Curation | OrbitalReg Free |
|---|---|---|
| CVE scanning of hosted artifacts | Paid — Xray subscription | ✓ Free — Trivy + Grype at upload & on demand |
| Block risky packages before entry | Paid — Curation add-on | ✓ Free — curated proxies + policy engine |
| Patch-version quarantine (hold new upstream versions) | Paid — via Curation policies | ✓ Free — hold N hours before serving |
| Pull-gate on advisory disclosure (fleet-wide 403) | Paid — Xray policies + actions | ✓ Free — one policy change, all repos |
| Signature verification on pull (Sigstore, PGP, X.509, CMS) | Partial — varies by tier/plugin | ✓ Free — verify-on-pull, per-repo policy |
| SIEM-ready structured audit log | Paid — platform tiers | ✓ Free — JSON out of the box |
| Air-gapped operation | Paid — self-hosted enterprise tiers | ✓ Free — one config flip, no phone-home |
| Contract / subscription required | Yes — commercial subscription | No — no contract, no signup wall |
| Proprietary vulnerability research & contextual analysis | Yes — JFrog security research, Advanced Security | No — OSS scanner engines (see caveat below) |
| SSO / SAML, multi-cluster scaling, support | Paid | Paid — that's what our tiers add |
How "free" works
30 days
full trial of everything — every commercial feature, no NDA, no credit card
forever
the security layer stays free after the trial: scanning, curation, quarantine, gates, audit
0
builds or deploys ever blocked by an expired trial — degradation never touches your pipeline
The model is deliberate: the security layer is the part of a registry that should never sit behind a paywall, because an unscanned, uncurated dependency hurts everyone downstream. Paid tiers add the things growing teams need — SSO/SAML, multiple cluster licences, support, lifetime price locks — and start at €100/year.
Proof of approach
Cargo · Aug 2026
Rust crates backdoor →
Poisoned versions live for ~90 minutes. A quarantine window longer than that keeps them out entirely.
npm · Aug 2026
The keyv npm worm →
A self-propagating credential worm racing advisories — blunted by curated proxies and the pull-gate.
All analyses: supply-chain case studies → · Moving off Artifactory? Migration playbooks →
Frequently asked
Yes. Every install starts with a 30-day full trial — no contract, no credit card. When the trial ends, the security layer stays free forever: CVE scanning, curated proxies, patch-version quarantine, verify-on-pull gates and the SIEM-ready audit log keep running, and an expired trial never blocks a build or a deploy. Commercial features (SSO/SAML, multi-cluster scaling, support) are what the paid tiers add.
Xray scans artifacts that are already in your registry for known vulnerabilities and licence issues. Curation sits in front of your remote repositories and blocks risky open-source packages before they enter. OrbitalReg Free covers both roles: Trivy and Grype scan every artifact at upload, and curated proxies with quarantine and pull-gate policies stop unvetted upstream versions from ever reaching a build.
No. There is no contract, no subscription and no signup wall. You install the Helm chart, run the 30-day full trial, and the free security layer continues after it — permanently. Paid tiers exist for teams that want SSO, multi-cluster licences and support, and they are optional.
Xray ships JFrog's proprietary vulnerability research and, with Advanced Security, features like secrets detection and contextual applicability analysis. OrbitalReg scans with the open-source Trivy and Grype engines and publishes results locally — strong coverage, but a different research pipeline. We recommend running both against one of your own SBOMs and comparing findings before you switch.
Replace Xray + Curation this week
Install the trial, point one repository at an OrbitalReg curated proxy, and watch the first quarantine hold a fresh upstream version. If you'd rather talk it through first, Rico — the founder — does the walkthroughs himself.