OrbitalReg Sign in →

Comparison

Free forever · no contract

The free alternative to JFrog Xray and Curation.

Xray scans what's already in your registry. Curation blocks risky packages before they enter. Both are paid products on top of a paid platform. OrbitalReg Free does both jobs — CVE scanning with Trivy and Grype, curated proxies with quarantine, and verify-on-pull gates — self-hosted on your hardware, with no contract and no cost.

Get OrbitalReg free → See the comparison

What Xray does

Scan what's inside.

JFrog Xray is software-composition analysis for artifacts already in Artifactory: known CVEs, licence conflicts, policy violations. In OrbitalReg, that role is covered by Trivy + Grype scanning on every artifact at upload and on demand, with pull-gate policies that block by severity, CVE-ID, format or tag — and auto-quarantine when a new CVE lands on something you already host.

What Curation does

Block before entry.

JFrog Curation gates your remote repositories so risky open-source packages never enter your pipeline. In OrbitalReg, that role is covered by curated remote proxies with patch-version quarantine: new upstream versions are held for N hours before they're served, and advisory-listed versions get a 403 fleet-wide from one policy change. It's the control that would have kept the 90-minute Rust crates backdoor and the keyv npm worm out of your builds.

Feature by feature

OrbitalReg Free vs. Xray + Curation.

"Paid" below means the capability requires a commercial JFrog subscription or add-on tier. Vendor packaging changes over time — verify current JFrog tiers against their pricing page.

Capability JFrog Xray / Curation OrbitalReg Free
CVE scanning of hosted artifacts Paid — Xray subscription ✓ Free — Trivy + Grype at upload & on demand
Block risky packages before entry Paid — Curation add-on ✓ Free — curated proxies + policy engine
Patch-version quarantine (hold new upstream versions) Paid — via Curation policies ✓ Free — hold N hours before serving
Pull-gate on advisory disclosure (fleet-wide 403) Paid — Xray policies + actions ✓ Free — one policy change, all repos
Signature verification on pull (Sigstore, PGP, X.509, CMS) Partial — varies by tier/plugin ✓ Free — verify-on-pull, per-repo policy
SIEM-ready structured audit log Paid — platform tiers ✓ Free — JSON out of the box
Air-gapped operation Paid — self-hosted enterprise tiers ✓ Free — one config flip, no phone-home
Contract / subscription required Yes — commercial subscription No — no contract, no signup wall
Proprietary vulnerability research & contextual analysis Yes — JFrog security research, Advanced Security No — OSS scanner engines (see caveat below)
SSO / SAML, multi-cluster scaling, support Paid Paid — that's what our tiers add

How "free" works

No contract. No signup wall. No expiry cliff.

30 days

full trial of everything — every commercial feature, no NDA, no credit card

forever

the security layer stays free after the trial: scanning, curation, quarantine, gates, audit

0

builds or deploys ever blocked by an expired trial — degradation never touches your pipeline

The model is deliberate: the security layer is the part of a registry that should never sit behind a paywall, because an unscanned, uncurated dependency hurts everyone downstream. Paid tiers add the things growing teams need — SSO/SAML, multiple cluster licences, support, lifetime price locks — and start at €100/year.

The honest caveat. Xray is a mature commercial SCA product with JFrog's proprietary vulnerability research behind it, and Advanced Security adds secrets detection and contextual applicability analysis that we do not claim to replicate. OrbitalReg scans with the open-source Trivy and Grype engines — broad, fast-moving coverage, but a different research pipeline. If scanner depth is your deciding criterion, do what we'd do: run both against one of your own SBOMs and compare findings. Where OrbitalReg wins is the part JFrog charges for — the curation layer, the quarantine window, the pull-gate — free, on your hardware, with no contract to negotiate.

Proof of approach

What this defence looks like against real attacks.

Cargo · Aug 2026

Rust crates backdoor →

Poisoned versions live for ~90 minutes. A quarantine window longer than that keeps them out entirely.

npm · Aug 2026

The keyv npm worm →

A self-propagating credential worm racing advisories — blunted by curated proxies and the pull-gate.

All analyses: supply-chain case studies → · Moving off Artifactory? Migration playbooks →

Frequently asked

The questions procurement will ask.

Is OrbitalReg really free as an Xray and Curation alternative?

Yes. Every install starts with a 30-day full trial — no contract, no credit card. When the trial ends, the security layer stays free forever: CVE scanning, curated proxies, patch-version quarantine, verify-on-pull gates and the SIEM-ready audit log keep running, and an expired trial never blocks a build or a deploy. Commercial features (SSO/SAML, multi-cluster scaling, support) are what the paid tiers add.

What is the difference between JFrog Xray and JFrog Curation?

Xray scans artifacts that are already in your registry for known vulnerabilities and licence issues. Curation sits in front of your remote repositories and blocks risky open-source packages before they enter. OrbitalReg Free covers both roles: Trivy and Grype scan every artifact at upload, and curated proxies with quarantine and pull-gate policies stop unvetted upstream versions from ever reaching a build.

Do I need a contract or subscription to use OrbitalReg Free?

No. There is no contract, no subscription and no signup wall. You install the Helm chart, run the 30-day full trial, and the free security layer continues after it — permanently. Paid tiers exist for teams that want SSO, multi-cluster licences and support, and they are optional.

What does JFrog Xray have that OrbitalReg does not?

Xray ships JFrog's proprietary vulnerability research and, with Advanced Security, features like secrets detection and contextual applicability analysis. OrbitalReg scans with the open-source Trivy and Grype engines and publishes results locally — strong coverage, but a different research pipeline. We recommend running both against one of your own SBOMs and comparing findings before you switch.

Replace Xray + Curation this week

One Helm chart. Thirty minutes. No contract.

Install the trial, point one repository at an OrbitalReg curated proxy, and watch the first quarantine hold a fresh upstream version. If you'd rather talk it through first, Rico — the founder — does the walkthroughs himself.

Get OrbitalReg free →