List of Available Conditions

JFrog Security User Guide

ft:sourceType
Ftml

This table lists the available conditions in Curation:

CategoryConditionDescriptionCustom condition availableRelaxation ParametersSupported Package Types
SecurityMalicious packageBlocks 3rd party packages that the JFrog Security Research team has identified as malicious.NoN/AAll
SecurityCVE with CVSS (all score combinations)Blocks 3rd party package versions with a known CVE with NVD CVSS score (all combinations)Yes
  • EPSS score consideration
  • Allow if no fixed version exists
  • Allow If CVE already exists in your repository
All (except Docker)
SecurityOpenSSFBlock packages based on one or more scorecard checks.YesDisregard if the score does not exist.All (except Docker)
SecurityPackage Vulnerable to CVEDetects if the 3rd party package is vulnerable to the configured CVE IDYesN/AAll (except Docker)
SecurityBlock packages listed by Catalog labelsBlocks 3rd party packages that are on a blocked listYesN/AAll (except Docker)
SecurityAllow only packages listed by Catalog labelsBlocks 3rd party any packages that are not on the allowed listYesN/AAll (except Docker)
LegalBlock list by LicenseBlocks 3rd party packages with any version that you defineYesAllow if one or more package licenses are not on the list.All (except Docker)
LegalAllow list by LicenseBlocks 3rd party packages with any version that is not on the defined listYesAllow if at least one package license is on the list.All (except Docker)
OperationalImage is not Docker Hub officialDetects Docker Images from the Docker Hub registry that do not have “Docker Official Image"NoN/ADocker
OperationalPackage version is aged (no newer version identified)Blocks 3rd party package versions whose release date is more than 2 years old, and no newer version of the package exists.YesN/AAll (except Docker)
OperationalPackage version is aged (new version available)Blocks 3rd party package versions whose release date is more than 180 days older than the package’s latest version release date.NoN/AAll (except Docker)
OperationalPackage version is immatureBlocks 3rd party packages whose version release date is less than the defined number of dates oldYesAllow if fixes CVE in your repositoriesAll (except Docker)