---
title: "Considering investing in JFrog Curation? Talk to Cloudsmith about an all-in-one alternative"
description: "JFrog moved package blocking out of XRay and into a separate product. Ingestion-time blocking now lives in JFrog Curation, not Xray - a separate product with its own license, price tag, and configuration. Without it, packages reach your pipeline without policy checks. With Cloudsmith, policy enforcement at ingestion is built into the same platform you use to manage artifacts. Before you sign on for another product to regain this functionality, let’s chat."
canonical_url: "https://cloudsmith.com/switch/jfrog-xray-curation"
last_updated: "2026-10-02T14:14:01Z"
---
# Considering investing in JFrog Curation? Talk to Cloudsmith about an all-in-one alternative

SEE WHY COMPANIES ARE MOVING TO CLOUDSMITH

## Package security without a second tool

Cloudsmith combines artifact management, package curation, vulnerability scanning, and policy enforcement - all in one platform. Talk to our team about switching

## JFrog moved package blocking out of Xray and into a separate product

Ingestion-time blocking now lives in JFrog Curation, not Xray - a separate product with its own license, price tag, and configuration. Without it, packages reach your pipeline without policy checks.  With Cloudsmith, policy enforcement at ingestion is built into the same platform you use to manage artifacts. Before you sign on for another product to regain this functionality, let’s chat.

## Migrate to Cloudsmith

Cloudsmith replaces Artifactory, Xray, and Curation with a single product: artifact management, policy enforcement, and vulnerability scanning under one license. You also get one team that works with you year-round, not just when your contract's up for renewal.

[Book a demo](/book-a-demo)

### Every package is checked against your policies at ingestion so only trusted packages reach your builds

- Prevent newly published packages from being consumed until a configurable time window elapses.
- Define usage policies via pre-set templates or in industry-standard OPA Rego.
- Detect malware at ingestion and quarantine it automatically.

### Packages are continuously re-evaluated against the latest advisories, surfacing newly disclosed risks automatically

- Apply one set of policies to every package and container, across every format and repository.
- Continuously recheck existing packages against the latest malware and CVE data.
- Trigger policy actions automatically, from quarantine to alerts.
- Prioritize fixes by EPSS exploit probability, so your team works on what matters first.

### Artifact management, security, and global delivery come together on one fully-managed cloud-native platform

- Manage 30+ package formats, including containers and ML models, in one place.
- Govern every package with built-in risk detection and policy enforcement.
- Serve artifacts from 750+ global points of presence, with high availability built in.
- Configure everything as code with Terraform, and leave upgrades, patching and scaling to us.

CASE STUDY

## A dedicated technical team with enterprise-scale migration expertise

Every migration is different. You get a dedicated team that plans around your repos, pipelines and timelines, and stays with you after go-live.

- A dedicated customer success manager who plans your migration around your environment.
- Engineer-led support for deeply technical assistance.
- A shared Slack channel for support that fits in your workflows.

- **68%:** of our customers migrate from JFrog

## The switch is easier than you think

Before you spend more money on Curation, make sure you're working with the right partners.

[Talk to a migration specialist](/book-a-migration-consultation)

[See Cloudsmith in action](/book-a-demo)
