JFrog Artifactory
Vetted Packages Through Your Artifactory Instance
ActiveState delivers built-from-source packages as native artifacts directly into your JFrog Artifactory instance. Your teams keep using Artifactory the same way they always have.

What ActiveState adds to Artifactory
Packages built from source
Every package in the catalog is compiled in SLSA Level 3 infrastructure. Artifactory stores and distributes them, and ActiveState provides the provenance and security guarantees behind them.
Continuous remediation
When a CVE affects a package in your catalog, ActiveState rebuilds and publishes the patched version. Artifactory serves the update to your teams automatically through your existing promotion workflows.
Full provenance and SBOMs
Every artifact includes build provenance, verified licensing, and a complete SBOM. Artifactory's metadata capabilities surface this information alongside the packages themselves.
FAQs
Still have questions?
Talk to our team.
Do I need a specific Artifactory tier?
ActiveState works with Artifactory Pro, Enterprise, and Cloud editions. Any tier that supports remote repositories can serve as a delivery point for your Curated Catalog.
What package formats does ActiveState deliver through Artifactory?
Native formats for each ecosystem: Python Wheels, Maven JARs, npm tarballs, NuGet packages, and more. Artifactory treats them as standard artifacts.
Secure Your Artifactory Pipeline
Talk to our team about connecting your Curated Catalog to your Artifactory instance.
%20(1).webp)



.webp)




