jfrog-curation-canary
v1.0.20260912
Published
A harmless, auto-published-daily npm package used to demo JFrog Curation's Immature Package Policy (blocks any package newer than N days, regardless of threat intelligence).
Readme
jfrog-curation-canary
A deliberately harmless npm package, published automatically to the public npm
registry once a day at 05:00 UTC by .github/workflows/canary-publish.yml
in this repo.
Why does this exist?
It's a demo fixture for JFrog Curation's Immature Package Policy — a policy that blocks any package newer than N days old, regardless of whether it's actually malicious. Most supply-chain attacks (e.g. the 2025 Shai-Hulud npm worm) exploit the gap between when a malicious package is published and when threat intelligence catches up to flag it. A policy that blocks anything "too new" closes that gap without needing to know anything about the package's actual content.
Because this package is republished daily, its latest version is always guaranteed to be less than 24 hours old — which makes it a reliable, real, live target for demonstrating that block, on demand, without needing to wait for a real (and possibly actually malicious) package to show up.
What does it do?
Nothing. require-ing or running it prints a one-line message and exits. See
index.js.
Who maintains this?
Dylan Mo, a JFrog Solutions Engineer, for use in JFrog Curation product demos. Not an official JFrog product or package. If you found this while investigating a dependency and have questions about it, feel free to open an issue.
