How to Route Package Traffic Through JFrog PTC With Zscaler: Setup and Policy Configuration
JFrog’s Package Traffic Controller (PTC) intercepts an organization’s public package traffic at the network layer and routes it through JFrog, so JFrog Curation policies and audit logging apply to every intercepted install without changing how developers work.
PTC integrates with the security edge (SASE) tool your organization already uses to inspect outbound traffic, redirecting matching package requests to Artifactory's package-reroute endpoint. Once the security edge client, trust store, and redirect policies are configured, every process on a workstation is governed consistently, whether the install comes from a human developer or an AI coding agent.
PTC works with your existing SASE vendor: Zscaler Internet Access, Netskope, or Cloudflare Gateway, rather than requiring an additional tool. Configuration does require a remote repository as the repo_key; virtual repositories aren't supported, keeping PTC aligned with the upstream-facing repository used for consumption tracking and Curation.
The result: consistent security coverage and visibility over open-source package installs across your organization, enforced at the network layer with no workflow disruption for developers.
⏰ Timestamps
00:00 - Checking NPM Default Behavior
00:54 - Workstation Setup & Zscaler CA Configuration
01:51 - JFrog Platform & Remote Repository Setup
02:58 - Configuring & Verifying JFrog Curation Policies
03:53 - Configuring Zscaler Inspection & URL Filtering
06:25 - Verifying PTC Package Rerouting & Security Blocking