Home / Companies / JFrog / Blog / November 2018

November 2018 Summaries

4 posts from JFrog

Filter
Month: Year:
Post Summaries Back to Blog
JFrog has announced the release of a new version of JFrog Xray, which is now available in a cloud-based SaaS model, emphasizing its integration with JFrog Artifactory to provide a comprehensive cloud DevSecOps solution. This release aligns with the "shift-left" philosophy by integrating security earlier into the development process, a necessity given the increase in software vulnerabilities and the widespread use of containers. JFrog claims that Xray has helped customers avoid numerous vulnerabilities since 2016, thanks to its accurate scans that minimize false positives and save significant time. Xray also assists compliance and legal teams in navigating OSS licenses and requirements. While Xray is now available in the cloud, it remains accessible on-premise, offering the same functionality to accommodate hybrid and multi-cloud DevOps strategies. Existing JFrog Cloud customers can easily upgrade Xray in their Artifactory Cloud instances, and those with on-premise setups can explore the cloud model with no risk. An informational webinar about Xray is scheduled for November 28.
Nov 27, 2018 526 words in the original blog post.
The JFrog Enterprise+ platform offers a comprehensive pipeline for managing the flow of binaries from build to production, covering the entire software deployment process. It facilitates a seamless workflow that includes managing JFrog services and creating, signing, and securely distributing release bundles to various target destinations. Key components of this process involve JFrog Mission Control for an overview of sites and nodes, JFrog Source Artifactory for selecting files for release bundles, JFrog Distribution for the creation and distribution of these bundles, and JFrog Artifactory Edge for receiving and inspecting release bundles through the REST API. The platform ensures that release bundles are effectively managed within the release bundles repository, consolidating the end-to-end deployment solution provided by Enterprise+.
Nov 14, 2018 141 words in the original blog post.
JFrog offers comprehensive Docker security solutions through its Xray tool, which provides end-to-end coverage for the lifecycle of Docker images, focusing on development management, vulnerability analysis, license compliance, artifact flow control, and distribution. Xray utilizes metadata from JFrog Artifactory to conduct deep recursive scans of all container layers, delivering transparency into component architecture and assessing the impact of vulnerabilities across Docker images. It not only identifies issues in base layers but also scrutinizes dependencies and software artifacts, ensuring thorough vulnerability checks. Xray is particularly notable for its ability to scan operating system packages, a critical area for vulnerabilities and licensing issues, and it can trigger CI pipeline failures if license changes are detected. The tool also offers the convenience of generating license compliance reports and is now accessible in a cloud model, promoting reduced costs, time, and risk while enabling incremental updates to applications in production.
Nov 07, 2018 412 words in the original blog post.
Harness offers a Continuous Delivery as-a-Service platform that automates CD processes using machine learning and security features, integrating with tools like Artifactory and XRay to streamline the deployment of artifacts into production. Despite the prevalence of Continuous Integration tools like Jenkins that manage code to artifact processes, Continuous Delivery remains a complex challenge, often involving manual and maintenance-heavy scripts. Harness aims to simplify this by providing a turnkey service that allows developers to create dynamic deployment pipelines, promoting artifacts across environments with ease. The integration with JFrog's Artifactory, essential for managing artifacts, enables users to define application hierarchies and automate version control, while incorporating JFrog XRay for security scans ensures that deployment workflows are both efficient and secure. This collaboration illustrates a significant advancement towards more automated and manageable Continuous Delivery pipelines, addressing prevalent challenges in modern DevOps practices.
Nov 01, 2018 710 words in the original blog post.