Home / Companies / JFrog / Blog / May 2021

May 2021 Summaries

7 posts from JFrog

Filter
Month: Year:
Post Summaries Back to Blog
JFrog recently unveiled several innovations at its annual swampUp DevOps conference aimed at enhancing its DevOps Platform for end-to-end binary lifecycle management, which is crucial for enterprise DevOps and large-scale modern application delivery. New features include Federated Repositories in JFrog Artifactory, which manage binaries across multi-site topologies and ensure rapid access to changes across remote locations, and Signed Pipelines in JFrog Pipelines, which enhance build integrity and security by creating an immutable, cryptographically-signed ledger. JFrog also introduced dependency scanning to detect OSS vulnerabilities early in the development lifecycle and announced new platform integrations to improve traceability and collaboration across the DevOps lifecycle. These integrations include a two-way link with Jira Cloud, as well as connections with tools like PagerDuty, Datadog, and Splunk, to enhance incident management and deliver actionable insights for development strategies.
May 26, 2021 833 words in the original blog post.
JFrog has announced the introduction of its Private Distribution Network (PDN) during their DevOps user conference, swampUP. This innovative solution is designed to help enterprises manage software updates across a vast and varied network infrastructure efficiently and securely. PDN addresses the challenges of deploying software rapidly to large-scale, hybrid environments, which include datacenters, cloud networks, and edge devices, by offering accelerated distribution capabilities and overcoming network limitations. The solution utilizes a secure, enterprise-grade P2P protocol and local CDN caches to optimize download speed and network utilization. It facilitates hierarchical content distribution through distribution groups and nodes, allowing enterprises to design network paths that minimize latency. The JFrog Platform integrates PDN as part of its comprehensive DevOps solution, promising enhanced security, compliance, and simplified management, with a beta version available before its general release in 2022.
May 26, 2021 1,083 words in the original blog post.
The JFrog Free subscription is a cloud-based DevOps platform designed to help developers, DevOps engineers, system administrators, and students tackle common DevOps challenges within a sandbox environment. By offering guided journeys, the platform facilitates onboarding through five key steps: signing up, choosing a path, creating repositories, setting up and deploying artifacts, and adding users to projects. It provides tools like Artifactory for repository management, Xray for security scanning, and pipelines for CI/CD automation, supporting various package types. Users can access training through JFrog Academy and are encouraged to stay active with a monthly usage policy. The platform aims to enhance the development process by integrating seamless automation and efficient workflow management.
May 24, 2021 1,104 words in the original blog post.
The recent Executive Order by the United States Government emphasizes the importance of cybersecurity as a component of national security, mandating that software applications and their components undergo thorough vetting. Within 60 days, new regulations will require vendors to adhere to minimum standards for testing software source code and providing a Software Bill of Materials (SBOM), which details the components and their provenance. This order aims to prevent cyber incidents and applies initially to US Federal Government entities and those doing business with them, with expectations to influence the private sector over time. Companies are urged to adopt practices such as comprehensive component inventory, vulnerability scanning, secure development environments, and cryptographically signed releases to comply with impending standards. The initiative reflects an awakening to the risks posed by cyber attacks and has significant implications for developers and DevOps practitioners, highlighting the need for proactive security measures in software development processes.
May 21, 2021 913 words in the original blog post.
JFrog has introduced new features to enhance its DevOps Platform, specifically JFrog Xray, which is recognized as a reliable software composition analysis (SCA) tool for identifying open-source vulnerabilities and license compliance issues. Xray now supports scanning Conan packages, as well as C and C++ builds, deployed to JFrog Artifactory, and integrates with various build systems, offering flexibility in managing pre-compiled binaries. The platform has incorporated the Common Vulnerability Scoring System (CVSS) v3 to prioritize security threat responses, while still supporting CVSS v2 if needed. Additionally, JFrog Xray has received Red Hat certification, ensuring its vulnerability and license compliance data are accurate for Red Hat packages, thereby boosting confidence for enterprises using RPM packages. The JFrog Platform has also been certified for Red Hat's OpenShift Operator and UBI Container Image, promising enhanced reliability and security, making these updates significant in the evolving landscape of DevSecOps.
May 11, 2021 596 words in the original blog post.
JFrog was recognized as a "Best Place to Work" by The San Francisco Business Times and Silicon Valley Journal due to its intentional and well-planned company culture that prioritizes employees and values cultural fit alongside professional skills. The emphasis on a people-first approach has been instrumental in navigating the challenges posed by the COVID-19 pandemic, including the transition to remote work. During this period, JFrog supported its employees by providing stipends for home office setups and internet, as well as implementing monthly rest days to help manage the stress of the new normal. Despite these disruptions, JFrog not only maintained high employee morale but also successfully went public, completed an IPO, and expanded its workforce, all while reinforcing its strong company culture through initiatives that ensured employee engagement and satisfaction.
May 07, 2021 630 words in the original blog post.
Managing user and group lifecycles becomes challenging as organizations grow, increasing the need for effective access and security management across multiple applications. The JFrog Platform addresses this by integrating the SCIM v2.0 protocol, which simplifies identity management by allowing IT departments to manage users and groups through Identity Providers like Okta or Azure Active Directory. This integration centralizes user management, enhancing security and compliance by enabling quick enablement or disabling of user access, and reduces the time and effort required for these tasks. The SCIM protocol's implementation in JFrog facilitates seamless user and group management, offering automated and intuitive operations such as creating, deleting, and deactivating users, which are crucial as the organization's user base expands. This integration not only streamlines administrative tasks but also helps in maintaining security and compliance by concentrating user management in one place and allowing easy access control adjustments.
May 04, 2021 926 words in the original blog post.