Home / Companies / JFrog / Blog / June 2021

June 2021 Summaries

16 posts from JFrog

Filter
Month: Year:
Post Summaries Back to Blog
Enterprise software development has evolved from small, centralized teams to a globally distributed, collaborative effort, necessitating advanced tools for efficient workflow management. JFrog Artifactory addresses this need with its Federated Repositories, a novel bidirectional mirroring technology that enables seamless synchronization of binaries and metadata across multiple sites. This system allows geographically dispersed DevOps teams to work with minimal latency, ensuring all teams have access to the latest artifacts and information. Federated repositories accommodate various topologies, such as star and full mesh, to suit different organizational needs, providing secure, scalable, and easy-to-manage solutions for global software development. By allowing local administrators to control access and maintain configurations, the platform supports hyper-local speeds and robust disaster recovery, effectively turning multiple sites into a unified development environment.
Jun 30, 2021 1,307 words in the original blog post.
JFrog has announced its acquisition of Vdoo, an Israeli-based product security company, to enhance its security capabilities by integrating Vdoo's technology and team into the JFrog Platform. This acquisition aims to unify development and security teams by providing a holistic security approach that reduces friction caused by disparate security tools and improves the efficiency of addressing security vulnerabilities. With the integration of Vdoo, JFrog plans to extend its capabilities to provide a comprehensive security solution that includes contextual threat analysis, zero-day vulnerability detection, and runtime protection for IoT and embedded devices. The acquisition also aims to strengthen security engineering efforts by incorporating Vdoo's expertise and advanced security research into the platform. Moving forward, JFrog intends to expand its Xray vulnerability scanning in the third quarter of 2021 and integrate further with the JFrog Platform, enhancing support for embedded software and offering a seamless security experience for developers and security teams.
Jun 29, 2021 1,029 words in the original blog post.
Tali Notman, JFrog's Chief Revenue Officer, has been recognized as one of the most influential women by the Silicon Valley Business Journal, reflecting her significant contributions to the tech industry, particularly in sales leadership. Joining JFrog as its sixth employee and first sales representative, Tali has successfully crafted the company's go-to-market strategy, growing its customer base from none to over 6,000, including major Fortune 100 companies, and expanding JFrog's presence to 10 countries. Her leadership has been pivotal in transforming JFrog from a small startup into a publicly traded company with a comprehensive DevOps platform. Tali's approach, which emphasizes teamwork and customer experience, has not only driven customer acquisition and retention but also fostered a culture of collaboration and success at JFrog, where women hold 50% of management roles. Her commitment to excellence and her belief in the power of teamwork have played a crucial role in JFrog's continued growth and innovation.
Jun 25, 2021 591 words in the original blog post.
DevSecOps and security are paramount for DevOps professionals, particularly following significant cybersecurity incidents and new governmental mandates requiring vetted software applications and trusted Software Bill Of Materials (SBOM). At the swampUP 2021 virtual conference, JFrog emphasized the importance of DevSecOps by featuring experts who shared insights on implementing efficient security practices. Sven Ruppert introduced easy-to-implement DevSecOps practices in a session that likened the experience to a Zen journey, while John Willis offered a philosophical and practical exploration of the current state of DevSecOps. Anuj Sharma demonstrated scaling DevSecOps with Amazon EKS and the JFrog Platform, and Quintessence Anx provided a step-by-step guide to effective DevSecOps implementation. Chris Riley discussed embedding security into software pipelines, emphasizing visibility and the role of JFrog and Splunk in enhancing DevSecOps. Additional presentations and resources, including a white paper on security and compliance with the JFrog Platform, are available on the JFrog swampUP resource page.
Jun 24, 2021 512 words in the original blog post.
The blog post explores the risks associated with the modern software development process, particularly focusing on how attackers can introduce malicious code through methods like typosquatting and dependency confusion in open-source projects. The researchers, leveraging findings from Sonatype, identified malicious PyPI packages that contained crypto-miners exploiting Ethereum or Ubiq. The text details the methods through which attackers obfuscate their code to evade detection and how these can be reversed for analysis. It also highlights how automated detection techniques, such as checking for the use of eval functions or analyzing package names with short edit distances from popular ones, can be employed to identify potential threats. The post offers actionable solutions for developers to protect their projects, such as inspecting dependencies and managing repository queries, and describes efforts by package maintainers to reserve "typosquatting-prone" names to prevent abuse.
Jun 24, 2021 1,691 words in the original blog post.
JFrog's DevOps platform, featuring Artifactory and Xray, enhances DevSecOps practices by integrating security vulnerability insights and artifact management across various tools and systems used by development teams. Xray's deep-recursive scanning identifies vulnerabilities in open-source dependencies, which can be monitored through Artifactory and visualized via a unified dashboard. To ensure teams can efficiently respond to these vulnerabilities, JFrog offers integrations with collaboration tools like Slack and Microsoft Teams, as well as observability platforms like DataDog, Splunk, Elastic, and Prometheus/Grafana. These integrations enable rapid communication and detailed investigation of security issues, allowing for quick remediation. JFrog's partnership with incident and change management systems like PagerDuty and Jira streamlines the process of tracking and resolving incidents by creating automatic links between detected vulnerabilities and project management workflows. This interconnected system transforms isolated tools into a cohesive DevSecOps machine, facilitating a comprehensive and responsive security management process across the development lifecycle.
Jun 23, 2021 960 words in the original blog post.
Managing Java dependencies efficiently can be streamlined using a Maven or Gradle repository, which provides secure and consistent access to shared dependencies in a centralized location. The JFrog cloud subscription, including tools like JFrog Artifactory, Xray, and Pipelines, facilitates the quick setup of local, remote, and virtual Maven/Gradle registries. The process involves logging into the environment, creating local and remote repositories to store custom and third-party dependencies, and establishing a virtual repository to manage these resources. Users need Maven or Gradle installed, along with the JFrog CLI, to configure and automate access to JFrog products. By following these steps, users can build projects by resolving dependencies from Artifactory and ultimately publish build information back to the repository for easy access and management within the JFrog platform.
Jun 22, 2021 636 words in the original blog post.
JFrog has streamlined the installation and maintenance of self-hosted instances of its DevOps Platform on AWS by introducing a set of AWS CloudFormation modules, now available in the AWS CloudFormation Public Registry. These modules facilitate the setup of JFrog Artifactory and Xray, enabling AWS customers to manage artifact repositories, Software Composition Analysis (SCA), and license compliance with ease. Customers can use these JFrog-verified modules to consistently provision services within their AWS accounts, treating their infrastructure as code. The modules support installation in both new and existing VPCs and are designed to work with EC2 instances, requiring appropriate JFrog self-hosted licenses. Users can find, activate, and use these modules through the AWS Console, with sample templates available on GitHub to assist in the installation process, ensuring a secure and scalable deployment of JFrog software on AWS.
Jun 21, 2021 637 words in the original blog post.
In a recent "ask me anything" session at swampUP, JFrog product leaders addressed questions about new features and capabilities, emphasizing enhancements to their platform. Noteworthy updates include the release of a new reporting module for JFrog Xray, which enables detailed vulnerability and policy violation reports with advanced filters and export options, as well as cloud-native high availability features that streamline maintenance tasks across cluster nodes in the JFrog DevOps Platform. The session highlighted the advantages of JFrog Pipelines, such as seamless integration with other JFrog products and scalability, offering a native integration with Jenkins to facilitate gradual migration. The discussion also covered the Signed Pipelines feature for ensuring artifact integrity, enhanced Artifactory performance, and the flexibility of the Private Distribution Network. Participants inquired about disaster recovery strategies, third-party monitoring tools, and competitive aspects with other platforms like WhiteSource. Furthermore, JFrog's response to dependency confusion attacks involves a new repository setting called Priority Resolution to safeguard against unauthorized package downloads.
Jun 18, 2021 3,114 words in the original blog post.
JFrog has launched an updated Technology Partner Program aimed at enhancing its ecosystem of integration partners and reinforcing its commitment to seamless integration within the DevOps community. The initiative provides partners with resources such as product training, marketing support, and technical assistance, emphasizing technology openness and interoperability to produce innovative solutions for joint customers. This program promises benefits for partners, including increased profitability through joint go-to-market activities, enhanced brand awareness, and access to a community of peers. It also offers technical training and support to facilitate integration with the JFrog DevOps Platform, benefiting customers with a diverse array of innovative solutions across various areas such as CI/CD, automation, security, and compliance. Additionally, the program features a self-service partner portal for streamlined management of technology integration and business activities.
Jun 16, 2021 526 words in the original blog post.
JFrog successfully migrated its cloud services from Helm v2 to Helm v3 to improve security and efficiency, as Helm v3 eliminates the need for the Tiller server and offers new features and greater stability. The migration process involved using the helm-2to3 plugin and could be done manually for a few releases or automated for larger numbers using shell scripts, which was necessary for JFrog's enterprise-scale operations running thousands of Kubernetes clusters across AWS, Azure, and Google Cloud. While the migration was mostly straightforward, challenges included ensuring Helm v3 labels and annotations were added to migrated Kubernetes objects, particularly for older releases that failed to upgrade automatically. The transition highlights the importance of staying up-to-date with software versions to maintain security and functionality across cloud services.
Jun 14, 2021 954 words in the original blog post.
SwampUP 2021 highlighted a pivotal moment for DevOps, emphasizing its integral role in global innovation and digital transformation. DevOps has transcended traditional IT boundaries, becoming essential in various sectors such as education, healthcare, and business, with developers leading this charge. The conference underscored the importance of binaries as the core of the DevOps workflow, illustrating the shift towards comprehensive management of the entire software lifecycle. JFrog introduced significant advancements, including the JFrog Private Distribution Network, to enhance software delivery and binary lifecycle management at scale. The event also featured insights from leaders of prominent DevOps companies, acknowledging the growing responsibilities and stress on developers as they adapt to complex, distributed architectures. JFrog's commitment to supporting developers and DevOps professionals with innovative tools reflects their mission to facilitate seamless software releases globally, reinforcing the notion that every company is now fundamentally a DevOps company.
Jun 09, 2021 1,186 words in the original blog post.
JFrog's swampUP DevOps conference highlighted the importance of collaboration in achieving liquid software, featuring expert insights from key partners on addressing critical DevOps challenges. The event showcased deep-dive technical sessions and partner contributions on topics such as the integration of Kubernetes and serverless technologies for cloud-native transformations, demonstrated by Microsoft Azure, and the support of cloud DevOps through Red Hat's OpenShift. Tidelift addressed software supply chain security amidst rising attacks, while NetApp's integration with the JFrog Platform aimed to minimize developer downtime through enhanced storage solutions. Amazon Web Services highlighted the application of machine learning models to improve operational performance via its DevOps Guru. Additional insights from companies like Google and Splunk covered a range of DevOps concerns, with accessible resources for further exploration available on JFrog's swampUP resource page.
Jun 04, 2021 554 words in the original blog post.
JFrog's recent swampUP conference highlighted the importance of DevOps as a central force in global business, drawing a diverse audience of developers, engineers, and industry leaders from companies like Amazon, Google, and Salesforce. The event featured the introduction of several pioneering JFrog solutions, including the Private Distribution Network (PDN) for accelerated and secure software distribution, Signed Pipelines for cryptographic verification of pipeline integrity, Federated Repositories for synchronized management of binaries across multiple sites, Scoped Tokens for enhanced security, and Dependency Scanning for early detection of vulnerabilities in open-source software. These innovations underscore the growing demand for comprehensive, secure pipeline management solutions. The conference celebrated community contributions, with Jayne Groll receiving the Carl Quinn Best Speaker Award, and emphasized the collaborative spirit and human factors driving DevOps innovation. Plans are already underway for the next hybrid swampUP event, with a focus on continued community engagement and development.
Jun 03, 2021 674 words in the original blog post.
In February 2021, researchers identified and disclosed six critical vulnerabilities in the Realtek RTL8195A Wi-Fi module, used in many connected devices, and later expanded their analysis to discover two additional vulnerabilities in the Realtek RTL8710C module. These vulnerabilities, which reside in the WPA2 handshake mechanism, can lead to complete control of the Wi-Fi module and potential root access on an embedded device's operating system if exploited. Successful exploitation requires an attacker to be on the same Wi-Fi network or know the network's pre-shared key (PSK). Realtek promptly patched these vulnerabilities, and there is no evidence of them being exploited in the wild. The blog post details the technical aspects of these vulnerabilities, including stack-based buffer overflows, and highlights the automated methods used for their detection. The vulnerabilities affect various industries, including agriculture, automotive, and healthcare, as the RTL8710C module is a cost-effective alternative to other Wi-Fi modules like the ESP8266. It emphasizes the importance of updating firmware to versions built after January 11, 2021, or applying strong WPA2 passphrases to mitigate the risks.
Jun 02, 2021 2,226 words in the original blog post.
GitHub Package Registry is a package management service integrated with GitHub, allowing developers to publish packages alongside their source code, but it does not replace JFrog Artifactory or serve as a comprehensive centralized repository like DockerHub or Maven Central. GitHub's service supports six package types and offers a hybrid solution through GitHub Enterprise Server, yet it lacks the extensive features and integrations that Artifactory provides, such as support for 30 package technologies, on-prem and multi-cloud deployment options, and comprehensive third-party tool integrations. Artifactory remains the preferred choice for managing a wide array of packages and ensuring a secure, traceable DevOps pipeline, highlighted by its universal support, robust security features, and flexibility, making it a trusted solution for many global enterprises and tech giants.
Jun 01, 2021 1,123 words in the original blog post.