July 2024 Summaries
10 posts from JFrog
Filter
Month:
Year:
Post Summaries
Back to Blog
The partnership between JFrog and GitHub has generated significant enthusiasm in the software development industry due to its potential to enhance DevOps, DevSecOps, MLOps, and AI practices by offering a cohesive and streamlined operational framework. By integrating the strengths of both platforms, the collaboration aims to improve the speed, quality, and security of software development processes, as discussed in a recent webinar that attracted numerous industry professionals. The integration is designed to work with both SaaS and self-hosted versions of GitHub and Artifactory, does not require GitHub Advanced Security for many features, and offers benefits like repo scanning, enhanced UI for Artifactory packages, and comprehensive security data visibility. While the partnership emphasizes the advantages of using Artifactory over other package management solutions, it also underscores JFrog's commitment to remain universal by supporting a wide range of tools and technologies. The collaboration is seen as a pivotal move in the software development lifecycle space, promising tangible benefits that surpass those offered by other solutions, with the integration's success highlighted by its widespread adoption among joint customers.
Jul 29, 2024
1,107 words in the original blog post.
Nearly two-thirds of U.S. businesses have experienced software supply chain attacks, highlighting the importance of securing the software development lifecycle (SDLC). Effective security requires identifying vulnerabilities, detecting and prioritizing threats, and remediating necessary issues across all development stages. However, using too many security tools can lead to challenges such as lack of centralized management, communication gaps, siloed operations, and slow breach response times. A platform approach can address these issues by unifying the supply chain, streamlining operations, increasing efficiency, and reducing risks, while also providing a single system of record and end-to-end traceability. Prioritizing security requirements and platform adoption is crucial to safeguarding software development operations, prompting the offer of an eBook to guide businesses in making informed decisions for future protection.
Jul 25, 2024
353 words in the original blog post.
Ansible, an open-source IT automation engine developed by Red Hat, is often used for a variety of tasks including infrastructure automation and application provisioning, and is now supported by JFrog Artifactory as of version 7.90.1. Artifactory's support for Ansible Collections allows IT teams to integrate Ansible into their software supply chain, applying best practices in binary management such as improved indexing, versioning, and authenticated access. This integration facilitates the management of Ansible Collections and Roles, enabling streamlined playbook creation and asset management. Users can access local, remote, and virtual Ansible repositories, and easily migrate legacy Ansible Roles to Collections. Artifactory supports Ansible Core version 2.17 and above, providing users with the ability to manage Ansible files efficiently and securely.
Jul 23, 2024
578 words in the original blog post.
Luis Felipe Visoso, the current CFO of Unity Software Inc., has joined JFrog's Board of Directors, bringing with him extensive experience from companies like Palo Alto Networks, AWS, Cisco, and Procter & Gamble. His decision to join JFrog was influenced by the company's mission to make software updates seamless and efficient, which he realized was crucial during a personal experience with a delayed software update. Visoso's career has been shaped by mentors like Jeff Wilke and Jon Moeller, who taught him the value of continuous learning and empowerment. He sees significant investment opportunities for JFrog in the areas of software proliferation across various industries, emphasizing the importance of trust and security. Additionally, Visoso believes that AI and machine learning present transformative opportunities and challenges, suggesting that companies that effectively leverage these technologies will maintain a competitive edge in the evolving digital landscape.
Jul 23, 2024
1,174 words in the original blog post.
Artifactory has expanded its support for Hugging Face repositories to include both datasets and models, emphasizing the importance of training machine learning models with quality datasets. This integration allows Artifactory users to proxy Hugging Face Datasets for both remote and local repositories using the Hugging Face Python library, ensuring dataset consistency and reliable performance. This setup provides fine-grain control over access to models and datasets, centralizing management and resolution of these assets. Hugging Face offers datasets either directly within its registry or through external links, with Artifactory caching the former and providing a pass-through for the latter. The initiative aims to enhance the linkage between models and their training datasets, and users can explore these features through a JFrog account or a free 14-day trial.
Jul 16, 2024
436 words in the original blog post.
JFrog's annual DevOps, Security, and MLOps conference, known for its industry significance, offers a comprehensive program from September 9-11 at Omni Resort in Austin, TX. The event provides a platform for software development executives, managers, and security professionals to learn from leading companies about tackling DevOps and security challenges, with an emphasis on implementing large-scale enterprise solutions. Participants can enhance their skills through hands-on training with cutting-edge technologies, guided by the JFrog Training Team. The conference covers the latest industry trends, emphasizing end-to-end security, tool consolidation, and a "shift-left" approach to automate security processes and improve security posture. Attendees can also engage with JFrog executives and domain experts, explore new product features, and network with peers in a relaxed setting, gaining valuable insights into best practices and emerging technologies in the field.
Jul 15, 2024
338 words in the original blog post.
The JFrog Security Research team uncovered a significant security threat when they discovered a leaked GitHub access token with administrative access to critical Python infrastructure repositories, including PyPI and the Python Software Foundation, in a public Docker container on Docker Hub. This discovery highlighted the severe potential consequences if the token had fallen into malicious hands, such as the possibility of a large-scale supply chain attack by injecting malicious code into Python packages or the language itself. The token was found in a compiled Python binary file, not in the source code, demonstrating the need for robust secrets detection that includes both source code and binary files. The incident was swiftly mitigated when JFrog reported the leak to PyPI, who revoked the token within 17 minutes, and an investigation showed no suspicious activity had occurred. This case underscores the importance of using modern, fine-grained tokens and the necessity of scanning beyond source code to include binaries in secrets detection. JFrog's ability to detect this leak was due to their comprehensive scanning methods, which analyze both text and binary files, enhancing the security of their software supply chain platform.
Jul 09, 2024
1,339 words in the original blog post.
JFrog Workers, now accessible to all Enterprise+ and Enterprise X customers as of October 2024, is a JFrog Cloud Platform service designed to enhance workflow automation and flexibility by allowing users to create customized workers that respond to platform events. These workers, managed in a serverless execution environment, can automate processes such as running code and adjusting functions, and benefit from version control, testing, and CI/CD integration through tools like Jenkins and GitHub Actions. The integration with JFrog CLI simplifies the creation and management of these workers, and the blog post provides a step-by-step guide on initializing, testing, and deploying workers using GitHub Actions, ensuring streamlined development pipelines.
Jul 08, 2024
825 words in the original blog post.
The 2024 JFrog Software Supply Chain report is an essential resource for developers and DevOps professionals, offering a comprehensive analysis of the current state of software supply chains and the security challenges they face. Drawing on data from Artifactory, insights from the JFrog Security Research team, and survey responses from over 1,200 professionals, the report discusses the growing complexity of technology stacks, with many organizations using multiple programming languages, which increases the attack surface. It highlights the predominance of open-source components and the associated security risks, emphasizing the need for proactive security measures, such as integrating security early in the development process, known as "shifting left." The role of AI and ML in enhancing security protocols and improving development efficiency is explored, though their use in code creation remains cautious due to security concerns. The report underscores the importance of effectively managing the entire software supply chain, not just the code, to ensure security, compliance, and efficiency, providing guidance for organizations to navigate the evolving technological landscape.
Jul 05, 2024
710 words in the original blog post.
JFrog, which hosted the JCenter repository for Java OSS libraries as part of its Bintray service, is sunsetting JCenter following Bintray's deprecation on May 1, 2021, to shift focus to the JFrog Platform. JCenter will transition to a read-only repository, redirecting requests to Maven Central, a more updated and widely supported repository for Java libraries. The sunset involves scheduled brown-outs starting with one-hour periods and culminating in a 24-hour period, leading up to a full redirection to Maven Central on August 15. Users relying on JCenter need to update their projects and remote repositories to ensure compatibility with Maven Central. Although most Maven packages from JCenter are available in Maven Central, there might be exceptions, prompting users to seek alternatives, such as contacting package owners or using internal repositories. JFrog encourages users to reach out for support if needed and advises checking Maven Central for the latest package versions.
Jul 02, 2024
776 words in the original blog post.