Home / Companies / JFrog / Blog / February 2025

February 2025 Summaries

7 posts from JFrog

Filter
Month: Year:
Post Summaries Back to Blog
The Swiss Financial Market Supervisory Authority (FINMA) mandates stringent compliance requirements for financial institutions in Switzerland, emphasizing robust security measures and operational resilience. These requirements, applicable to both Swiss-based and foreign entities operating in the Swiss financial market, underscore the importance of cybersecurity and software supply chain integrity. As of January 2025, adherence to these regulations is mandatory, focusing on comprehensive risk management, continuous monitoring, and secure IT practices integrated throughout the software development lifecycle. JFrog offers a platform approach to help organizations meet FINMA compliance by embedding security into governance frameworks, managing software components with traceability, and ensuring data quality for AI systems. Their tools facilitate automated vulnerability scanning, policy enforcement, and continuous monitoring, thereby enhancing visibility and reducing complexity in managing compliance across DevOps, MLOps, and Security practices. This approach aligns with FINMA's emphasis on governance, risk management, and operational resilience, ensuring institutions can respond swiftly to threats while maintaining audit readiness.
Feb 24, 2025 960 words in the original blog post.
JFrog has expanded its Artifactory platform to include support for Hex packages, enhancing its commitment to offering a versatile artifact management system that now supports nearly 40 package types. Hex is a package manager used within the BEAM ecosystem, which includes programming languages like Elixir and Erlang, known for their capabilities in handling high consistency, concurrency, and scalability in applications such as messaging, telecommunications, financial services, and gaming. With this addition, JFrog Artifactory can now cache the Hex.pm public registry and serve it to Hex's build tool, Mix, ensuring efficient software delivery at scale. The Hex repository support is currently available in local and remote SaaS configurations, with virtual SaaS support coming soon, and self-hosted users can expect availability across all repository types in the near future.
Feb 18, 2025 267 words in the original blog post.
Migrating applications to the cloud offers significant financial and technological advantages, with providers like AWS, Google Cloud, and Microsoft Azure offering frameworks to enhance infrastructure design. The AWS Well-Architected Framework, updated in June 2024, assists cloud architects in creating secure, high-performing, resilient, and efficient cloud systems by providing best practices across six pillars, particularly focusing on Operational Excellence and Security. JFrog aligns with these principles by offering solutions within its Software Supply Chain Platform that support secure, reliable, and efficient cloud architectures. JFrog Xray and JFrog Advanced Security enhance security by identifying vulnerabilities and ensuring compliance, while JFrog Artifactory supports operational excellence through automation and seamless DevOps lifecycle management. As an AWS Partner, JFrog aids organizations in optimizing their cloud strategies and improving performance, with a commitment to ongoing analysis and support for frameworks from other cloud providers like Google Cloud and Microsoft Azure.
Feb 14, 2025 563 words in the original blog post.
JFrog's Release Lifecycle Management (RLM) offers a streamlined and robust alternative to the legacy build promotion API by providing a more comprehensive approach to managing release candidates throughout their lifecycle. RLM ensures the immutability of releases from build to production, maintaining integrity and traceability while enabling faster, more reliable releases with full control and visibility. Central to RLM is the concept of Release Bundles, which encapsulate release candidate versions and support actions such as creation, promotion, and distribution, along with the inclusion of Evidence, which captures all testing, scanning, and approval metadata for auditability. This system enhances the traditional build promotion process by eliminating manual errors, providing a unified promotion step for multi-technology pipelines, and offering detailed visibility through features like the RLM Kanban Board. JFrog facilitates the transition for users of the legacy system by automating certain processes and aligning environmental configurations, ensuring a smooth shift to the enhanced capabilities of RLM.
Feb 13, 2025 1,032 words in the original blog post.
The Indian Computer Emergency Response Team (CERT-In), under the Ministry of Electronics and Information Technology, has been crucial in strengthening India's cybersecurity infrastructure since its establishment in 2004. To further this goal, CERT-In released guidelines in October 2024 mandating the integration of Software Bill of Materials (SBOM) practices for organizations involved in software development for regulated entities. These guidelines aim to enhance software security by ensuring that SBOMs provide detailed information about software components, including their names, versions, dependencies, and vulnerabilities. The JFrog Platform, with its Artifactory and Xray tools, offers a comprehensive solution for automating SBOM generation, managing software artifacts, and ensuring compliance with CERT-In's requirements. JFrog Artifactory centralizes artifact management and automates SBOM creation, while JFrog Xray focuses on vulnerability identification, license compliance, and maintaining secure supply chains, thus enabling organizations to maintain compliance with the latest cybersecurity standards.
Feb 12, 2025 1,391 words in the original blog post.
JFrog has upgraded its ISO certification to the latest version, ISO/IEC 27001:2022, reinforcing its commitment to high standards in cybersecurity and information security. This new certification highlights improvements over the previous 2013 version, focusing on enhanced cybersecurity controls, effective risk management, and streamlined security measures. The certification process involved a comprehensive audit by an independent organization, confirming that JFrog's data management and security practices align with top international standards. JFrog emphasizes a continuous commitment to cybersecurity by regularly assessing and enhancing its security measures to stay ahead of emerging threats, ensuring a secure environment for customer data.
Feb 10, 2025 394 words in the original blog post.
The Network and Information Systems Directive 2 (NIS2), adopted by the European Union in December 2022, is designed to enhance cybersecurity across critical sectors by expanding the scope of its predecessor and emphasizing supply chain security. With the October 2024 deadline for transposition into national standards now passed, organizations must ensure compliance by January 2025, with large and medium-sized entities in sectors like energy, transportation, healthcare, and banking being particularly affected. JFrog offers a comprehensive platform to assist organizations in meeting NIS2 requirements by integrating security and compliance into the software development lifecycle, focusing on securing the software supply chain, automating vulnerability management, and enhancing incident response and reporting. By providing tools for real-time monitoring, incident response, and governance, JFrog helps organizations streamline compliance, strengthen their cybersecurity posture, and maintain accountability, ensuring that they are well-equipped to meet the demands of international cybersecurity standards as they move into 2025.
Feb 06, 2025 898 words in the original blog post.