April 2025 Summaries
8 posts from JFrog
Filter
Month:
Year:
Post Summaries
Back to Blog
JFrog Artifactory is a universal DevOps tool designed to manage, store, and distribute software binaries and artifacts, such as application installers, libraries, and container images, across the software development lifecycle. It acts as a central hub in the software supply chain, offering benefits like automated deduplication, version control, and multisite support to ensure scalable and efficient software delivery. Artifactory supports over 30 software build packages and file types, integrates with major CI/CD platforms, and provides a secure, reliable source for managing artifacts and dependencies, thereby enhancing the DevOps process by bridging gaps between development and deployment. Although Artifactory does not manage source code, it complements existing tools by storing and managing binaries and artifacts until needed, facilitating efficient internal and external distribution. As part of the JFrog DevOps Platform, Artifactory helps organizations streamline operations, maintain software integrity, and enable best practices in software delivery.
Apr 30, 2025
1,694 words in the original blog post.
JFrog has strategically transitioned to AWS Graviton processors for its Amazon Elastic Kubernetes Service (EKS) and other managed services, such as Amazon RDS, to optimize performance and cost efficiency, particularly for their JFrog Artifactory. This move is part of a broader global deployment strategy aimed at enhancing cost-effectiveness and sustainability while maintaining high performance for their SaaS solutions. The migration involved meticulous planning, rigorous testing, and the adoption of DevOps best practices to ensure a smooth transition, resulting in significant cost savings and improved performance, including a 20% reduction in compute costs and a 20% drop in CPU utilization. The transition also aligns with JFrog's commitment to sustainability by reducing their carbon footprint by 60%, offering customers enhanced performance, cost efficiency, and environmental responsibility. Lessons learned during the migration process have highlighted the importance of aligning Reserved Instances with new commitments, and JFrog continues to explore further advancements in their infrastructure as part of their "Liquid Software" vision for continuous software innovation.
Apr 25, 2025
931 words in the original blog post.
Organizations face challenges in retaining previous software releases due to internal policies, external regulations, and the need to preserve development context, which is essential for compliance and operational efficiency. JFrog's Smart Archiving offers a solution by providing a long-term, policy-driven software retention service that automates the archiving process, ensuring regulatory compliance and operational efficiency. This service allows for the seamless transfer of software assets to an archive while maintaining complete development context for easy restoration and simplified auditing. By leveraging low-cost cloud storage, Smart Archiving eliminates manual errors and supports globally distributed development teams, enhancing workflow efficiency and reducing build times. Users can define archive policies, perform dry runs, and manage archived assets through the JFrog Platform, which integrates with existing enterprise functionalities like Federation and Projects. Smart Archiving is available for JFrog Cloud and as a hybrid offering, making it easier for organizations to manage their software assets effectively.
Apr 23, 2025
691 words in the original blog post.
Last week, the cybersecurity industry narrowly avoided a crisis when the MITRE Corporation announced the impending expiration of its contract to manage the Common Vulnerabilities and Exposures (CVE) program, which has been crucial for identifying software vulnerabilities over the past 25 years. This announcement caused widespread concern about the continuity of the CVE system, which is vital for standardized vulnerability identification and management. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) quickly extended MITRE's contract for 11 months, temporarily allaying fears of disruption. The CVE program, managed by MITRE and sponsored by CISA, has historically provided a standardized naming convention for publicly disclosed software vulnerabilities, a role that is now threatened by potential changes in management. Concerns remain about the lack of viable alternatives to the CVE system, with existing options like GitHub, OSV, and various vendor-specific identifiers offering incomplete coverage. In response, the security community has launched initiatives such as the CVE Foundation to ensure the program's future stability and independence. Meanwhile, organizations are urged to diversify their vulnerability management strategies by leveraging multiple data sources and implementing security tools that support various vulnerability identifiers. This approach aims to maintain a robust security posture amidst potential disruptions and ongoing challenges in vulnerability data enrichment and management.
Apr 23, 2025
2,930 words in the original blog post.
JFrog has expanded its platform's capabilities by officially supporting Chocolatey and PowerShell with its NuGet repositories in JFrog Artifactory, enhancing its position as a universal package management solution. This integration provides users with greater flexibility in managing packages and streamlining automation within Windows environments, as both Chocolatey and PowerShell are essential tools for working with NuGet. Chocolatey is a package manager that allows for the management, installation, and updating of software applications through the command line, while PowerShell is a Microsoft-developed task automation and configuration framework. The support for these tools is now live, offering JFrog users an easy setup process via the "Set Me Up" feature, and it is recommended to maintain separate local, remote, and virtual repositories for each client to prevent index mixing. Users can explore the platform's offerings for Chocolatey and PowerShell through the Help Center or by consulting with a JFrog team member.
Apr 22, 2025
370 words in the original blog post.
JFrog Security Research has identified a malicious package named "ccxt-mexc-futures" that poses a significant threat by exploiting the legitimate CryptoCurrency eXchange Trading (CCXT) Python package, which is widely used for cryptocurrency trading. The malicious package impersonates the original CCXT functionality to hijack trading API requests, redirecting them to a fake server designed to steal sensitive information such as API keys and crypto tokens. It utilizes sophisticated obfuscation techniques and a fraudulent domain that mimics the MEXC exchange, misleading users into believing their trades are legitimate. In response, JFrog Xray has been updated to detect this threat, encouraging users to revoke compromised tokens and remove the package to secure their trading accounts.
Apr 15, 2025
1,546 words in the original blog post.
Organizations need a well-defined software retention strategy to manage incremental builds and old release versions effectively, ensuring compliance with data retention, privacy, and cybersecurity requirements. This strategy involves creating software retention policies, which can be classified into cleanup and archival policies, dictating when and how software assets and their metadata are maintained or removed. Key considerations when developing these policies include assessing resource capacity, understanding regulatory requirements, aligning with the software development lifecycle, and meeting business needs. Implementing retention policies, especially with automation, offers benefits such as improved productivity, reduced costs, simplified compliance, and prevention of accidental data loss. Best practices recommend using an artifact management solution like JFrog to automate processes, test policies before implementation, and maintain necessary metadata for compliance and restoration purposes.
Apr 03, 2025
1,249 words in the original blog post.
Managing and securing the software supply chain is increasingly challenging in a rapidly evolving technological landscape, particularly in a post-AI world. JFrog's third annual Software Supply Chain State of the Union Report highlights key trends and insights, emphasizing the growing size and complexity of software supply chains and the persistent rise in security vulnerabilities, such as CVEs. The report reveals that many organizations are adopting new technologies swiftly, including AI, but are also facing heightened risks due to open-source ecosystem expansion and the use of multiple programming languages. It stresses the importance of not overlooking security basics, the need for artifact management solutions to mitigate risks, and the challenges in governing machine learning model usage. Although the pace of change can increase organizational risk, implementing smart tools and processes can help organizations leverage the diverse software ecosystem to gain a competitive edge. For comprehensive analysis and practical security tips, the full report is available for download, along with an upcoming webinar to discuss the findings in detail.
Apr 01, 2025
999 words in the original blog post.