July 2025 Summaries
10 posts from JFrog
Filter
Month:
Year:
Post Summaries
Back to Blog
Cloudsmith positions itself as an enterprise-ready solution for modern organizations, claiming reliability, performance, security, and scalability as its core strengths. However, upon testing its performance under real-world conditions, particularly under stress, it became evident that Cloudsmith's platform struggles to handle concurrent workloads and high request volumes, leading to issues such as timeouts, rate limiting, and service disruptions. The tests, conducted by JFrog, compared Cloudsmith's performance to JFrog's own platform, revealing that while initial low-load tests showed similar performance, Cloudsmith's infrastructure faltered under increased pressure, resulting in errors and throttling. In contrast, JFrog's platform demonstrated stability and consistent performance, even under significantly higher concurrency. Furthermore, Cloudsmith's uptime reports indicate service availability issues, raising concerns about its reliability as a cloud-native solution. This suggests that while Cloudsmith markets itself as scalable and robust, it may fall short of meeting the demands of large-scale enterprise environments, where uninterrupted service and reliability are critical.
Jul 29, 2025
1,855 words in the original blog post.
JFrog's annual swampUP conference, scheduled for September 8-10, 2025, at Meritage Resort & Spa in Napa, CA, serves as a pivotal event for professionals in DevOps, DevSecOps, and MLOps to explore the "Quantum Shift" in software development driven by AI advancements. The conference offers hands-on training, opportunities for certifications, and insights from industry leaders, with speakers from major companies like ServiceNow, Dell Technologies, NVIDIA, and Cisco. Attendees can enhance their skills, gain practical advice from JFrog experts, and learn about building secure AI/ML models while bridging DevOps and MLOps practices. The event also provides a platform for networking with peers and industry leaders in a relaxed setting, complemented by a gala celebration featuring Grammy-nominated cellist Tina Guo. The conference emphasizes the importance of trust, traceability, and transparency in intelligent software development, aiming to equip attendees with strategies to improve modern software delivery.
Jul 28, 2025
552 words in the original blog post.
JFrog has achieved the "Deployed on AWS" badge in the AWS Marketplace, highlighting its commitment to providing innovative solutions that leverage AWS's infrastructure for enhanced user experience and efficiency. This recognition reflects JFrog's adherence to AWS's standards for reliability, scalability, and performance, benefiting organizations by maximizing their cloud investments. JFrog's collaboration with AWS includes adopting AWS Graviton processors, which has improved performance and reduced costs, aligning with sustainable technology goals. The integration with AWS services such as Amazon EKS, Amazon SageMaker, and others supports JFrog's mission to provide secure and efficient software supply chain platforms, enhancing DevSecOps capabilities. This partnership exemplifies a shared vision for innovation and excellence, with JFrog poised to deliver accelerated performance and sustainable computing through ongoing collaboration with AWS.
Jul 25, 2025
587 words in the original blog post.
In a significant security breach, JounQin's npm account was compromised through a phishing attack, leading to the release of six malicious versions of the popular eslint-config-prettier package and three additional infected packages. These compromised packages, which experience approximately 78 million weekly downloads, highlight the vulnerabilities in widely used npm packages. The attack primarily affected Windows systems through an embedded binary that installed the Scavenger malware, capable of exfiltrating files and stealing credentials. JFrog Curation offers a solution by automatically detecting and blocking suspicious packages, thereby safeguarding development environments from such supply chain attacks. This incident underscores the necessity of robust security measures to protect against unexpected threats in software ecosystems.
Jul 23, 2025
588 words in the original blog post.
Attestations play a crucial role in ensuring software supply chain security, but the process of verifying these attestations can be cumbersome without the right tools. JFrog has introduced a free DSSE Attestation Online Decoder, aimed at simplifying the verification of DSSE (Dead Simple Signing Envelope) envelopes, a standard JSON format for attesting software supply chain security. The tool allows users to easily decode and verify DSSE envelopes by pasting the JSON and, if desired, a public key for signature verification, making the evidence payload human-readable within seconds. This innovation supports compliance with global regulations and enhances workflows related to SLSA provenance, in-toto verification, and Sigstore, while also integrating with JFrog's automated evidence collection for governance, risk, and compliance efforts.
Jul 22, 2025
364 words in the original blog post.
JFrog has introduced the MCP Server, a new feature of its Software Supply Chain Platform, which facilitates the integration of large language models (LLMs) with JFrog's tools, thus eliminating the need for developers to be DevOps or JFrog experts. This integration is enabled by the Model Context Protocol (MCP), a framework that connects AI systems with external tools through a lightweight interface, enhancing interoperability and accessibility. The MCP Server supports essential tools for creating and managing projects, repositories, and provides detailed security information without context-switching, all while being remotely delivered to ensure it remains up-to-date. By leveraging MCP, developers can easily automate complex set-ups, such as project creation and repository configuration, via simple AI-driven commands, streamlining workflows and reducing the risk of errors. The JFrog Remote MCP Server is available in open beta for all JFrog SaaS customers, offering a simplified and AI-enhanced development process.
Jul 17, 2025
698 words in the original blog post.
The UK government has introduced the Software Security Code of Practice, a framework aimed at enhancing cybersecurity for organizations involved in software development and sales, emphasizing the integration of security throughout the software development lifecycle (SDLC). This initiative underscores the importance of secure design, understanding software composition, rigorous testing processes, and secure deployment and maintenance, aiming to mitigate vulnerabilities and risks while fostering a security-focused culture. JFrog is highlighted as a key partner in helping organizations meet these guidelines by offering a comprehensive suite of tools that facilitate secure software development, including Software Composition Analysis, Static Application Security Testing, and secrets scanning, while promoting collaboration across development, operations, and security teams. By adopting these practices and leveraging JFrog’s solutions, businesses can enhance their cybersecurity posture, deliver safer products, and maintain competitiveness in a landscape of increasing cyber threats.
Jul 16, 2025
1,405 words in the original blog post.
Integrating security within the Software Development Life Cycle (SDLC) is essential, and DevSecOps extends DevOps by making security a shared responsibility from development to deployment. The JFrog Platform facilitates this integrated approach by combining security, compliance, and automation across the software supply chain. It enhances DevSecOps workflows through tools like Artifactory, Xray, and Distribution, ensuring security, visibility, and control from code commit to production deployment. Developers can integrate these tools within their Integrated Development Environments (IDEs) for real-time vulnerability scanning, while JFrog Frogbot provides additional protection by scanning Git repositories for vulnerabilities after code commits. The platform automates CI/CD processes, allowing artifacts to be securely stored and scanned before deployment. As artifacts are promoted through development stages, each step is documented, ensuring audit readiness and compliance. JFrog Distribution ensures secure and tamper-proof delivery to production environments, while Edge Nodes improve performance and runtime protection by caching release bundles close to runtime environments. Overall, the JFrog Platform offers a comprehensive DevSecOps blueprint that enhances security, compliance, and efficiency across the SDLC, allowing organizations to innovate quickly without sacrificing security.
Jul 15, 2025
1,273 words in the original blog post.
JFrog's EveryOps Day in Sydney served as a collaborative platform where technology leaders, customers, developers, architects, and partners engaged in discussions about the future of DevSecOps and MLOps, emphasizing the importance of co-creation and shared learning. The event featured diverse industry attendees from fintech, retail, energy, and banking, who explored common themes of automation, governance, security, and scalability through four thematic streams: security-driven consolidation, ecosystem integration with partners, platform modernization at enterprise scale, and ML adoption in secure cloud environments. Key sessions underscored the necessity of consolidating security tools for end-to-end visibility, integrating ecosystem partnerships for streamlined software lifecycle management, modernizing cloud infrastructures as demonstrated by Iress, and ensuring secure machine learning workflows. JFrog's commitment to adapting global solutions to local challenges was evident, as the event aimed to foster feedback for evolving its platform and partnerships to meet the specific needs of ANZ organizations.
Jul 10, 2025
777 words in the original blog post.
CVE-2025-6514 is a critical security vulnerability identified in the mcp-remote tool, a proxy used by Model Context Protocol (MCP) clients, that allows attackers to execute arbitrary OS commands on a machine when it connects to an untrusted MCP server. This flaw poses a high risk of system compromise, particularly affecting mcp-remote versions 0.0.5 to 0.1.15, with the issue resolved in version 0.1.16. The vulnerability is platform-specific, leading to arbitrary command execution on Windows, and potentially on macOS and Linux. Attack scenarios include connecting to compromised or insecure MCP servers, often within local networks. Mitigation involves updating mcp-remote to version 0.1.16 and ensuring connections are made only to trusted servers using HTTPS. The vulnerability highlights the need for caution in the rapidly evolving MCP ecosystem, underscoring the importance of secure connection practices and vigilance against potential vulnerabilities.
Jul 09, 2025
2,074 words in the original blog post.