Home / Companies / JFrog / Blog / October 2025

October 2025 Summaries

11 posts from JFrog

Filter
Month: Year:
Post Summaries Back to Blog
JFrog and GitHub have formed a partnership to enhance software supply chain security and efficiency through a comprehensive integration of their platforms, offering a unified experience for developers and security teams. This integration combines GitHub's source code management and collaboration tools with JFrog's expertise in artifact management and binary scanning, providing seamless visibility and traceability from commit to runtime. By collaborating on features like policy-driven guardrails, unified security dashboards, and AI-powered remediation, the partnership aims to create a secure-by-default, frictionless developer experience. The integration, which employs modern authentication methods like OpenID Connect, minimizes operational friction and enhances security by providing a single source of truth for code and binaries. Recognized as GitHub's Technology Partner of the Year for 2025, JFrog's collaboration with GitHub is a significant step toward realizing a unified, resilient, and self-healing software supply chain that supports agile and secure software delivery for enterprises of all sizes.
Oct 28, 2025 1,024 words in the original blog post.
AI-driven software development is transforming the industry, with tools like JFrog Fly facilitating efficient artifact management and release processes for AI-native teams. JFrog Fly serves as an agentic artifact repository, enabling seamless integration with AI-native development environments through a zero-configuration setup. It centralizes artifact management, linking binary repositories with source control to allow comprehensive metadata tracking, which aids in creating and managing releases with ease. By utilizing the Model Context Protocol, JFrog Fly ensures that all artifacts and related contextual information are readily available for agents to execute tasks through natural language commands. The platform emphasizes simplifying deployment and distribution, offering features like automatic generation of necessary deployment files and semantic release identification, which enhance development speed and reliability. As an extension of the JFrog Software Supply Chain Platform, JFrog Fly caters specifically to small teams, streamlining processes without the need for extensive DevOps resources, and is now available for beta testing.
Oct 28, 2025 891 words in the original blog post.
The integration of models into JFrog Artifactory using the FrogML SDK marks the beginning of an efficient AI/ML management process, where models are treated as first-class artifacts in a secure and dynamic Model Registry. This approach addresses common challenges in model management, such as versioning, data quality, governance, and team collaboration, by providing a centralized, traceable system that ensures compliance and security. Artifactory serves as a universal repository for storing and managing proprietary and third-party models, offering simplified versioning and robust security measures. The JFrog ML platform further enhances the MLOps lifecycle by facilitating model training, deployment, and monitoring, while the JFrog AI Catalog accelerates production with features like model lineage and one-click deployment. Together, these tools enable organizations to incorporate AI development into their standard business processes, promoting faster innovation and maintaining the necessary visibility and control to build trust in AI applications.
Oct 24, 2025 861 words in the original blog post.
Cloud outages pose significant risks to organizational operations, with potential to halt development processes entirely, as highlighted by user experiences. To mitigate these risks, a strategic, layered resilience framework is essential, focusing on architectural strategies that ensure business continuity. The framework includes three levels: essential resilience through multi-region configurations within a single cloud vendor; greater protection for mission-critical assets by differentiating resilience needs and possibly implementing a multi-cloud strategy for high-risk assets; and achieving zero downtime through true vendor independence with a full multi-cloud strategy. By adopting this approach, organizations can minimize service disruptions and maintain operational continuity even during outages. The JFrog Platform is cited as a versatile, cloud-agnostic solution supporting these strategies, demonstrated by Iress's successful implementation of a hybrid solution for workflow flexibility and operational continuity.
Oct 23, 2025 594 words in the original blog post.
JFrog has been recognized as a 'Visionary' in Gartner's 2025 Magic Quadrant for Application Security Testing, highlighting its innovative approach to seamlessly integrating security within the software development lifecycle. This strategy allows organizations to deliver secure applications without compromising developer productivity. JFrog's recent innovations include AppTrust, which embeds governance, risk, and compliance into the software supply chain, and Agentic Remediation, which leverages AI to enhance security with less manual intervention. They also launched Curation for IDE Extensions to block malicious open-source packages early in the development process. JFrog’s comprehensive security solution spans the entire software supply chain, from initial code to running images, using tools like JFrog Xray for software composition analysis and JFrog Runtime for monitoring production environments. The company's commitment to security innovation is further demonstrated by their active role in security research and their leadership in machine learning security, ensuring the integrity and compliance of software releases without hindering delivery speed.
Oct 22, 2025 800 words in the original blog post.
JFrog Security Research has identified and disclosed several vulnerabilities in oatpp-mcp, a framework implementing Anthropic’s Model Context Protocol (MCP), with CVE-2025-6515 being particularly notable due to its potential for session ID hijacking. This vulnerability, termed "Prompt Hijacking," allows attackers to manipulate AI behavior by exploiting session-level protocol mechanics without altering the model itself. MCP, developed by Anthropic in 2024, facilitates real-time context provision to AI models, bridging the gap between training data and current environments. The protocol's architecture includes components such as MCP Hosts, Clients, Servers, and various data sources, with communication facilitated through JSON-RPC and multiple transport methods, including the recently deprecated SSE. The flaw arises from using memory pointers as session IDs in Oat++'s MCP implementation, leading to predictable and non-secure session IDs that attackers can exploit to inject malicious prompts. The impact of these attacks depends on how MCP clients process incoming data, with traditional defenses potentially bypassed by attackers. To mitigate such vulnerabilities, the implementation of cryptographically secure random generators for session IDs and robust event validation and session management practices are recommended.
Oct 21, 2025 1,678 words in the original blog post.
SwampUP Europe 2025, an extension of the renowned DevOps, DevSecOps, and MLOps conference, is set to take place in Berlin from November 12-14, emphasizing the transformative "quantum shift" in software development, security, and scalability in the AI era. Hosted at the JW Marriott Hotel, the event will focus on trust, traceability, and transparency, offering hands-on workshops and insights from industry leaders such as Admiral, Adyen, and NVIDIA. The conference will also feature networking events, including a gala with Master Mentalist Lior Suchard. Sessions are tailored for various professional roles, covering topics like integrating security into workflows, optimizing automation, and secure AI/ML model deployment. The event offers flexible registration options, with early bird pricing available until October 25, making it a strategic career investment for attendees eager to engage with the latest trends in software delivery.
Oct 16, 2025 626 words in the original blog post.
Software supply chains have become increasingly complex, necessitating improved management to maintain security and compliance across accelerated release cycles. JFrog AppTrust offers a comprehensive solution to address these challenges by integrating development, governance, and operations into an automated framework that ensures security and compliance without hindering delivery speed. AppTrust elevates applications from mere artifacts to business entities with defined ownership, allowing for precise accountability and risk management. By binding software packages to applications, AppTrust provides clarity on responsibility, even in complex microservice environments, and uses evidence-based policies to enforce security, quality, and compliance checks at each stage of the software development lifecycle. The solution enables a "Trusted Release" model, where each application version is verified, compliant, and continuously monitored for risks post-release. Through its structured framework, AppTrust consolidates security, testing, and compliance data into a unified view, facilitating faster, data-driven decisions and enhancing both security and delivery efficiency.
Oct 16, 2025 1,150 words in the original blog post.
Security teams often face challenges in handling vast amounts of data to identify vulnerabilities in production environments, leading to prioritization issues and potential security blind spots. JFrog addresses this with its Runtime Scope capability, which automatically scans active clusters for vulnerabilities using JFrog Xray and Advanced Security. This approach eliminates manual processes, reduces prioritization paralysis, and ensures comprehensive coverage by focusing on images actively running in clusters. It enhances productivity by aligning security efforts with what is most relevant, provides centralized control of scanning policies, and offers actionable compliance insights through real-time monitoring and dashboards. This integrated solution fundamentally shifts security workflows from reactive to proactive, enabling teams to concentrate on critical risks effectively.
Oct 15, 2025 757 words in the original blog post.
JFrog has developed an internal tool called the near Zero Downtime Migration (nZDM) to address the challenges associated with database migrations, which often result in significant downtime and data loss. This tool, designed exclusively for JFrog's internal use, leverages the PostgreSQL extension pglogical for logical data replication, automating key migration tasks to minimize human error and ensure seamless service continuity. nZDM's architecture, which includes an event-driven approach and microservices, allows for efficient pre-migration checks and monitoring through tools like Grafana and Coralogix. Since its implementation, nZDM has improved JFrog's internal migration processes by reducing downtime, enhancing efficiency, and enabling simultaneous migrations, ultimately leading to a better user experience for their customers. JFrog continues to innovate with plans to expand nZDM's capabilities to support cross-cloud migrations and integrate additional technologies like Kafka for message streaming.
Oct 08, 2025 1,068 words in the original blog post.
In the effort to manage the expanding attack surface in cybersecurity, many companies have adopted a fragmented mix of tools, leading to increased complexity and a reactive security posture. This disjointed approach results in inconsistencies, a lack of unified visibility, and financial inefficiencies, as redundant tools complicate audits, slow remediation, and increase costs. To address these issues, a shift towards integration and collaboration across teams such as DevOps, SecOps, and IT Ops is advocated, where sharing data and simplifying the software supply chain can enhance trust and security. By validating production integrity and streamlining vulnerability triage, organizations can create a resilient and transparent security infrastructure. The article emphasizes the need for a unified security model and encourages the breaking down of silos to build a proven and secure software supply chain, with an example of how JFrog can facilitate this integration through its tools and services.
Oct 01, 2025 694 words in the original blog post.