Home / Companies / JFrog / Blog / December 2025

December 2025 Summaries

11 posts from JFrog

Filter
Month: Year:
Post Summaries Back to Blog
As companies face increasing challenges in protecting their software supply chains, many are transitioning from traditional, siloed application security tools like Snyk and Checkmarx to integrated platforms such as JFrog. This shift is driven by the need for comprehensive solutions that offer end-to-end visibility, security, and control, effectively reducing tool sprawl and false positives while enhancing collaboration between DevOps and security teams. Real-world examples include a top 10 Fortune 500 company and a federal organization that chose JFrog for its unified artifact management and security capabilities, enabling them to meet specific industry regulations, improve security efficiency, and maintain delivery speed and quality. JFrog's platform offers features like scanning both source code and binaries, reducing false positives through contextual analysis, and blocking risky third-party software from entering the development lifecycle. These capabilities have led enterprises to view security as an enabler of increased release velocity when integrated into a single, streamlined platform, transforming their security posture into a more automated and reliable supply chain solution.
Dec 31, 2025 1,110 words in the original blog post.
Application Security (AppSec) has evolved beyond traditional source code scanning, as modern software development involves assembling components from open-source packages, containers, binaries, and AI models. While tools like Checkmarx primarily focus on source code, JFrog offers a more comprehensive approach by securing the entire software supply chain, including binaries, containers, and runtime images, thus addressing vulnerabilities that source code scanners might miss. JFrog integrates security into the development pipeline, employing features such as Software Composition Analysis (SCA), binary scanning, and preemptive blocking of risky components to ensure end-to-end release integrity. Additionally, JFrog provides advanced contextual analysis and runtime security to prioritize and mitigate vulnerabilities effectively while supporting various deployment options. It is trusted by many leading companies, including over 80% of the Fortune 100, for its innovative solutions that streamline AppSec processes and enhance security across the entire software lifecycle.
Dec 31, 2025 832 words in the original blog post.
The accelerating adoption of AI and automated development is intensifying regulatory scrutiny and supply chain risks, particularly due to the limitations of traditional source code scanning which fails to detect vulnerabilities in compiled binaries and third-party components. JFrog's approach emphasizes the importance of focusing on binaries, with tools like JFrog Xray offering continuous, binary-focused scanning to identify risks unseen by source-only tools, and JFrog Advanced Security providing enhanced vulnerability prioritization through artifact-aware transitive contextual analysis. Additionally, JFrog Curation acts as a proactive gatekeeper against malicious packages by verifying them against a database before they integrate into the software development life cycle. The JFrog Platform serves as a unified system of record for all artifacts, streamlining security processes and ensuring fewer vulnerabilities. It also addresses the regulatory demands of AI/ML by providing a secure environment for managing models and ensuring compliance through transparency. Emphasizing an end-to-end, native, binary-focused DevSecOps platform, JFrog positions itself as a solution to not only secure the software supply chain but also to enhance development velocity by integrating security directly into artifact management.
Dec 30, 2025 859 words in the original blog post.
Docker has made its catalog of over 1,000 Docker Hardened Images (DHI) free and open source, which allows developers to begin their Dockerfiles with a secure, minimalistic foundation that is compliant with near-zero CVEs and SLSA Level 3 standards. This change enhances container security by enabling developers to easily integrate these images into their workflows, especially when using JFrog as a Docker registry. JFrog Artifactory acts as a caching proxy, simplifying the authentication process and centralizing management for enterprises while avoiding rate limits and credential management complexities. The platform also provides continuous security through tools like JFrog Xray and JFrog Advanced Security, which scan for vulnerabilities, enabling proactive monitoring and compliance with frameworks such as FedRAMP, HIPAA, or PCI DSS. By consolidating images into a central, trusted system, organizations can maintain a consistent and traceable security posture, ensuring that containerization remains secure throughout its lifecycle.
Dec 29, 2025 624 words in the original blog post.
SwampUP Europe 2025, held at the JW Marriott in Berlin, became the focal point for discussions on the future of DevOps, DevSecOps, and MLOps, emphasizing a "Quantum Shift" towards DevGovOps and AI Supply Chain Security. The event highlighted the dual challenge of accelerating software delivery through AI while managing security risks and regulatory compliance, with JFrog unveiling solutions like Shadow AI Detection and AI-Generated Code Validation to address these issues. Attendees explored the implications of new regulatory frameworks, the dangers of untracked AI-generated code, and practical insights such as Admiral's transformation using the JFrog Platform to streamline its Identity and Access Management infrastructure. The conference underscored the importance of unified control in software delivery, with JFrog's platform integrating DevOps, Security, MLOps, and DevGovOps to support organizations during this transformative era, while partnerships with major tech players contributed to the event's success.
Dec 23, 2025 968 words in the original blog post.
As businesses face increasing security vulnerabilities such as Log4j and npm attacks, the importance of a robust and integrated security solution becomes paramount, especially as the number of Common Vulnerabilities and Exposures (CVEs) continues to rise. The hypothetical scenario described highlights the potential pitfalls of relying on individual security vendors, which may be compromised due to industry consolidation and a focus on cost-cutting rather than innovation. JFrog offers an alternative by providing a unified platform that seamlessly integrates with existing development pipelines, offering comprehensive protection across the software supply chain. By consolidating AppSec tools into a single solution, JFrog aims to mitigate the risks associated with fragmented security measures and vendor instability, ensuring businesses remain resilient against evolving threats.
Dec 22, 2025 686 words in the original blog post.
The rapid integration of AI technologies in development processes often leads to the emergence of Shadow AI, which encompasses unmanaged AI assets that exist outside established governance frameworks, posing significant security and compliance risks. Shadow AI includes external API calls, open-source models, and custom models, each with its own vulnerabilities such as data leakage, malicious injection, and license violations. To manage these risks, organizations can adopt a structured approach using tools like the JFrog AI Catalog, which offers a comprehensive solution for detecting, auditing, and governing AI assets. The steps involve scanning repositories to identify Shadow AI, prioritizing and assessing risks, enforcing compliance policies, and creating a trusted environment for AI development. This methodology not only mitigates the risks associated with unmanaged AI but also transforms the chaotic integration of AI into a streamlined, secure, and compliant process, thereby facilitating innovation without compromising security.
Dec 16, 2025 1,158 words in the original blog post.
The current AI/ML landscape is often compared to a chaotic "wild west," where models are treated like "magic," leading to unmanaged risks and inefficiencies. To address these challenges, the concept of AISecOps extends DevSecOps principles to the entire AI lifecycle, embedding security, governance, and compliance. This approach advocates treating models as scannable, verifiable, and traceable binaries rather than black boxes, thereby reducing vulnerabilities and improving auditability. JFrog's platform supports AISecOps by providing a unified solution where models are stored in a secure, versioned registry and integrated with tools for governance and security scanning. This shift from "magic" to disciplined engineering practices is essential in meeting real-world risks and regulatory requirements, transforming AI assets into secure and manageable components of the software supply chain.
Dec 09, 2025 1,300 words in the original blog post.
A critical vulnerability known as "React2Shell" has been identified in React and Next.js that allows remote, potentially unauthenticated attackers to execute arbitrary code through React Server Function endpoints. The vulnerability is nearly 100% exploitable in default configurations, though no proof of concept exploits have been confirmed as legitimate. React servers using Server Function endpoints or supporting Server Components are at risk, as are Next.js applications using the App Router in default settings. The affected packages include react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack, with fixed versions available for upgrade. Mitigation strategies include upgrading to patched versions or, for Next.js, migrating back to the Pages Router. JFrog provides tools for tracking and addressing these vulnerabilities through its Xray platform and open-source detectors.
Dec 05, 2025 711 words in the original blog post.
Amazon Elastic Kubernetes Service (EKS) is a managed Kubernetes service that facilitates running, managing, and scaling containerized applications in various environments, including on AWS, on-premises, and at the edge. The JFrog Kubelet Credential Provider introduces a new, secure method for managing container image credentials by using temporary, identity-based credentials instead of static, long-lived secrets, reducing security risks and operational overhead. This enhancement integrates seamlessly with Amazon EKS, utilizing the Kubernetes Kubelet Image Credential Provider standard, which is also employed by other cloud providers for registry authentication. This solution enhances security by minimizing the attack surface associated with static credentials and improves operational efficiency by eliminating the manual management of Kubernetes secrets, thereby enabling faster and more secure deployment of workloads. The integration streamlines the user experience by allowing developers and DevOps teams to focus more on application delivery rather than managing infrastructure credentials, ultimately optimizing the deployment pipeline.
Dec 03, 2025 1,373 words in the original blog post.
JFrog Security Research uncovered three critical zero-day vulnerabilities in PickleScan, a widely used tool for scanning machine learning models for malicious content, which could allow attackers to bypass its malware detection capabilities. These vulnerabilities enable potential supply chain attacks by allowing malicious ML models to evade detection and execute harmful actions when loaded. PickleScan, recognized as an industry standard and integrated into platforms like Hugging Face, relies on blacklist-based detection, which has limitations in identifying new threats. The vulnerabilities include file extension bypass, CRC bypass in ZIP archives, and unsafe globals check bypass with subclass imports, each allowing malicious actors to circumvent PickleScan's security measures. Despite the rapid advancements in AI, data scientists often prioritize speed over security, leading to continued use of insecure formats like Pickle. JFrog recommends updating PickleScan to version 0.0.31, implementing layered defenses, and transitioning to safer serialization formats like Safetensors to mitigate these risks. JFrog's approach to addressing these challenges includes continuous research, multi-layered analysis, and integration with existing DevOps workflows, ensuring comprehensive protection for AI and ML environments.
Dec 02, 2025 2,537 words in the original blog post.