Company
Date Published
Author
Paul Garden, JFrog Partner and Industry Solutions
Word count
954
Language
English
Hacker News points
None

Summary

At swampUP 2025, JFrog and GitHub announced a new integration that unifies source code and binary security into a single DevSecOps workflow, addressing the traditional separation that causes blind spots and increased risks. This integration delivers end-to-end security and visibility across the software supply chain, enhancing automation, unification, and intelligence. Key features include a simplified setup with secure authentication, bulk deployment of the Frogbot for automated scanning, unified security results in GitHub's dashboard, and the merging of source and binary Software Bill of Materials (SBOMs). Additionally, GitHub Copilot now accesses JFrog’s security knowledge for agentic remediation, ensuring secure coding. The integration also streamlines audits and provides compliance through evidence-backed attestations, offering significant benefits to developers, DevOps, platform, and security teams by reducing context switching and enhancing security practices across multiple repositories.