Company
Date Published
Author
Elaad Yaacov
Word count
300
Language
English
Hacker News points
None

Summary

JFrog Xray's integration with Artifactory and Jenkins significantly enhances the security of software builds by automatically failing Jenkins build jobs if vulnerabilities are detected, preventing compromised builds from advancing through the pipeline to production systems. As of version 1.6, Xray collaborates with Artifactory version 4.16 and Jenkins Artifactory Plugin version 2.9.0 to provide early warnings about vulnerabilities, reducing the risk of deploying insecure software. While it is not necessary for developers to scan every build, incorporating a scan in nightly builds that include the latest code from all developers can offer daily alerts about potential issues. Initially, Xray's CI/CD integration was compatible with Jenkins CI, and from version 1.8, it also supports JetBrains TeamCity, with the potential for more CI server integrations in the future. Artifactory operates seamlessly without requiring additional configuration, ensuring an effortless integration process.