Company
Date Published
Author
Paul Garden
Word count
596
Language
English
Hacker News points
None

Summary

JFrog has introduced new features to enhance its DevOps Platform, specifically JFrog Xray, which is recognized as a reliable software composition analysis (SCA) tool for identifying open-source vulnerabilities and license compliance issues. Xray now supports scanning Conan packages, as well as C and C++ builds, deployed to JFrog Artifactory, and integrates with various build systems, offering flexibility in managing pre-compiled binaries. The platform has incorporated the Common Vulnerability Scoring System (CVSS) v3 to prioritize security threat responses, while still supporting CVSS v2 if needed. Additionally, JFrog Xray has received Red Hat certification, ensuring its vulnerability and license compliance data are accurate for Red Hat packages, thereby boosting confidence for enterprises using RPM packages. The JFrog Platform has also been certified for Red Hat's OpenShift Operator and UBI Container Image, promising enhanced reliability and security, making these updates significant in the evolving landscape of DevSecOps.