JFrog Contributes Open Source Pyrsia to CD Foundation
October 25, 2022

JFrog announced Pyrsia, an open source software community initiative that utilizes blockchain technology to secure software packages (a.k.a. binaries) from vulnerabilities and malicious code, has become an incubating project under the Continuous Delivery Foundation (CDF).

Working together, JFrog and the CD Foundation will ensure Pyrsia grows its backing and engagement through the use of a centralized governance model, defined roadmap, and broad representation within the wider technology and open source communities.
JFrog-Led Open Source Initiative “Pyrsia” to be incubated under the CD Foundation.

Stephen Chin, VP of Developer Relations at JFrog and Governing Board Member for the CD Foundation, said: “With the CD Foundation’s support, and that of our incredible industry partners, developers can leverage Pyrsia to have peace of mind in knowing their open source components have not been compromised, and confidently deliver secure software at scale.”

Pyrsia is an open source-based, decentralized, secure build network and software package repository that seamlessly integrates with the package management systems developers are already using today, so they can certify their software components without foregoing compatibility, security, or efficiency. Developers receive a digitally signed, immutable chain of evidence for their code, which is an essential building block for Software Bill of Materials (SBOMs). This provides developers and their customer’s assurance in knowing the exact source of their packages.

“We see Pyrsia as a natural extension of our organization’s mission to grow and sustain projects that are part of the wider continuous delivery ecosystem,” said Fatih Degirmenci, Executive Director, CD Foundation. “We’ve recently learned as an industry that no one is safe from cybercriminal activity, particularly when bad actors inject malicious packages into central repositories, wreaking havoc on downstream systems and applications. We’re proud to support Pyrsia because it puts the power back in the hands of developers and, ultimately, accelerates innovation.”

JFrog, along with other open source technology leaders, including Docker, DeployHub, Futurewei, and Oracle, collaborated to officially launch Pyrsia in May 2022. Since then, these software giants have lent their expertise on how to better secure the software supply chain to the Pyrsia network, creating opportunities for cross-project collaboration within the CD Foundation to interlink secure packages with community tools, helping improve developers’ ability to deliver secure software at scale.

Share this

Industry News

May 21, 2024

Puppet by Perforce announced a significant enhancement to the capabilities of its commercial offering with the addition of new security, compliance, and continuous integration/continuous delivery (CI/CD) capabilities.

May 21, 2024

Red Hat and Nutanix announced an expanded collaboration to use Red Hat Enterprise Linux as an element of Nutanix Cloud Platform.

May 21, 2024

Nutanix announced Nutanix Kubernetes® Platform (NKP) to simplify management of container-based modern applications using Kubernetes.

May 21, 2024

Octopus Deploy announced their GitHub Copilot Extension that increases efficiency and helps developers stay in the flow.

May 20, 2024

Pegasystems introduced Pega GenAI™ Coach, a generative AI-powered mentor for Pega solutions that proactively advises users to help them achieve optimal outcomes.

May 20, 2024

SmartBear introduces SmartBear HaloAI, trusted AI-driven technology deploying across its entire product portfolio.

May 16, 2024

Pegasystems announced the general availability of Pega Infinity ’24.1™.

May 16, 2024

Mend.io and Sysdig unveiled a joint solution to help developers, DevOps, and security teams accelerate secure software delivery from development to deployment.

May 16, 2024

GitLab announced new innovations in GitLab 17 to streamline how organizations build, test, secure, and deploy software.

May 16, 2024

Kobiton announced the beta release of mobile test management, a new feature within its test automation platform.

May 15, 2024

Gearset announced its new CI/CD solution, Long Term Projects in Pipelines.

May 15, 2024

Rafay Systems has extended the capabilities of its enterprise PaaS for modern infrastructure to support graphics processing unit- (GPU-) based workloads.

May 15, 2024

NodeScript, a free, low-code developer environment for workflow automation and API integration, is released by UBIO.

May 14, 2024

IBM announced IBM Test Accelerator for Z, a solution designed to revolutionize testing on IBM Z, a tool that expedites the shift-left approach, fostering smooth collaboration between z/OS developers and testers.

May 14, 2024

StreamNative launched Ursa, a Kafka-compatible data streaming engine built on top of lakehouse storage.