JFrog Adds New Security, DevOps and MLOps Capabilities
September 14, 2023

JFrog unveiled new capabilities that set the standard for quality, security, MLOps and integrity of software releases.

From creation to production, the JFrog Platform infuses security at the binary level in every stage of the software development lifecycle to ensure applications are traceable, reliable, compliant, and secure.

“JFrog has been strategically investing heavily in the development of comprehensive, DevOps-centric security solutions aimed at addressing future threats. JFrog automates DevSecOps processes uniquely at the binary level, and our customers affirm that this is the most effective approach to safeguarding their software supply chain,” said Shlomi Ben Haim, co-founder and CEO, JFrog. “The industry is in a constant race against attackers, and JFrog consistently releases new capabilities that outpace other worldwide vendors. Customers’ range of protection with JFrog now spans from open-source and first-party code, secrets detection, IaC security, and Curation of OSS packages – and today brings in AI and MLOps security, caching and protection of customers’ ML models. JFrog continues to be set apart by our unique capability to control software binaries, made possible by the leading position of Artifactory.”

The new capabilities in the JFrog Software Supply Chain Platform continue to meet customers’ needs for comprehensive, DevOps-centric security and automation that drives a true shift-left strategy, including:

- AI and ML Model Security: JFrog’s new ML Model Management capabilities quickly scan and detect malicious machine learning models, block their use if needed, and ensure license compliance with company policies to enable safer use of AI. JFrog’s ML Model Management capabilities are currently available in Beta for JFrog Cloud customers.

- Static Application Security Testing (SAST): Seamlessly integrates with several developer environments to help customers quickly and accurately scan source code for zero-day security vulnerabilities. JFrog SAST also helps minimize false positives and prioritize remediation efforts using contextual analysis.

- Open-Source Software (OSS) Catalog: As part of JFrog Curation, Catalog provides a “search engine for software packages” in the JFrog UI or via API – that’s backed by both public and JFrog data – giving users immediate insight to the security and risk metadata associated with all OSS packages.

“With the alarming rise of software supply chain attacks, securing at the binary level with immutable software bundles is a must because it’s the only way to certify that what you’re releasing is safe for use,” said Asaf Karas, CTO, JFrog Security. “By providing a comprehensive platform that is developer-friendly and enterprise-ready – with security baked in at every phase, backed by an expert team of security researchers always watching for emerging threats – we can better arm companies to innovate faster with peace of mind in knowing their software is safe for use both today, and tomorrow.”

Each element of the JFrog Platform is backed by a dedicated team of security engineers and researchers actively investigating, analyzing, and exposing new vulnerabilities and attack methods. All new DevSecOps capabilities build upon JFrog’s already robust set of security products, designed to deliver a comprehensive and continuous approach to automatically securing binaries across all stages of software development and delivery, including:

- JFrog Curation, with its new OSS Catalog capability, helps organizations prevent malicious packages or vulnerabilities from ever entering their development environment.

- JFrog Xray for proactively detecting risky packages before deployment.

- JFrog Advanced Security with Contextual Analysis to help quickly assess critical vulnerability and secrets exposures once software is in production so timely remediation efforts can be executed.

While detailing the new security capabilities in the JFrog Platform, the company also unveiled new DevOps functionality, including:

- Hugging Face local repository – Native connection with popular AI repository – Hugging Face – allows Python developers and Data Scientists to easily proxy and cache the open source AI models they rely on from deletion or modification.

- ML Model Management: Brings AI model development in line with an organization’s existing software processes to accelerate and govern the continuous delivery of ML components.

- Release Lifecycle Management (RLM) abilities: Creates an immutable “Release Bundle” defining a software package and its components early in the software development lifecycle, providing a single source of truth for each application. JFrog RLM also uses anti-tampering systems, compliance checks, and evidence capture to collect data and insights on each release bundle at every stage of development for transparency on the quality of each build that can be easily shared with multiple stakeholders across DevOps, IT, and security.

Share this

Industry News

November 21, 2024

Red Hat announced the general availability of Red Hat Enterprise Linux 9.5, the latest version of the enterprise Linux platform.

November 21, 2024

Securiti announced a new solution - Security for AI Copilots in SaaS apps.

November 20, 2024

Spectro Cloud completed a $75 million Series C funding round led by Growth Equity at Goldman Sachs Alternatives with participation from existing Spectro Cloud investors.

November 20, 2024

The Cloud Native Computing Foundation® (CNCF®), which builds sustainable ecosystems for cloud native software, has announced significant momentum around cloud native training and certifications with the addition of three new project-centric certifications and a series of new Platform Engineering-specific certifications:

November 20, 2024

Red Hat announced the latest version of Red Hat OpenShift AI, its artificial intelligence (AI) and machine learning (ML) platform built on Red Hat OpenShift that enables enterprises to create and deliver AI-enabled applications at scale across the hybrid cloud.

November 20, 2024

Salesforce announced agentic lifecycle management tools to automate Agentforce testing, prototype agents in secure Sandbox environments, and transparently manage usage at scale.

November 19, 2024

OpenText™ unveiled Cloud Editions (CE) 24.4, presenting a suite of transformative advancements in Business Cloud, AI, and Technology to empower the future of AI-driven knowledge work.

November 19, 2024

Red Hat announced new capabilities and enhancements for Red Hat Developer Hub, Red Hat’s enterprise-grade developer portal based on the Backstage project.

November 19, 2024

Pegasystems announced the availability of new AI-driven legacy discovery capabilities in Pega GenAI Blueprint™ to accelerate the daunting task of modernizing legacy systems that hold organizations back.

November 19, 2024

Tricentis launched enhanced cloud capabilities for its flagship solution, Tricentis Tosca, bringing enterprise-ready end-to-end test automation to the cloud.

November 19, 2024

Rafay Systems announced new platform advancements that help enterprises and GPU cloud providers deliver developer-friendly consumption workflows for GPU infrastructure.

November 19, 2024

Apiiro introduced Code-to-Runtime, a new capability using Apiiro’s deep code analysis (DCA) technology to map software architecture and trace all types of software components including APIs, open source software (OSS), and containers to code owners while enriching it with business impact.

November 19, 2024

Zesty announced the launch of Kompass, its automated Kubernetes optimization platform.

November 18, 2024

MacStadium announced the launch of Orka Engine, the latest addition to its Orka product line.