September 18, 2024 - JFrog, the streaming software company and creator of the JFrog Software Supply Chain Platform, and GitHub, the world's leading code development platform, recently released a new integration feature at the JFrog Annual User Conference. Through continued deepening cooperation, developers can be provided with a comprehensive view of project status and security posture, helping them quickly resolve potential vulnerabilities discovered by the company's advanced security products. In addition, to help developers quickly understand third-party software packages, the two parties also announced the launch of the Copilot Chat extension plug-in to quickly select updated, enterprise-approved, and safe-to-use software packages.
“For developers to be more productive, they need full visibility into the quality and security of the code and binaries they integrate into their software,” said Yoav Landman, CTO and co-founder of JFrog . “Our collaboration with GitHub enables teams to quickly understand and ensure trust in this information using Copilot. Our partnership also enables developers to build and release trusted software faster through more intuitive workflows that allow them to navigate between code and binary artifacts produced during the build process. We are on a journey together and look forward to delivering a unified platform experience to our customers.”
According to the "2024 Global Software Supply Chain Development Report" released by JFrog , only 56% of companies use both source code and binary scanning to protect their software supply chains, which puts nearly half of the companies at risk of binary-level security vulnerabilities, which poses a huge security risk to enterprises. At the same time, the JFrog security research team recently discovered that a token was accidentally left behind in the Docker container, which granted full access to the Python package repository. If this token is discovered and exploited, it will affect tens of millions of computer systems around the world, which support most of today's Internet and cloud infrastructure, automated work tasks, financial services, and data analysis.
Create secure developer workflows by integrating best-of-breed source and binary platforms
The JFrog and GitHub integration promises to provide an easier and more secure way to track the code lifecycle from source code to generated binaries on both platforms, with the following key features:
-
Get deep insights into packages with Copilot Chat integration: The new GitHub Copilot extension makes developers more productive by providing deep insights into open source packages in the JFrog binary environment, along with GitHub code data, eliminating the need to search documentation or online forums. The recommendations provided are aligned with corporate governance policies, allowing developers to select packages based on security and market adoption, making smart choices for the business. Combining Copilot's chat capabilities with JFrog's artifact metadata creates a powerful AI assistant for developers.
-
Integrated security dashboard: A unified view of security scan results from GitHub Advanced Security and JFrog Advanced Security (including the scanner that discovered the aforementioned Python vulnerability) can help developers identify and eliminate potential software vulnerabilities early in the development lifecycle, saving time and reducing risk.
-
Bidirectional end-to-end release traceability: The new job summary page on GitHub provides developers with a quick view of each GitHub Actions workflow run and security status, allowing developers to quickly view the output packages of each build and easily jump to locations in JFrog Artifactory and back. This bidirectional navigation enhances software traceability by leveraging the software bill of materials (SBOM) stored in JFrog Artifactory.
-
Dynamic project mapping and authentication: Leveraging the current OpenID Connect (OIDC) integration, we have improved automatic authorization and seamless project mapping between GitHub repositories and JFrog projects in Artifactory, eliminating the need for developers to re-authenticate to each repository.
Previous article:VeriSilicon Selects Arteris Interconnect IP to Power Its High-Performance SoC Design
Next article:JFrog Launches First Runtime Security Solution for Comprehensive Software Integrity and Traceability from Code to Cloud
- Popular Resources
- Popular amplifiers
- Red Hat announces definitive agreement to acquire Neural Magic
- 5G network speed is faster than 4G, but the perception is poor! Wu Hequan: 6G standard formulation should focus on user needs
- SEMI report: Global silicon wafer shipments increased by 6% in the third quarter of 2024
- OpenAI calls for a "North American Artificial Intelligence Alliance" to compete with China
- OpenAI is rumored to be launching a new intelligent body that can automatically perform tasks for users
- Arm: Focusing on efficient computing platforms, we work together to build a sustainable future
- AMD to cut 4% of its workforce to gain a stronger position in artificial intelligence chips
- NEC receives new supercomputer orders: Intel CPU + AMD accelerator + Nvidia switch
- RW61X: Wi-Fi 6 tri-band device in a secure i.MX RT MCU
Professor at Beihang University, dedicated to promoting microcontrollers and embedded systems for over 20 years.
- LED chemical incompatibility test to see which chemicals LEDs can be used with
- Application of ARM9 hardware coprocessor on WinCE embedded motherboard
- What are the key points for selecting rotor flowmeter?
- LM317 high power charger circuit
- A brief analysis of Embest's application and development of embedded medical devices
- Single-phase RC protection circuit
- stm32 PVD programmable voltage monitor
- Introduction and measurement of edge trigger and level trigger of 51 single chip microcomputer
- Improved design of Linux system software shell protection technology
- What to do if the ABB robot protection device stops
- CGD and Qorvo to jointly revolutionize motor control solutions
- CGD and Qorvo to jointly revolutionize motor control solutions
- Keysight Technologies FieldFox handheld analyzer with VDI spread spectrum module to achieve millimeter wave analysis function
- Infineon's PASCO2V15 XENSIV PAS CO2 5V Sensor Now Available at Mouser for Accurate CO2 Level Measurement
- Advanced gameplay, Harting takes your PCB board connection to a new level!
- Advanced gameplay, Harting takes your PCB board connection to a new level!
- A new chapter in Great Wall Motors R&D: solid-state battery technology leads the future
- Naxin Micro provides full-scenario GaN driver IC solutions
- Interpreting Huawei’s new solid-state battery patent, will it challenge CATL in 2030?
- Are pure electric/plug-in hybrid vehicles going crazy? A Chinese company has launched the world's first -40℃ dischargeable hybrid battery that is not afraid of cold
- I bought a Hanshuo electronic price tag and ended up buying a CC2640. Isn't that annoying?
- How does a phase shifter shift phase?
- Automotive controller development schematics and wiring diagrams using software recommendations
- Ferrite beads and inductors
- CircuitBrains Deluxe Development Board
- Silicon Labs Development Kit Review – First Look
- SIMterix-Simplis~7~
- Is it because there is no system initialization function that causes the register version of the program PROTUES cannot be simulated?
- [GD32E231 DIY Contest] 2. Light up a digit of the digital tube
- [National Technology N32G457 Review] 2. Basic Engineering Evaluation and Template Engineering Construction