Welcome to the JFrog Blog

Follow the Data: A Hidden Directory Traversal Vulnerability in QNX Slinger

Follow the Data: A Hidden Directory Traversal Vulnerability in QNX Slinger

Through our ongoing device security analysis, we often uncover—and responsibly disclose—new unknown vulnerabilities in both closed and open source software components used in connected devices. In this blog post, we discuss a directory traversal vulnerability that we recently discovered while analyzing the firmware of a device based on the BlackBerry QNX operating system. First, here’s…
Best Practices for Onboarding JFrog Xray

Best Practices for Onboarding JFrog Xray

Note: A version of this blog post is also published on dev.to Introducing, adding, or replacing a new SCA (Software Composition Analysis) tool such as JFrog Xray into your SDLC, if not handled correctly, can be very disruptive to the SDLC and organization. This blog post provides recommended best practices for onboarding JFrog Xray; in…
Track JFrog Platform Performance with Datadog Analytics

Track JFrog Platform Performance with Datadog Analytics

Faithful operation of your JFrog Platform can be best assured by tracking usage data of Artifactory and Xray. With insights gained through real-time observability and log analytics, you can boost the efficiency of your DevOps pipeline and keep your software releases running joyfully. Datadog is a SaaS-based data analytics platform that is a popularly used…
Unified JFrog Platform Monitoring With Prometheus and Grafana

Unified JFrog Platform Monitoring With Prometheus and Grafana

Running the JFrog DevOps Platform on Kubernetes in your enterprise can mean serving millions of artifacts to developers and customers each day. But operating at top performance requires being able to answer some vital questions. Like what is the most requested artifact? What is the most popular repo? Who are your heaviest users? For security,…
Stretch Your Reach with Unified JFrog Data and Elastic

Stretch Your Reach with Unified JFrog Data and Elastic

  DevOps teams rely on Artifactory as the bread and butter tool of universal binary repo managers, but observing its operations can be challenging. With multiple high availability nodes and unification with Xray as the JFrog DevOps Platform, that operations data is spread out across logs for each service in the JFrog Platform deployment. Operations…
Official JFrog Ansible Collection for Artifactory & Xray

Official JFrog Ansible Collection for Artifactory & Xray

Ansible has become one of the most popular tools used by operations teams to automate their IT tasks. It allows them to quickly, and at the largest enterprise scale, manage the configuration of their IT systems. This includes software and infrastructure on-premise and in the cloud. Its open-source roots has allowed it to grow a…
Make DevSecOps So: Cloud Enterprise+ on AWS Marketplace

Make DevSecOps So: Cloud Enterprise+ on AWS Marketplace

JFrog is pleased to announce that our comprehensive Cloud Enterprise+ plan is now available on Amazon Web Services (AWS) Marketplace. JFrog Cloud Enterprise+ on AWS is a universal, highly-available SaaS offering of the JFrog Platform for demanding DevSecOps at global scale.  Its Mission: DevSecOps at Enterprise Scale The JFrog Platform is built for start-to-finish, “one-stop…
A Smooth Operator to Run JFrog Enterprise on OpenShift

A Smooth Operator to Run JFrog Enterprise on OpenShift

Red Hat OpenShift and JFrog Artifactory are a smooth fit together for cloud-native, containerized software development at enterprise scale. With the new availability of OpenShift operators certified for JFrog Enterprise, that fit now fastens tight. Catch us live with Red Hat to learn more. Join us for a live session January 21st, 10:30AM PST or…
Unified JFrog Log Analytics With Splunk

Unified JFrog Log Analytics With Splunk

We work best by coming together. That’s why we built the JFrog DevOps Platform, bringing together our set of solutions to operate as a single, unified user experience. That unity powered by Artifactory 7 helps bring total understanding and control of your software build pipelines. To keep it running, you also need a unified, real-time…