CERT-In-Guidelines-Blog_Thumbnail

JFrog Simplifies Compliance with Indiaโ€™s new CERT SBOM Guidelines

Overview The Indian Computer Emergency Response Team (CERT-In) is the national agency responsible for addressing cybersecurity incidents in India. Established in 2004 and operating under the Ministry of Electronics and Information Technology (MeitY), CERT-In is dedicated to enhancing the security of Indiaโ€™s digital infrastructure. The organization plays a vital role in preventing, detecting, and responding โ€ฆ

Build Info in Your VCS

Take control of your Security: How to use Build-Info in your VCS to track vulnerable versions

Tracking vulnerabilities and compliance requirements is essential for maintaining application security in any software project. However, this process can be time-consuming and complicated, especially as new issues are identified. Fortunately, the JFrog build-info provides a comprehensive solution by recording key information about your projectโ€™s build. With build-info, you can easily track vulnerable versions of your โ€ฆ

Collect and Manage your Binary Metadata using Build-Info

Collect and Manage your Binary Metadata using Build-Info

Our modern life depends on software from the most trivial to critical task. How software is built, behaves and what it actually contains are fundamental questions that almost all stakeholders of the Software Development Life Cycle (SDLC) need to know. Being able to effectively manage your binaries (aka software packages, artifacts, containers, imagesโ€ฆ) provides full โ€ฆ

Building images in OpenShift with Artifactory and JFrog CLI

Whatโ€™s in your build? Building Images in OpenShift with Artifactory and JFrog CLI

Red Hat OpenShift is an enterprise Kubernetes container platform. It lets you build Docker images and use them to deploy your applications on a cloud-like environment (even if itโ€™s not really on the cloud, rather a simulated cloud environment). Images built in OpenShift can be easily pushed into JFrog Artifactory โ€“ JFrogโ€™s leading universal repository โ€ฆ

JFrogโ€™s Best DevSecOps Blogs of 2021

Always a concern for DevOps teams, security has now become a critical part of developing and releasing software โ€“ a reality reflected on the sharp increase in JFrog blogs about DevSecOps. In fact, we generated so many hard-hitting and instructive blogs about security and compliance in 2021 that we decided our DevSecOps coverage deserved its โ€ฆ

Itโ€™s Time to Get Hip to the SBOM

The DevOps, IT security and IT governance communities will remember 2021 as the year when the Software Bill of Materials, or SBOM, graduated from a โ€œnice to haveโ€ to a โ€œmust have.โ€  Around for years, the SBOM has now become a critical DevSecOps piece, which everyone must thoroughly understand and incorporate into their SDLC (Software โ€ฆ

US Executive Order on Cybersecurity: What it Means for DevOps

The United States Government equates cybersecurity with national security.  Thatโ€™s the crux of the recent Executive Order that will mandate that not only must software applications be vetted, but there will be upcoming regulations on providing all of the components that make up the software. As section 1 notes:  โ€œprevention, detection, assessment, and remediation of โ€ฆ