helping to deliver secure software updates from code to the edge.
You have been redirected to the JFrog website
Ihre Agenten sind nur so vertrauenswürdig wie das, was sie konsumieren, entwickeln und ausliefern. JFrog verwaltet jedes KI-Modell, jede Agentenfähigkeit, jeden MCP-Server, jeden KI-generierten Code und jedes zusammengesetzte Artefakt in einer Single Source of Truth.
Sichern Sie Ihre gesamte agentische Software-Lieferkette ab, damit Sie vertrauenswürdige Software in Ihrer neuen Geschwindigkeit ausliefern können.
help drive evidence-based policies in JFrog AppTrust, streamlining application lifecycle management and governance. Read Less >
Verified Proof of Code Quality
SonarQube’s static code analysis is integrated into JFrog CLI to generate signed evidence containing quality gate results, security scan findings, and code coverage metrics.
Code Quality Attestations Integrated into Unified Evidence Collection
SonarQube’s signed code quality attestations are seamlessly integrated into JFrog Evidence Collection as verifiable proof of software meeting quality standards – alongside all other key evidence across the SDLC.
Code Quality as a Driver for Application Governance
JFrog AppTrust ingests Sonar’s code quality attestations as key evidence driving its evidence-based policy engine, establishing governance over the software supply chain.
The integration is designed to collect and verify SonarQube’s code analysis results as signed evidence and seamlessly integrate them into JFrog AppTrust. This provides a unified, verifiable proof of a software’s code quality and security.
SonarQube generates signed evidence that includes quality gate results, security scan findings, and code coverage metrics. This information acts as a verifiable attestation that the code has met the required quality and security standards.
JFrog uses the code quality attestations from SonarQube as a key input for JFrog AppTrust’s evidence-based policy engine. This allows for the enforcement of application governance policies, ensuring that only software that meets predefined quality standards can progress through the supply chain.
The signed code quality attestations from SonarQube are stored in JFrog’s Evidence Collection. This serves as a central hub where all key evidence from across the SDLC is gathered, providing a single source of truth for audits and compliance.
By integrating SonarQube’s verified code quality evidence, JFrog can establish robust governance over the software supply chain. It provides a reliable, data-driven mechanism to ensure that all software artifacts meet specific quality and security criteria before they are approved for release or deployment.
Your action was successful
Bitte versuchen Sie es später noch einmal.
Modale Nachricht
helping to deliver secure software updates from code to the edge.
You have been redirected to the JFrog website