Ledger Fortifies Software Supply Chain Security with the JFrog Platform

Single Source of Truth

All software artifacts are unified across cloud, on-prem and firmware – globally

Zero-Trust OSS Ingestion

Open-source dependencies pass strict risk thresholds before entering the development environment

Keyless CI/CD Authentication

OIDC keyless authentication mitigates credential exposure across all GitHub Actions pipelines

How the world’s leading digital asset security and self-custody company unified its infrastructure, automated open-source vetting, and eliminated static secrets from CI/CD – without compromising development velocity and application security.

 

ABOUT LEDGER

Headquarters

Paris, France

Industry

Digital asset security / hardware

Security model

Two specialized teams: product security and cybersecurity engineering

JFrog products

JFrog Artifactory · JFrog Xray · JFrog Curation · JFrog Advanced Security

OVERVIEW

Ledger is the global leader in digital asset security for individuals and institutions, best known for the Ledger signers – the gold standard for secure ownership of digital value. In addition to developing hardware, Ledger operates a vast and complex software ecosystem including:

  • The Ledger WalletTM app
  • Cloud-native web services
  • Firmware for embedded devices
  • Manufacturing systems for hardware production.

Across all of these products, services and processes, a single security failure doesn’t just compromise a specific product, but can potentially threaten the financial holdings of millions of customers.

CHALLENGE

Established more than a decade ago, Ledger’s global operations have scaled significantly, with its software artifacts expanding across multiple systems – GitHub, Harbor, local FTP servers, and various package registries spanning Cargo, Conan, and npm. For a fintech company with stringent security requirements this dispersed structure could be improved.

The security team needed a single, audited source of truth, to check that the artifact in staging was the same artifact that reached production. This would help scan the open source packages used by developers for potential vulnerabilities prior to usage.

In an important strategic shift, the Security Engineering team took an increasingly proactive approach to help secure their software supply chain without impeding developer speed. This means identifying and stopping potentially malicious code before it even has the opportunity to enter the development environment. All this must be done in a way that doesn’t create friction between engineers working across multiple environments.

“As Ledger scaled, maintaining consistent visibility and control across multiple artifact ecosystems became increasingly complex. The objective was to consolidate this into a stronger, auditable, and security-first model.”

– Enguerrand Allamel, Staff Cloud Security Engineer, Ledger

 

SOLUTION

Ledger selected the JFrog Platform as the core of its software supply chain – deploying a hybrid architecture spanning Kubernetes on AWS, and on-prem data centers to serve the full range of Ledger’s business units.

To ensure the success of  their security-first approach, JFrog Artifactory became the mandatory repository for every type of software artifact. This includes everything from open-source dependencies entering the environment, to packages published to public registries for Ledger’s partners and ecosystem.

 

JFrog Curation
A firewall for open-source dependenciesBefore any open-source package can enter Ledger’s development environment, it is designed to pass through JFrog Curation. Ledger enforces strict, custom risk thresholds — blocking all dependencies with a threshold CVE score, as well as proactive detection of malicious packages and typosquatting attempts. The result is an intelligent gatekeeper that gives developers freedom to pull pre-scanned, secure OSS packages as they need it. 
JFrog Advanced Security & Xray
Continuous compliance for all binaries JFrog Xray and JFrog Advanced Security provide deep scanning across Ledger’s full artifact ecosystem supporting Rust (Cargo), Python, npm, Docker, and more. The resulting vulnerability detection, secrets scanning, and metadata verification give Ledger’s security team the ability to audit any artifact, at any point in the lifecycle, and with the intention of confirming it is exactly what it claims to be. Kubernetes cluster visibility means every image running in production can be traced back to a verified, JFrog-managed origin.
GitHub Actions + OIDC
Zero static secrets in the pipelineBy combining Terraform-managed infrastructure and OIDC (OpenID Connect) keyless authentication in GitHub Actions, pipeline interactions with JFrog are now identity-based and ephemeral – no more long-lived tokens, no credential sprawl and no single key that can unlock the supply chain.

Hybrid deployment
One platform, three distinct environmentsLedger’s product surface spans hardware firmware (extreme lockdown), backend services (strict), and web applications (agile). JFrog’s hybrid deployment – AWS plus on-premises – allows each environment to operate under its own security policy while feeding into a single, unified artifact registry. This enables the security team to enforce compliance globally without requiring valuable engineering team hours to manage infrastructure.

“With JFrog Curation and Xray, we have a genuine firewall for our dependencies. Developers can pull what they need – packages are already audited, verified, and cleared before they touch it. Security becomes a property of the environment, not a step they have to remember.”

– Enguerrand Allamel, Staff Cloud Security Engineer, Ledger

 

RESULTS

The JFrog Platform has boosted Ledger’s software development operations, providing a secure foundation for the company’s ongoing growth and innovation.

Business value realized with JFrog:

  • Single source of truth achieved – Artifacts – web, backend, containers – are now managed through JFrog across cloud and on-premise environments, eliminating the fragmented registry sprawl that can create blind spots.
  • Proactive dependency defense operational –  JFrog Curation automatically blocks malicious packages, typosquatting attempts, and any dependency exceeding Ledger’s CVE risk threshold – before developers ever encounter them.
  • Zero static credentials in CI/CD-  OIDC-based keyless authentication has eliminated long-lived tokens from all GitHub Actions pipelines, removing the attack vector that defined the industry’s most damaging recent supply chain incident.
  • Preventing software supply chain security incidents – Consolidating with JFrog helps Ledger prevent software supply chain security incidents linked to their packages.
  • Hybrid compliance at scale – Three distinct security environments – from locked-down firmware to open web services – are now managed under a single unified platform with environment-specific policies enforced automatically.
  • Full production Kubernetes visibility –  Every container image running in Ledger’s production clusters can now be traced to a verified, JFrog-managed origin, turning runtime provenance from an audit exercise into a continuous guarantee.

“The best impact we’ve seen from JFrog is unification. We no longer have artifacts scattered across different systems. Everything is in one place, with the visibility and control that our security team requires and the simplicity that our developers deserve.”

– Enguerrand Allamel, Staff Cloud Security Engineer, Ledger

 

What’s Next for Ledger and JFrog?

JFrog is now the mission-critical infrastructure for Ledger. Not a point tool for the security team, but the platform the entire software supply chain is built upon. As Ledger continues to scale its operations, the team is deepening its use of JFrog Advanced Security for runtime artifact analysis and extending policy enforcement further left into the development lifecycle. For a company whose essence is trust, the ability to check the provenance, integrity, and security of every artifact – from commit to customer – is not a feature. It’s a foundation.

 

“JFrog is a core component for our environment; all of our software supply chain management is based on it. It is mission-critical for us, which is why we are continuing to expand our use of the platform as we keep moving forward.”

– Enguerrand Allamel, Staff Cloud Security Engineer, Ledger

 

We invite DevOps and Security professionals in technology companies to schedule a personalized demo or take an online guided tour and see how the JFrog Platform can transform your operations with enhanced security, efficiency and governance.

 


Products
The JFrog Platform, JFrog Artifactory, JFrog Xray, JFrog Curation, JFrog Advanced Security

Additional Resources
Strategic Briefing:  The Immutable Ledger: Powering the Next Era of Global Finance
Solution Sheet:  JFrog for Financial Services
Case Study: How Iress Optimized Global DevSecOps with JFrog: Scaling Compliance, Security & Efficiency

Release Fast Or Die