Artifactory 7.10.1 Cloud

JFrog Release Information

ft:sourceType
Paligo

Released: 11 October 2020

JFrog Artifactory 7.10.1 is Available as a Cloud Version

The JFrog Artifactory 7.10.1 release is available as a Cloud version and is aligned with the Artifactory 7.10.2 Self-Hosted version.

Highlights

New JFrog Platform Onboarding Experience

In Artifactory 7.10.1, we have introduced a new Onboarding experience in the web UI for Admin users. This new interactive experience guides the user through the essential onboarding steps to get started with the JFrog Platform.

Note

This new Onboarding experience will be rolled out to all users over the next couple of weeks.

Feature Enhancements

Artifactory Supports AWS Secrets for DB Connections

You can now use the AWS SecretsManager alias in the Artifactory system.yaml allowing Artifactory to automatically retrieve the secret associated with the alias connection.

Verify Audience Restriction Applied for SAML SSO

As part of JFrog's security enforcement, an additional verification step has been set up opposite the SAML server to validate SAML SSO authentication requests. The verifyAudienceRestriction attribute for SAML SSO is set by default in the JFrog Platform for new Artifactory installations. When upgrading from a previous Artifactory release, this parameter is disabled only if SAML was already configured.

Improved Maven Plugin Metadata Calculation

Maven plugin metadata is now calculated for every deploy or delete actions.

Resolved Issues

Jira Issue

Description

RTFACT-15577

Fixed an issue, whereby Pypi remote and virtual repositories returned a 404 error even if the package existed in the public registry.

RTFACT-20334

Fixed an issue, whereby Artifactory indexed Helm Charts with an invalid version number or appVersion number but the Helm repository containing these charts could not be added to the helm client’s repository.

RTFACT-19010

Fixed an issue, whereby value updates (add/remove) to Property sets were not reflected in files and directories in the repositories.

RTFACT-17512

Fixed an issue whereby, Artifactory did not proxy Nexus PyPi repositories.

RTFACT-20036

Fixed an issue whereby, the Prune process was consuming a lot of memory when handling a large files list.

RTFACT-20143

Fixed an issue, whereby in a number of cases the CRAN package metadata displayed in the UI was not consistent with the CRAN package info.

RTFACT-23136

Fixed an issue whereby, checksum mismatch errors and 404 errors occurred when resolving nested Go modules in Artifactory from a virtual repository that included remote pointers to Github.

RTFACT-23347

Fixed an issue, whereby the Artifactory CacheLoader returned a null error following LDAP authentication.

RTFACT-19109

Fixed an issue, whereby Conda metadata calculation failed due to a Race condition.

RTFACT-22640

F

ixed an issue, whereby JFrog Xray unable to connect to Artifactory when the Password policy was set in the access.config file.

RTFACT-14226

Fixed an issue, whereby the TimestampSnapshotComparator compare method that compared two different snapshotVersion sections according to timestamps was not compatible with maven-metadata.xml artifacts that contained a base-revision with more than one element.

RTFACT-23368

Fixed an issue, whereby in certain instances, Azure guest users were unable to log in to Artifactory.

RTFACT-20226

Fixed an issue, whereby users without the required permissions could deploy the same package to their Local Cran repository.

RTFACT-19094

Fixed an issue, whereby, under certain circumstances, the Helm remote repository URLs were not added correctly to the Artifactory virtual repository index.yaml file.

RTFACT-22323

Fixed an issue, whereby Exclude patterns were not applied on Remote Repositories when REST API commands when triggering REST API commands.

Security-Related Resolved Issues

Artifactory now will check the AudienceRestriction or SubjectConfirmationData Recipient values in every SAML response. For more information, see Verify Audience Restriction Applied for SAML SSO.

Hardened the logging process between Artifactory and the Docker Client.

Vulnerable security values are no longer supported when running the Create User command via the REST API.

Vulnerable security values are no longer supported for permission targets.

For a complete list of changes, please refer to our JIRA Release Notes.