GitHub Artifact Attestations

JFrog and GitHub have deepened their partnership by seamlessly bringing together the context of source code and binaries, helping organizations establish software supply chain governance.

GitHub Evidence Integration Features

Frequently Asked Questions

What is the main purpose of the GitHub and JFrog evidence integration?

This integration is designed to seamlessly collect and store GitHub Artifact Attestations and build provenance as critical evidence within JFrog’s Evidence Collection. This creates a single source of truth for the entire software development lifecycle (SDLC), connecting code-level proof with the actual production binaries.

How does JFrog use build provenance from GitHub?

JFrog attaches the GitHub build provenance directly to the corresponding binary throughout its entire lifecycle, all the way into production. This creates a continuous chain of evidence, providing a clear context for production binaries and making it easier to resolve issues and understand their origin.

Are the attestations from GitHub permanently stored?

GitHub Artifact Attestations are stored permanently in JFrog. This ensures they are always available as a key resource for enforcing policies, maintaining compliance, and providing an immutable record of the build process.

What is an attestation in this context?

An attestation is a verifiable, cryptographically signed statement about a software artifact. In this integration, it refers to the verifiable evidence generated by GitHub (known as GitHub Artifact Attestations) that provides a secure, tamper-proof record of what happened during the build process.

What are the other integrations between GitHub and JFrog?

Visit https://jfrog.com/jfrog-and-github/ for the latest information.

About GitHub

GitHub empowers developers and organizations to build, scale, and deliver secure software. As the world's largest developer platform, GitHub fosters a global community where millions of people and businesses collaborate, innovate, and drive code to its full potential.