helping to deliver secure software updates from code to the edge.
You have been redirected to the JFrog website
エージェントの信頼性は、取り込み・生成・配布するものの信頼性によって決まります。JFrogは、すべてのAIモデル、Agent Skills、MCPサーバー、AI生成コード、そして生成されたアーティファクトを単一の信頼できる管理基盤(Single Source of Truth)で統制します。
エージェント型ソフトウェアサプライチェーン全体をセキュアに保護することで、新しい開発スピードでも信頼できるソフトウェアを提供できます。
following the in-toto and DSSE (Dead Simple Signing Envelope) specification, which includes OCI SLSA build attestations. These attestations are collected as evidence for application governance. Read Less >
Native Support for OCI Containers
JFrog Artifactory natively supports OCI standards, including full support for OCI v1.0, as well as the latest OCI v1.1 specification.
OCI SLSA Provenance as Evidence
As OCI packages are created and pushed into JFrog Artifactory, signed OCI attestations are automatically collected as evidence into JFrog’s Evidence Collection.
Full Traceability of OCI Images
By ingesting and displaying OCI attestations, the JFrog Platform provides a clear audit trail of how container images are built, streamlining traceability and compliance reporting.
The integration is designed to provide native support for OCI (Open Container Initiative) standards within JFrog Artifactory. It automatically collects signed OCI attestations as evidence, creating a clear and verifiable record for every OCI container image.
It means that JFrog Artifactory can fully manage and work with OCI container images, including complete support for the latest OCI v1.1 specification. This allows Artifactory to act as a central repository for OCI images, just as it does for other package types.
OCI SLSA (Supply Chain Levels for Software Artifacts) build attestations are cryptographically signed statements that provide verifiable proof of how an OCI package was created. These attestations are automatically collected as evidence when OCI packages are pushed to Artifactory.
By ingesting and displaying the OCI attestations, the JFrog Platform creates a clear audit trail of the container image’s build process. This provides full traceability, which is crucial for streamlining compliance reporting and ensuring the integrity of your container images.
The signed OCI attestations are automatically collected into JFrog’s Evidence Collection, which holds all the verifiable proof related to your software, including the build provenance of your OCI containers, ensuring the data is permanently available for auditing and governance.
Your action was successful
Please try again later
Modal Message
helping to deliver secure software updates from code to the edge.
You have been redirected to the JFrog website