JFrog Introduces Xray
May 23, 2016

JFrog introduced its fourth and newest product, JFrog Xray, which gives organizations visibility into the contents of software components.

JFrog Xray is a universal impact analysis product, giving organizations an unparalleled level of understanding about all of their container images, software packages and binary artifacts, even with the huge volume and variety of components that development teams share in the software build and distribution process.

JFrog Xray provides radical transparency into every component an organization has ever used. It includes:

- Impact analysis that indicates how production and continuous integration (CI) environments are impacted

- A full dependencies graph on which users can easily zoom in to find vulnerability or compliance issues

- An open API that enables integration with all current and future types of component-scanning technology to allow custom scanning capabilities for performance, quality, popularity or any other criteria required

- A universal solution that integrates with vulnerability and license compliance databases such as VersionEye, Black Duck and WhiteSource

- Powerful integration with a user’s registry and repository to allow full sync through all the CI/CD flow

Through tight integration with JFrog Artifactory and access to the exhaustive metadata that Artifactory indexes, JFrog Xray analyzes the relationships between binary artifacts across an entire organization and the impact that one component has on any other. In addition to security vulnerabilities, JFrog Xray can also analyze the potential impact of performance issues or architectural changes.

“JFrog Xray responds to a profound pain of our users and the entire software development community with an infinitely expandable way to know everything about every component they’ve ever used in a software project – from build to production to distribution,” said Shlomi Ben Haim, Co-Founder and CEO of JFrog. “While container technology revolutionized the market and the way people distribute software packages, it is still a ‘black hole’ that always contains other packages and dependencies. The Ops world has a real need for full visibility into these containers, plus an automated way to point out changes that will impact their production environment. With JFrog Xray, you can not only scan your container images but also track all dependencies in order to avoid vulnerabilities and optimize your CI/CD flow.”

JFrog Xray is a fully automated platform with a powerful REST API, allowing integration and automation with an organization’s CI/CD pipeline, and enabling other inspection and security tools to fit into the full build-to- production automated flow.

JFrog Xray includes the VersionEye technology and database. VersionEye, a startup company based in Mannheim, Germany, improves developer productivity through a system that tracks open source libraries and alerts developers in real time to key information such as security vulnerabilities, license violations and outdated dependencies.

“VersionEye technology monitors over a million open source projects on a daily basis,” said Robert Reiz, CEO and co-founder of VersionEye. “Integrating the VersionEye technology with the JFrog platform creates an unparalleled capability for deep understanding of the quality and provenance of the software components organizations depend on. JFrog has leveraged its Universal approach, supporting all type of components, into a leadership position with its artifact repository and addresses a real community pain with JFrog Xray. We are excited to be part of the solution.”

The technology solves a critical problem for companies as they increase their use of container technology and make open source a mainstay of their development strategies. With so many open source components available, it has become extremely difficult, if not impossible, for application builders to know pertinent information about each one and avert security issues, such as the Heartbleed bug in the popular OpenSSL cryptographic software library that put user passwords on many popular websites at risk.

JFrog Xray will be available on June 30, 2016.

Share this

Industry News

April 24, 2024

Opsera announced that two new patents have been issued for its Unified DevOps Platform, now totaling nine patents issued for the cloud-native DevOps Platform.

April 23, 2024

mabl announced the addition of mobile application testing to its platform.

April 23, 2024

Spectro Cloud announced the achievement of a new Amazon Web Services (AWS) Competency designation.

April 22, 2024

GitLab announced the general availability of GitLab Duo Chat.

April 18, 2024

SmartBear announced a new version of its API design and documentation tool, SwaggerHub, integrating Stoplight’s API open source tools.

April 18, 2024

Red Hat announced updates to Red Hat Trusted Software Supply Chain.

April 18, 2024

Tricentis announced the latest update to the company’s AI offerings with the launch of Tricentis Copilot, a suite of solutions leveraging generative AI to enhance productivity throughout the entire testing lifecycle.

April 17, 2024

CIQ launched fully supported, upstream stable kernels for Rocky Linux via the CIQ Enterprise Linux Platform, providing enhanced performance, hardware compatibility and security.

April 17, 2024

Redgate launched an enterprise version of its database monitoring tool, providing a range of new features to address the challenges of scale and complexity faced by larger organizations.

April 17, 2024

Snyk announced the expansion of its current partnership with Google Cloud to advance secure code generated by Google Cloud’s generative-AI-powered collaborator service, Gemini Code Assist.

April 16, 2024

Kong announced the commercial availability of Kong Konnect Dedicated Cloud Gateways on Amazon Web Services (AWS).

April 16, 2024

Pegasystems announced the general availability of Pega Infinity ’24.1™.

April 16, 2024

Sylabs announces the launch of a new certification focusing on the Singularity container platform.

April 15, 2024

OpenText™ announced Cloud Editions (CE) 24.2, including OpenText DevOps Cloud and OpenText™ DevOps Aviator.

April 15, 2024

Postman announced its acquisition of Orbit, the community growth platform for developer companies.