JFrog Xray Supports AWS Security Hub
July 27, 2022

JFrog announced its DevSecOps tool, JFrog Xray, now supports Amazon Web Services (AWS) Security Hub, a cloud security posture management service that performs best practice checks, aggregates alerts, and allows automated remediation.

JFrog, already part of the DevSecOps category under the AWS DevOps competency, also revealed it is participating in the new AWS Marketplace Vendor Insights, which helps streamline the complex third-party software risk assessment process by enabling JFrog to make security and compliance information available to customers through AWS Marketplace. By using AWS Marketplace Vendor Insights, customers can reduce the vendor assessment cycle from months down to a few hours by allowing them to access JFrog’s validated security profile.

“Security and trust are at the core of our JFrog product development philosophy. We’re proud to have achieved the AWS DevSecOps Competency, which recognizes JFrog’s technical expertise and our DevOps platform’s ability to securely enable customers through their cloud journey,” said Kelly Hartman, SVP of Global Channels and Alliances, JFrog. “We’re also proud to be part of AWS Marketplace Vendor Insights to provide customers with additional visibility when it comes to vendor solution risk assessments, so they can have greater peace of mind.”

JFrog Xray’s support of AWS Security Hub will help developers ensure security is continuously implemented across development pipelines and that they have a central location for visibility into vulnerability alerts, contextual applicability of the threat, and prioritization of remediation activities.

With JFrog’s new support of AWS Security Hub customers can utilize JFrog Xray to:

- Get a consolidated view of all license compliance and security vulnerabilities across their cloud instances.

- Enhance vulnerability identification, assessment, and management tapping into the JFrog Xray database of critical vulnerabilities exposures (CVEs).

- Better contextualize and prioritize vulnerabilities and automate remediation workflows to reduce Mean Time to Recovery (MTTR).

“AWS Marketplace Vendor Insights make it easier for a customer’s governance, risk, and compliance teams to assess software through a unified web-based dashboard. We are thrilled to partner with JFrog to deliver a streamlined compliance experience and to help customers secure their software supply chain,” said Chris Grusz, Director, Independent Software Vendor Partner and AWS Marketplace Business Development at AWS.

Share this

Industry News

March 28, 2024

Check Point® Software Technologies Ltd. announced a collaboration with Microsoft that utilizes the Microsoft Azure OpenAI Service to enhance Check Point Infinity AI Copilot, marking a significant advancement in cyber security AI applications.

March 28, 2024

ArmorCode announced ArmorCode Risk Prioritization, providing a 3D scoring approach for managing application security risks.

March 28, 2024

AppViewX and Fortanix announced a partnership to offer cloud-delivered secure digital identity management and code signing.

March 27, 2024

WaveMaker has updated its platform in response to customer demand for more sophisticated API and code management tools.

March 27, 2024

Vercara announced the launch of UltraAPI™, a product suite that protects APIs and web applications from malicious bots and fraudulent activity while ensuring regulatory compliance.

March 27, 2024

Legit Security announced the launch of its standalone enterprise secrets scanning product, which can detect, remediate, and prevent secrets exposure across the software development pipeline.

March 26, 2024

Progress announced a strategic partnership with Veeam® Software, the #1 leader by market share in Data Protection and Ransomware Recovery, to provide customers with an enterprise-ready cyber defense solution that strengthens the security of their business-critical data.

March 26, 2024

GitGuardian released its Software Composition Analysis (SCA) module.

March 26, 2024

DataStax announced a milestone in its journey to simplify enterprise retrieval-augmented generation (RAG) for developers by integrating with Microsoft Semantic Kernel.

March 25, 2024

Check Point® Software Technologies Ltd. is collaborating with NVIDIA to enhance the security of AI cloud infrastructure. Integrating NVIDIA BlueField DPUs, which feature a broad range of purpose-built, innovative security capabilities, the new Check Point AI Cloud Protect solution will help prevent threats at both the network and host levels.

March 25, 2024

Sentry announced the release of Autofix, an AI-powered feature to debug and fix code in minutes, saving important time and resources.

March 25, 2024

Apiiro announced a product integration and partnership with Secure Code Warrior, the agile developer security training platform, to extend its ASPM technology and processes to the people layer.

March 21, 2024

Progress announced that Progress® Semaphore™, its metadata management and semantic AI platform, was named a Champion in SoftwareReviews’ 2024 Metadata Management Emotional Footprint Awards.

March 21, 2024

The Cloud Native Computing Foundation® (CNCF®) has partnered with Udemy, an online skills marketplace and learning platform.

March 21, 2024

GitLab has acquired Oxeye, the provider of a cloud-native application security and risk management solution.