JFrog and GitHub Expand Partnership, Deliver Single Pane of Glass for Security and Copilot Chat to Empower Developers
Enhanced integration delivers Copilot chat powered by comprehensive software package insights, alongside holistic software supply chain security protection from code to binaries
This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20240910960053/en/
JFrog and GitHub expand partnership to deliver unified view of project status and security posture, plus a new Copilot chat extension for validating third-party software packages. (Graphic: Business Wire)
“For developers to be productive, they need complete information about the quality and security of the code and binaries they integrate into their software. Our partnership with GitHub enables teams to do this quickly and with confidence using Copilot,” said
According to JFrog’s 2024 Software Supply Chain State of the Union report, only 56% of companies use both source code and binary scanning to secure their software supply chains, leaving nearly half of companies vulnerable to attacks at the binary level. This is very risky, as underscored by the
Creating Secure Developer Workflows by Uniting Best-of-Breed Source Code and Binary Platforms
JFrog’s integration with GitHub is expected to offer an easier, more secure way to trace code from its source to the resulting binaries across both platforms with the following key capabilities:
- Copilot Chat Integration for Software Package Insights: The new GitHub Copilot extension boosts developer productivity by providing insights on open-source packages within the JFrog binary environment alongside GitHub code data, eliminating the need to search through documentation or online forums. It also aligns recommendations with organizational curation policies, enabling informed software package choices that consider security and market adoption. Combining Copilot's chat features with JFrog's artifact metadata creates an invaluable AI-powered assistant for developers.
- Consolidated, Single Pane of Glass Security Dashboard: A unified view of security scan results from GitHub Advanced Security and JFrog Advanced Security (including the scanners that found the Python vulnerability mentioned above), helping developers address and remove potential software vulnerabilities earlier in the development lifecycle, saving time and reducing risk.
- Bidirectional End-to-End Release Lineage: The new job summary page on GitHub offers a quick view of the health and security status of each GitHub Actions Workflow, allowing developers to quickly see the output packages from each build, navigate to their location in JFrog Artifactory and back again. This bidirectional navigation utilizes a software bill of materials (SBOM) preserved in JFrog Artifactory, enhancing software lineage traceability.
- Dynamic Project Mapping and Authentication: Improved automatic authorization and seamless project mapping between GitHub Repositories and JFrog Projects in Artifactory utilizing current OpenID Connect (OIDC) integration, eliminating the need for developers to reauthenticate per repository.
For a deeper look at the one-platform experience provided by the JFrog and GitHub integration and partnership, visit the solutions page or read this blog.
Like this story? Post this on X (formerly Twitter): .@jfrog and @gitHub partner to deliver #security & #AI in a one platform experience for #developers. Learn more: https://jfrog.co/3MB3Ygb #DevSecOps #SDLC #softwaresupplychain
About JFrog
Cautionary Note About Forward-Looking Statements
This press release contains “forward-looking” statements, as that term is defined under the
These forward-looking statements are based on our current assumptions, expectations and beliefs and are subject to substantial risks, uncertainties, assumptions and changes in circumstances that may cause JFrog’s actual results, performance or achievements to differ materially from those expressed or implied in any forward-looking statement. There are a significant number of factors that could cause actual results, performance or achievements to differ materially from statements made in this press release, including but not limited to risks detailed in our filings with the
View source version on businesswire.com: https://www.businesswire.com/news/home/20240910960053/en/
Media Contact:
jfrog@bocacommunications.com
Investor Contact:
Source: