Paul Krill
Editor at Large

JFrog Curation blocks malicious open source software packages

news
Jul 19, 20231 min

DevSecOps system validates incoming software packages against JFrog’s security research library to establish a repository of trustworthy components for software developers to use.

shutterstock 1127162939 traffic light  red yellow green code 1200x800
Credit: Titima Ongkantong / Shutterstock

JFrog has unveiled JFrog Curation, a devsecops system designed to prevent malicious or risky open source or third-party software packages from entering an organization’s software development pipeline.

JFrog Curation blocks the use of risky open source software packages without compromising development speed or the developer experience, JFrog said. It uses binary metadata for identifying malicious packages with higher-severity CVEs (Critical Vulnerabilities and Exposures), operational, or license compliance issues. This removes the need to download each package for scanning before use, thus preserving developer ease and speed, JFrog said.

JFrog Curation validates incoming software packages against JFrog’s security research library of recorded CVEs and publicly available information to establish a repository of pre-approved, third-party software components for development use. It provides central visibility and governance of every open source package requested by a developer or build tool and creates an audit trail to comply with regulatory requirements, JFrog said.

Paul Krill

Paul Krill is editor at large at InfoWorld. Paul has been covering computer technology as a news and feature reporter for more than 35 years, including 30 years at InfoWorld. He has specialized in coverage of software development tools and technologies since the 1990s, and he continues to lead InfoWorld’s news coverage of software development platforms including Java and .NET and programming languages including JavaScript, TypeScript, PHP, Python, Ruby, Rust, and Go. Long trusted as a reporter who prioritizes accuracy, integrity, and the best interests of readers, Paul is sought out by technology companies and industry organizations who want to reach InfoWorld’s audience of software developers and other information technology professionals. Paul has won a “Best Technology News Coverage” award from IDG.

More from this author