1. https://appdevelopermagazine.com/open-source
  2. https://appdevelopermagazine.com/jfrog-xray-offers-visibility-for-container-images,-software-packages-and-binary-artifacts/
5/25/2016 3:02:18 PM
JFrog Xray Offers Visibility for Container Images, Software Packages and Binary Artifacts
JFrog,Open API,Xray,REST
/JFrog-Xray-App-Developer-Magazine_oldrleov.jpg
App Developer Magazine
JFrog Xray Offers Visibility for Container Images, Software Packages and Binary Artifacts

Open Source

JFrog Xray Offers Visibility for Container Images, Software Packages and Binary Artifacts


Wednesday, May 25, 2016

Stuart Parkerson Stuart Parkerson


JFrog has announced the launch of JFrog Xray, which provides visibility into the contents of software components. JFrog Xray is a universal impact analysis product, to provide companies with understanding about their container images, software packages and binary artifacts, providing insight into the huge volume and variety of components that development teams share in the software build and distribution process.

The technology solves a problem for companies as they increase their use of container technology and make open source part of their development strategies. With so many open source components available, it has become extremely difficult, if not impossible, for application builders to know pertinent information about each one and avoid security issues, such as the Heartbleed bug in the OpenSSL cryptographic software library that put user passwords on many popular websites at risk.

JFrog Xray analyzes the relationships between binary artifacts across an entire organization and the impact that one component has on any other. In addition to security vulnerabilities, JFrog Xray can also analyze the potential impact of performance issues or architectural changes.

JFrog Xray is a fully automated platform with a REST API allowing integration and automation with an organization’s CI/CD pipeline, and enabling other inspection and security tools to fit into the full build-to- production automated flow.

JFrog Xray includes the VersionEye technology and database. VersionEye is a startup company based in Mannheim, Germany whose platform helps improve developer productivity through a system that tracks open source libraries and alerts developers in real time to key information such as security vulnerabilities, license violations and outdated dependencies.

The platform offers the following functionality:


- Impact analysis that indicates how production and continuous integration (CI) environments are impacted.

- A full dependencies graph on which users can easily zoom in to find vulnerability or compliance issues.

- An open API that enables integration with all current and future types of component-scanning technology to allow custom scanning capabilities for performance, quality, popularity or any other criteria required.

- A universal solution that integrates with vulnerability and license compliance databases such as VersionEye, Black Duck and WhiteSource.

- Integration with a user’s registry and repository to allow full sync through all the CI/CD flow.




Read more: https://www.jfrog.com/xray/




Subscribe to App Developer Magazine

Become a subscriber of App Developer Magazine for just $5.99 a month and take advantage of all these perks.

MEMBERS GET ACCESS TO

  • - Exclusive content from leaders in the industry
  • - Q&A articles from industry leaders
  • - Tips and tricks from the most successful developers weekly
  • - Monthly issues, including all 90+ back-issues since 2012
  • - Event discounts and early-bird signups
  • - Gain insight from top achievers in the app store
  • - Learn what tools to use, what SDK's to use, and more

    Subscribe here



Featured Stories


Spotlite Expands Into AI Era With New IP Protection Tool
Spotlite Expands Into AI Era With New IP Protection Tool Wednesday, June 3, 2026




Spotify and UMG strike landmark AI music licensing deal
Spotify and UMG strike landmark AI music licensing deal Thursday, May 28, 2026


Anthropic investigation opened after Mythos accessed by Discord group
Anthropic investigation opened after Mythos accessed by Discord group Wednesday, May 27, 2026


AI layoffS: What is really behind it all
AI layoffS: What is really behind it all Tuesday, May 26, 2026


The identity system is failing under AI
The identity system is failing under AI Monday, May 25, 2026


The Real World Launches Expert-Verified AI Certification Framework
The Real World Launches Expert-Verified AI Certification Framework Friday, May 22, 2026


Multiple language options when developing apps with Evoke
Multiple language options when developing apps with Evoke Thursday, May 21, 2026


When Social Listening Becomes Social Surveillance
When Social Listening Becomes Social Surveillance Wednesday, May 20, 2026


Medical debt relief custom-built platform moopFi launches
Medical debt relief custom-built platform moopFi launches Tuesday, May 19, 2026


Quant Pros Say AI Is Widening the Skills Gap
Quant Pros Say AI Is Widening the Skills Gap Monday, May 18, 2026


Stay Updated

Sign up for our newsletter for the headlines delivered to you

SuccessFull SignUp

Get More App News



/sites/themes/prod/assets/js/less.js"> ' ' %>