JFrog Software Supply Chain Platform Logo

JFrog Software Supply Chain Platform

0
Commercial
Visit Website

The JFrog Platform is a comprehensive software supply chain management solution that integrates multiple security and development components: 1. Repository Management: - Provides universal artifact and ML model repository management through Artifactory - Enables centralized storage and distribution of software packages, containers, and ML models 2. Security Features: - Implements Software Composition Analysis (SCA) for detecting vulnerabilities - Offers source code scanning capabilities (SAST) - Includes secrets detection mechanisms - Provides runtime security monitoring - Features Infrastructure as Code (IaC) security scanning 3. DevSecOps Integration: - Enables package curation and validation - Implements automated security controls throughout the development pipeline - Offers supply chain exposure scanning and impact analysis 4. AI/ML Capabilities: - Supports ML model lifecycle management - Provides security controls specific to AI/ML workflows - Enables model building, training, deployment, and monitoring 5. Distribution and Management: - Facilitates secure software distribution across multiple endpoints - Includes IoT device management capabilities - Supports multi-site deployments and high availability configurations The platform integrates with common development tools and cloud providers, supporting both cloud-native and hybrid deployments while maintaining compliance and security standards.

FEATURES

ALTERNATIVES

Integrates static APK analysis with Yara and requires re-compilation of Yara with the androguard module.

ThreatLocker is an enterprise cybersecurity platform that provides comprehensive endpoint protection and zero-trust security to prevent ransomware, viruses, and other malicious software from running on endpoints.

An insecure web application with multiple vulnerable web service components for learning real-world web service vulnerabilities.

SAST and malware analysis tool for Android APKs with detailed scan information.

Scan files for viruses and malware with language-agnostic REST API

A web security tool that scans for vulnerabilities and known attacks.

A SaaS-based web application firewall that combines signature and behavioral-based threat detection to protect applications deployed across cloud, on-premises and edge environments.

A static code analysis tool for parsing common data formats to detect hardcoded credentials and dangerous functions.

PINNED

ImmuniWeb® Discovery Logo

ImmuniWeb® Discovery

ImmuniWeb Discovery is an attack surface management platform that continuously monitors an organization's external digital assets for security vulnerabilities, misconfigurations, and threats across domains, applications, cloud resources, and the dark web.

Attack Surface Management
InfoSecHired Logo

InfoSecHired

An AI-powered career platform that automates the creation of cybersecurity job application materials and provides company-specific insights for job seekers.

Resources
Mandos Brief Newsletter Logo

Mandos Brief Newsletter

A weekly newsletter providing cybersecurity leadership insights, industry updates, and strategic guidance for security professionals advancing to management positions.

Resources
Checkmarx SCA Logo

Checkmarx SCA

A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Application Security
Check Point CloudGuard WAF Logo

Check Point CloudGuard WAF

A cloud-native web application and API security solution that uses contextual AI to protect against known and zero-day threats without signature-based detection.

Application Security
Orca Security Logo

Orca Security

A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

Cloud Security
DryRun Logo

DryRun

A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.

Application Security
Wiz Logo

Wiz

Wiz Cloud Security Platform is a cloud-native security platform that enables security, dev, and devops to work together in a self-service model, detecting and preventing cloud security threats in real-time.

Cloud Security