JFrog Releases OSS Tools to Identify Log4j Utilization in Both Binaries & Source Code
JFrog Ltd. (NASDAQ: FROG) has launched free open-source scanning tools to help developers identify and address Apache Log4j vulnerabilities in their software. The four new tools are designed for both Java and Python environments and provide specialized scans for direct and transitive dependencies. With nearly half of global enterprises impacted by the Log4j vulnerability, JFrog aims to facilitate community collaboration to enhance security practices. The tools can be downloaded via GitHub and integrate easily into existing developer workflows.
- Launch of four free scanning tools to identify Log4j vulnerabilities.
- Tools available for both Java and Python users.
- Strong community collaboration emphasized for security improvements.
- None.
Open-Source Tools Allow Developers to Quickly Determine Exposure & Focus Remediation Efforts to Speed Time to Resolution
The new tools perform specialized scans to identify direct or indirect (transitive) dependencies, as well as instances where Log4j does not appear as a separate file, but is bundled inside a larger software package and harder to detect. The new tools are command line-based for easy integration with developers’ existing environments and their open-core helps ensure the capabilities will continue to evolve over time as needs change.
“The Log4j vulnerability has set the enterprise software landscape on fire due to its widespread usage as a component across the software supply chain, making it difficult to rapidly pinpoint and remediate,” said
Industry research estimates nearly half of all global enterprises have already been impacted by the Log4j vulnerability with incidents rising by the day. Government officials from
The Log4j vulnerability was originally discovered and reported to Apache by the
Interested parties can also register to learn more about Log4j, its impact, and how to quickly identify and manage threats in JFrog’s webinar, “Log4Shell Vulnerability: All you need to know,” taking place on
Like this Story? Tweet this: .@jfrog releases 4 new OSS tools to help identify and remediate Log4j vulnerabilities. Download them now: https://github.com/jfrog/log4j-tools
About JFrog
JFrog is on a mission to be the company powering all of the world’s software updates, driven by a “Liquid Software” vision to allow the seamless, secure flow of binaries from developers to the edge. The company’s end-to-end DevOps platform – the JFrog Platform - provides the tools and visibility required by modern organizations to solve today’s challenges across critical pieces of the DevOps cycle. JFrog’s hybrid, universal, multi-cloud DevOps platform is available as both self-managed and SaaS services on a number of cloud service provider platforms. JFrog is trusted by millions of users and thousands of customers, including a majority of the Fortune 100 companies that depend on JFrog solutions to manage their mission-critical software delivery pipelines. Learn more at jfrog.com.
Cautionary Note About Forward-Looking Statements
This press release contains “forward-looking” statements, as that term is defined under the
There are a significant number of factors that could cause actual results, performance or achievements, to differ materially from statements made in this press release, including but not limited to risks detailed in our filings with the
View source version on businesswire.com: https://www.businesswire.com/news/home/20211216005779/en/
Press Contact:
Jfrog@bocacommunications.com
Investor Contact:
jhorne@marketstreetpartners.com
Source:
FAQ
What new tools did JFrog release for Log4j vulnerabilities?
How can developers work with the new JFrog scanning tools?
What impact does the Log4j vulnerability have on enterprises?
Is there a specific date for JFrog's webinar on Log4j?