JFrog Unveils New DevSecOps Contextual Analysis Capabilities
JFrog Ltd. (NASDAQ: FROG) has launched enhancements to its JFrog Xray DevSecOps solution, incorporating advanced contextual analysis capabilities. This update allows customers to evaluate the relevance and threat levels of known vulnerabilities, referred to as CVEs, more efficiently. The new features are part of JFrog's strategy following its acquisition of Vdoo in June 2021, enabling automated, scalable identification and prioritization of vulnerabilities. These advancements are aimed at improving security response times for DevSecOps teams, helping them focus on critical threats amidst increasing software vulnerabilities.
- Introduction of advanced contextual analysis in JFrog Xray enhances vulnerability assessment capabilities.
- Improved accuracy in prioritizing remediation efforts for CVEs, enabling faster responses.
- Integration with JFrog Artifactory provides a comprehensive solution for vulnerability management.
- None.
Latest Release of JFrog Xray Helps Customers Dynamically Assess the Relevance, Impact & Needed Remediation for Security Vulnerabilities, Speeding Time to Resolution
The new contextual analysis features in the latest release of JFrog Xray allow customers to more precisely determine the threat level and relevance of common vulnerability exposures (CVEs), leading to more rapid and accurately-prioritized remediation. The new solution is also a proof point of JFrog's integrated roadmap following its Vdoo acquisition in
Rather than spending time and resources on researching or solving each new CVE based on the common vulnerability scoring system (CVSS), JFrog Xray’s contextual analysis capabilities take an intelligent approach to software scans at the binary level, painting a more complete picture of the applicability and danger of each vulnerability. Knowing whether a particular CVE is relevant to your environment and easily exploitable will help already over-stretched DevSecOps teams quickly pinpoint and address their most critical security gaps. Because JFrog Xray is part of the JFrog Platform, once a vulnerability is identified, customers can securely build, distribute, and connect the required software updates from end to end.
“We are thrilled to offer customers an integrated platform approach for quickly determining each CVE’s applicability and risk, then deploying the appropriate remediation,” said
In a world where software vulnerabilities and attacks are increasing at unprecedented rates in terms of both volume and sophistication, industry research indicates the average time needed for businesses and agencies to fix security vulnerabilities grew from 197 days to 202 days over the first half of 20211. Traditional software composition analysis (SCA) tools can often find hundreds of vulnerabilities in a single scan, giving development teams the arduous task of determining which vulnerabilities truly matter. Using advanced binary scans of container images, JFrog Xray’s contextual analysis delivers a more accurate picture of what vulnerabilities exist, if they are relevant, and/or easily exploitable – enabling developers and DevSecOps teams to prioritize efforts and resources for swift remediation.
Identification and assessment of relevant contextual factors such as the existence of a reachable path to the vulnerable code, or a configuration variable that affects the CVE applicability, typically require extensive manual analysis by security experts. This approach cannot meet the needs of modern businesses to secure at DevOps speed and scale. As a recognized
Contextual analysis and the other new features in JFrog Xray will be rolled out progressively across the JFrog customer base starting in mid-February. This JFrog Xray update is supported across multiple languages and architectures, including JS, Java and Python based on JFrog’s universal product philosophy. For additional information on contextual analysis and other new features in the latest version of JFrog Xray read this blog or visit the JFrog Xray solution page. Interested parties can also register to learn more about the new contextual analysis, enhanced CVE data, Git Dependency Scanning, and SBOM capabilities in JFrog Xray during our “New Year, New Features in Xray” webinar.
Like this Story? Tweet this: .@jfrog unveils JFrog Xray contextual analysis capabilities, providing dynamic CVE assessment at the binary level to help speed time to resolution. #cybersecurity #DevSecOps #Xray
About JFrog
Cautionary Note About Forward-Looking Statements
This press release contains “forward-looking” statements, as that term is defined under the
There are a significant number of factors that could cause actual results, performance or achievements, to differ materially from statements made in this press release, including but not limited to risks detailed in our filings with the
____________________
1 https://securityintelligence.com/news/news-vulnerabilities-25-days-remediate/
View source version on businesswire.com: https://www.businesswire.com/news/home/20220216005530/en/
Media Contact:
Investor Contact:
Source:
FAQ
What are the new features in JFrog Xray released in February 2022?
How does JFrog Xray help with security vulnerability remediation?
What company announced the new JFrog Xray features?
When will the new JFrog Xray features be available to customers?