VOOZH about

URL: https://thenewstack.io/jfrog-platform-crypto-signs-binaries-for-secure-software-lifecycle-management/

⇱ JFrog Platform 'Crypto-Signs' Binaries for Zero-Trust Software Lifecycle Management - The New Stack


TNS
SUBSCRIBE
Join our community of software engineering leaders and aspirational developers. Always stay in-the-know by getting the most important news and exclusive content delivered fresh to your inbox to learn more about at-scale software development.
REQUIRED
It seems that you've previously unsubscribed from our newsletter in the past. Click the button below to open the re-subscribe form in a new tab. When you're done, simply close that tab and continue with this form to complete your subscription.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.
Welcome and thank you for joining The New Stack community!
Please answer a few simple questions to help us deliver the news and resources you are interested in.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Great to meet you!
Tell us a bit about your job so we can cover the topics you find most relevant.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Welcome!

We’re so glad you’re here. You can expect all the best TNS content to arrive Monday through Friday to keep you on top of the news and at the top of your game.

What’s next?

Check your inbox for a confirmation email where you can adjust your preferences and even join additional groups.

Follow TNS on your favorite social media networks.

Become a TNS follower on LinkedIn.

Check out the latest featured and trending stories while you wait for your first TNS newsletter.

PREV
1 of 2
NEXT
VOXPOP
As a JavaScript developer, what non-React tools do you use most often?
Angular
0%
Astro
0%
Svelte
0%
Vue.js
0%
Other
0%
I only use React
0%
I don't use JavaScript
0%
Thanks for your opinion! Subscribe below to get the final results, published exclusively in our TNS Update newsletter:
NEW! Try Stackie AI
From clobbered drafts to real-time sync
Apr 14th 2026 10:00am, by David Moore
TypeScript 6.0 RC arrives as a bridge to a faster future
Mar 14th 2026 9:00am, by Darryl K. Taft
Mastra empowers web devs to build AI agents in TypeScript
Jan 28th 2026 11:00am, by Loraine Lawson
2021-05-26 09:26:48
JFrog Platform 'Crypto-Signs' Binaries for Zero-Trust Software Lifecycle Management
news,sponsor-jfrog,sponsored-event-coverage,
DevOps / Security / Software Development

JFrog Platform ‘Crypto-Signs’ Binaries for Zero-Trust Software Lifecycle Management

JFrog's Crypto-signing is the first commercial use of a blockchain technology by a commercial DevOps build, or CI/CD platform.
May 26th, 2021 9:26am by Joab Jackson
👁 Featued image for: JFrog Platform ‘Crypto-Signs’ Binaries for Zero-Trust Software Lifecycle Management
JFrog sponsored this post.

The JFrog DevOps Platform is putting the blockchain to use, digitally signing the software binaries to document and secure their journeys through the entire development process.

JFrog‘s crypto-signing functionality may be the first commercial use of a blockchain technology to capture changes on a CI/CD platform, asserted JFrog founder and chief technology officer Yoav Landman. This update, and others unveiled at the company’s SwampUP user conference being held this week virtually, are part of the JFrog’s overall goal to give enterprises, and their developers, more efficient and secure ways to manage the software development lifecycle.

The management of software binaries — the actual application after its code has been compiled into an executable program — is a huge portion of this lifecycle management, Landman said in an interview with The New Stack.

Fearless delivery with a hybrid, universal, end-to-end DevOps platform. Universal package repository, SecOps, CI/CD and software distribution all in one platform. Available on all clouds or in a self-hosted HA solution. JFrog and TNS are under common control.
Learn More
The latest from JFrog

“Developers like to think about code, but in reality, what’s happening is that the transition to binary is almost immediate,” Landman said. Even in accelerated DevOps schedules, binaries are needed to build against as dependencies. “The binary that will travel all the way to the runtime, through scanning, distribution, all the QA testing for different phases, all the way to production.”

Zero-Trust Pipelines

A software development pipeline is essentially a series of events to build an application and then move it to production. Each action can be captured in a log for record-keeping and accountability purposes. The crypto-signing augmentation of JFrog Pipelines workflow functionality automatically signs each step, and outcome, in the continuous integration and delivery (CI/CD) pipeline, in effect creating immutable a set of artifacts.  The platform uses a blockchain,  a cryptographically signed write-only ledger to provide proof of each pipeline action.

This approach has an obvious security benefit in that only those binaries that have been signed at each step of the process can be moved into production.

It provides cryptographic “non-disputable proof that everything that happened in the background really happened,” Landman said. Every action is signed with a private key, which is then disposed, leaving only the corresponding public key to read the entry into the append-only log.  Each entry is formatted in JSON, which can be easy to read and program against.

.@JFrog‘s new Signed Pipelines feature “collects a rich set of metadata during the build process, including the input, output and configuration. The collected metadata is signed and associated with artifacts that are being generated.”–@drorbr #SwampUP #Spon #ZeroTust #Blockchain pic.twitter.com/t6yXgsWPJh

— The New Stack (@thenewstack) May 26, 2021

“You have many steps in your pipeline for creating software, and for upgrading software. At the end of the day, you want to verify that what ends up in your runtime in your production is exactly the same thing that you initially built and packaged and compiled,” Landman said, pointing to the growing concern of securing the software development pipeline against attacks and malicious code.

As an example, a manager may have to approve through ServiceNow a software application being moved into production. This capability will capture that approval point in a tamper-proof way. It can also stop software drift, or minor configurations made by some developer that may in the short term be helpful, but ultimately moves the software away from the desired configuration.

“Most of the #DevOps infinity loop is applied to binaries and is about managing binaries. #BinOps is most fundamental thing in achieving fast and reliable software releases.” — @jfrog‘s @_yoav_
#SwampUP #Sponsored #SLDC #Dev pic.twitter.com/R8bNhlfNKg

— The New Stack (@thenewstack) May 26, 2021

Also in the Box

Other new features to the DevOps platform revealed include Cold Artifact Storage to archive software artifacts no longer actively needed but still required for regulatory requirements or corporate policies. A new security service, based on JFrog Xray, to scan open source third-party dependencies, will also be available later this year.

Also new for the platform are federation capabilities for the JFrog Artifactory, allowing organizations to build out multiple software repositories, synchronizing the contents across all of them. The new federated repository service offers automatic mirroring bi-directional synchronization of all binaries across separate instances of the JFrog DevOps Platform — the different “members” of the federation. In addition to the binaries, configuration and metadata can also be mirrored.

👁 Image

The JFrog DevOps platform is available both as a hosted service and as stand-alone software that can be run in-house.

JFrog is sponsoring our coverage of SwampUP, so check back here, and on our Twitter account,  for updates throughout the day, and in the week to come.

Fearless delivery with a hybrid, universal, end-to-end DevOps platform. Universal package repository, SecOps, CI/CD and software distribution all in one platform. Available on all clouds or in a self-hosted HA solution. JFrog and TNS are under common control.
Learn More
The latest from JFrog
TRENDING STORIES
Joab Jackson is a senior editor for The New Stack, covering cloud native computing and system operations. He has reported on IT infrastructure and development for over 30 years, including stints at IDG and Government Computer News. Before that, he...
Read more from Joab Jackson
JFrog sponsored this post.
SHARE THIS STORY
TRENDING STORIES
TNS owner Insight Partners is an investor in: Pragma.
SHARE THIS STORY
TRENDING STORIES
TNS DAILY NEWSLETTER Receive a free roundup of the most recent TNS articles in your inbox each day.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.