home.social

#jfrog — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #jfrog, aggregated by home.social.

fetched live
  1. 🚨 Ah yes, the perilous saga of imaginary #SQLite #vulnerabilities - where #JFrog #Security bravely fights against the fearsome specter of non-existent code. 🙄 #NVD and #CISA, always on the pulse of non-issues, declared a crisis, but JFrog heroically deduced the obvious: the boogeyman doesn’t exist. 👏
    research.jfrog.com/post/sqlite #Cybersecurity #Humor #HackerNews #ngated

  2. 🚨 Ah yes, the perilous saga of imaginary #SQLite #vulnerabilities - where #JFrog #Security bravely fights against the fearsome specter of non-existent code. 🙄 #NVD and #CISA, always on the pulse of non-issues, declared a crisis, but JFrog heroically deduced the obvious: the boogeyman doesn’t exist. 👏
    research.jfrog.com/post/sqlite #Cybersecurity #Humor #HackerNews #ngated

  3. OpenAI Models Exploit JFrog Zero-Days to Breach Hugging Face

    OpenAI's models uncovered critical zero-day vulnerabilities in JFrog's self-hosted Artifactory installations, potentially granting hackers unrestricted internet access - but thanks to JFrog's swift response, fixes were rapidly developed and deployed to protect customers. The vulnerabilities, now patched, were responsibly disclosed by OpenAI…

    osintsights.com/openai-models-

    #ZeroDay #Jfrog #Openai #Artifactory #VulnerabilityDisclosure

  4. Стало известно, как ИИ‑агент OpenAI сбежал и взломал Hugging Face. Дыра нашлась в софте JFrog

    В истории о том, как две модели OpenAI “сбежали” во время тестирования и взломали Hugging Face, появилась новая важная деталь. До недавнего времени было незвестно, как именно модели смогли выбраться. OpenAI говорила обтекаемо — про zero‑day в некоем стороннем ПО, которое проксировало пакетные репозитории, — но вендора не называла. 27 июля дыра обрела имя: в блоге компания JFrog призналась, что уязвимости нашлись в ее собственном продукте — Artifactory.

    habr.com/ru/articles/1064180/

    #OpenAI #Hugging_face #Jfrog

  5. RE: mastodon.ie/@JSAMcFarlane/1167

    This hit me again so I filed an issue fully expecting the Conan team to reject it. Fair play, they changed their CLI within half a day!❤️ #simplicity #jfrog #software

  6. RE: mastodon.ie/@JSAMcFarlane/1167

    This hit me again so I filed an issue fully expecting the Conan team to reject it. Fair play, they changed their CLI within half a day!❤️ #simplicity #jfrog #software

  7. #NanoClaw and #JFrog have partnered to launch a #security integration that protects NanoClaw autonomous #agents from malicious #codeinjection. The integration hardwires NanoClaw agents to JFrog’s vetted software registries, ensuring they only download safe dependencies. This addresses the growing risk of autonomous agents installing packages without human oversight, often falling victim to software supply chain attacks. venturebeat.com/security/nanoc #AIagent #AI #ML #NLP #LLM #GenAI

  8. #NanoClaw and #JFrog have partnered to launch a #security integration that protects NanoClaw autonomous #agents from malicious #codeinjection. The integration hardwires NanoClaw agents to JFrog’s vetted software registries, ensuring they only download safe dependencies. This addresses the growing risk of autonomous agents installing packages without human oversight, often falling victim to software supply chain attacks. venturebeat.com/security/nanoc #AIagent #AI #ML #NLP #LLM #GenAI

  9. JFrog (IL0011684181) sorgt mit Insider-Verkäufen und einer Kursbewertung, die viele Trader als überhöht empfinden, für Diskussionen.
    • Hohe Bewertung wirft Fragen zur Unternehmensentwicklung auf
    • Insider-Verkäufe oft als Warnsignal interpretiert
    • Tech-Sektor bleibt volatile Lage

    #DevOps #JFrog #TechStocks #PrivacyTech #Decentralization

    🔗 news.google.com/rss/articles/C

  10. Just found #JFrog's SKILL repository docs.jfrog.com/artifactory/doc which feels like the slightly heavy handed enterprise approach. lets see if there is something a sightly more lightweight.

  11. Just found #JFrog's SKILL repository docs.jfrog.com/artifactory/doc which feels like the slightly heavy handed enterprise approach. lets see if there is something a sightly more lightweight.

  12. To my #jfrog bubble: Given #artifactory with a remote (cached) repository. I can see the contents of the remote repo using curl commands, even using jf rt curl commands. But if I try to jf rt search for something, it doesn't return results. For jf rt dl you have to set JFROG_CLI_TRANSITIVE_DOWNLOAD=true. Is there something similar for jf rt search? Or do I have to code up a recursive curl based search?

  13. To my #jfrog bubble: Given #artifactory with a remote (cached) repository. I can see the contents of the remote repo using curl commands, even using jf rt curl commands. But if I try to jf rt search for something, it doesn't return results. For jf rt dl you have to set JFROG_CLI_TRANSITIVE_DOWNLOAD=true. Is there something similar for jf rt search? Or do I have to code up a recursive curl based search?

  14. I searched quite a bit this morning, and it turns out there is a far better open-source tool that works as an Artifactory replacement for small projects. It's not in any of the alternatives-to lists. It is known as mkdir.

    #artifactory #jfrog #linux #selfhosting

  15. I searched quite a bit this morning, and it turns out there is a far better open-source tool that works as an Artifactory replacement for small projects. It's not in any of the alternatives-to lists. It is known as mkdir.

    #artifactory #jfrog #linux #selfhosting

  16. Just stumbled upon the #JFrog AI Catalog "Your centralized hub for all AI models and initiatives, from third-party to internally-developed. It simplifies model discovery and access, provides robust governance, and accelerates the delivery of trusted AI applications."
    jfrog.com/ai-catalog/

  17. Just stumbled upon the #JFrog AI Catalog "Your centralized hub for all AI models and initiatives, from third-party to internally-developed. It simplifies model discovery and access, provides robust governance, and accelerates the delivery of trusted AI applications."
    jfrog.com/ai-catalog/

  18. @mvniekerk at 2025 , they don't know about #artifactory and #jfrog 🤓 even GitHub also head some repository functionality

  19. @mvniekerk at 2025 , they don't know about and 🤓 even GitHub also head some repository functionality

  20. #boycottJfrog they support what Israel is doing in #Gaza. They support #genocide. Here are the alternatives to their products

    - #sonatype nexus
    - #snyk
    - azure, gcp, aws container registries

    In all cases, the other solutions are cheaper. Don’t use #jfrog products

  21. #boycottJfrog they support what Israel is doing in #Gaza. They support #genocide. Here are the alternatives to their products

    - #sonatype nexus
    - #snyk
    - azure, gcp, aws container registries

    In all cases, the other solutions are cheaper. Don’t use #jfrog products

  22. Ich möchte jemanden angespitzt in den Boden stampfen.
    ❯ curl -IL https://repository.example.com/
    HTTP/1.1 302 Moved Temporarily
    Server: nginx/1.24.0 (Ubuntu)
    Date: Fri, 21 Feb 2025 08:44:06 GMT
    Content-Type: text/html
    Content-Length: 154
    Location: https://repository.example.com/ui/
    Connection: keep-alive
    
    HTTP/1.1 502 Bad Gateway

    Hingegen:
    ❯ curl -IL --user-agent "Microsoft Edge" https://repository.example.com/
    HTTP/1.1 302 Moved Temporarily
    Server: nginx/1.24.0 (Ubuntu)
    Date: Fri, 21 Feb 2025 08:52:12 GMT
    Content-Type: text/html
    Content-Length: 154
    Location: https://repository.example.com/ui/
    Connection: keep-alive
    
    HTTP/1.1 200 OK

    #Jfrog #Artifactory
  23. Huh.. rumor of #jfrog using #databrokers to get more data on people trying out their service and making some aggressive style marketing movements. I didn't send them my number.. why and how are they texting me?

  24. Huh.. rumor of #jfrog using #databrokers to get more data on people trying out their service and making some aggressive style marketing movements. I didn't send them my number.. why and how are they texting me?

  25. Anyone know someone at I could reach out to, concerning their SaaS solution for ?

    Ran into issues where it looks like they need to update some of their AWS backend infra configuration to support IPv6 (dualstack) to accept users that are reaching out from IPv6-only environments. Otherwise, packages are unable to be downloaded from their hosted endpoints in those scenarios.

  26. Anyone know someone at #JFrog I could reach out to, concerning their SaaS solution for #Artifactory ?

    Ran into issues where it looks like they need to update some of their AWS backend infra configuration to support IPv6 (dualstack) to accept users that are reaching out from IPv6-only environments. Otherwise, packages are unable to be downloaded from their hosted endpoints in those scenarios.

  27. GitHub has announced a new partnership with JFrog Ltd., bringing advanced security capabilities directly into the GitHub developer workflow. #GitHub dlvr.it/TFrvss #GitHub #JFrog #DevSecOps

  28. Supply chain attack na Pythona, czyli o krok od kolejnego dużego incydentu

    Często słyszy się określenie, że bezpieczeństwo to ciągła „gra w kotka i myszkę” lub wyścig. W rzeczy samej, często badacze muszą ścigać się z przestępcami, aby zapobiec poważnym atakom. Od czasu ataku na SolarWinds, dużą popularność i rozgłos zyskują ataki na łańcuch dostaw. Na łamach sekuraka opisywaliśmy wielokrotnie sytuacje, w...

    #WBiegu #Jfrog #Pypi #Python #Supplychain

    sekurak.pl/supply-chain-attack

  29. Supply chain attack na Pythona, czyli o krok od kolejnego dużego incydentu

    Często słyszy się określenie, że bezpieczeństwo to ciągła „gra w kotka i myszkę” lub wyścig. W rzeczy samej, często badacze muszą ścigać się z przestępcami, aby zapobiec poważnym atakom. Od czasu ataku na SolarWinds, dużą popularność i rozgłos zyskują ataki na łańcuch dostaw. Na łamach sekuraka opisywaliśmy wielokrotnie sytuacje, w...

    #WBiegu #Jfrog #Pypi #Python #Supplychain

    sekurak.pl/supply-chain-attack

  30. #JFrog / Zero tolerance for the sad horrific truth

    Israelis are thin skinned and can’t deal with criticism. Who knew.

    Q: You are an Israeli company with branches around the world. Has the war affected you?

    Shlomi Ben-Chaim: "On October 11th, one of the employees wrote anti-Israel words on her Instagram. She was fired within two hours. She is suing me. We are a global Israeli company, no one will hide or conceal this, we grew up here. This is the flag on NASDAQ and in Netiv HaAsara. We are present in many countries, in Europe and the USA, in India and China, and it's like providing education at home. Don't be surprised if your employees behave this way if you don't set boundaries for them. JFrog has a very clear set of values written by the employees, not by management, and every employee must respect them. Not comfortable with them? It's a free country, work somewhere else. Anyone who came out against Israeliness in any manifestation was out of the company. This is natural loyalty, I believe this is how they would act in any company in the world."​​​​​​​​​​​​​​​​

    [Hebrew] ynet.co.il/economy/article/sjn

    @israel
    @palestine
    #IsraelWarCrimes #Ethnocide