• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • Skip to secondary sidebar
  • Skip to footer

Cybersecurity Market

Cybersecurity Technologies & Markets

  • Cyber Security Events 2023-2024
  • Market Reports
  • Sponsored Post
  • Make a Contribution
  • About
  • Contact

JFrog Ushers in New Era of Open-Source Software Security, Launching Project Pyrsia to Help Prevent Software Supply Chain Attacks

May 25, 2022 By admin

JFrog, Docker, DeployHub, Futurewei, and Oracle Collaborate on Blockchain-based Decentralized Network for Validating Software Packages and Binary Code

SUNNYVALE, Calif. & SAN DIEGO, May 25, 2022 – (swampUP 2022) – JFrog Ltd. (“JFrog”) (NASDAQ: FROG), the Liquid Software company and creators of the JFrog DevOps Platform, today introduced Project Pyrsia, an open-source software community initiative that utilizes blockchain technology to secure software packages (A.K.A Binaries) from vulnerabilities and malicious code. Available for sign-ups immediately, Project Pyrsia is an open-source-based, decentralized, secure build network and software package repository aimed at helping developers establish chain of provenance for their software components, creating greater confidence and trust.

“Open-source is everywhere, and while it has always been seen as a seed for innovation and modernization, the recent rise of software supply chain attacks has made every organization vulnerable,” said Shlomi Ben Haim, Co-Founder and CEO, JFrog. “Led by developers and for developers, JFrog is proud to work with the community on developing Project Pyrsia so everyone can continue to embrace open source with confidence, while protecting the software supply chain.”

Open-source software is a critical element of nearly every technology we use today – from our operating systems and browsers to the applications and services on which we depend to run our lives. Yet there’s no question the volume, sophistication and severity of software supply chain attacks has increased in the last year. In recent months the JFrog Security Research team tracked over 20 different open-source software supply chain attacks – two of which were zero-day threats. While open-source components are designed to make development more efficient, not knowing where your software comes from makes it hard to spot risks – seeding doubt and uncertainty about its safety.

Thus, JFrog and other open-source technology leaders, including Docker, DeployHub, Futureway, and Oracle, worked together to establish the Project Pyrsia network for validating the source and security of open-source software packages. With Pyrsia, developers can confidently use open-source software knowing their components have not been compromised, without needing to build, maintain, or operate complex processes for securely managing dependencies.

“At JFrog we believe open-source security will only be successful if we provide the community with the same tools and services that are available to enterprises,” said Stephen Chin, VP of Developer Relations, JFrog. “The combination of an open-source, customizable architecture, and a robust, active community makes Pyrsia the most transparent and trustworthy way to obtain secure software packages. We’re grateful for the help of our industry partners and the community for joining us in securing open source so it can remain a true fountain of innovation.”

Pyrsia aims to seamlessly integrate with the package management systems developers are already using today, so they can certify their software components without foregoing compatibility, security, or efficiency. Utilizing standards like Sigstore’s Cosign and Notary V2 allows developers to quickly access their containers leveraging the Pyrsia network. Using digital signatures, developers receive an immutable chain of evidence for their code, providing peace of mind from knowing the exact source of their packages.

To help guide developers on the process of using Pyrsia for validating software components, a select few entities will build and publish images that will be available for everyone’s use – otherwise known as ‘bootstrapping’ the project. Organizations interested in supporting Pyrsia can volunteer their resources to help establish the project’s first distributed network. From there, Project Pyrsia’s decentralized framework will help provide:

An independent, secure build network for open-source software
Trustworthiness of software packages
Completeness of known open-source software dependencies
For more information on Project Pyrsia or to sign-up to be a contributor visit https://pyrsia.io/. You can also learn more about the project in this blog or chat directly with JFrog Community leaders and Project Pyrsia experts during swampUP 2022 taking place in San Diego, May 25 – 26. For more information and to register visit https://swampup.jfrog.com/.

Supporting Quotes from Industry Partners

“The DeployHub team’s focus is firmly rooted in securing the supply chain, and there is no better place to start than fully auditing the build and package step. To that end, Pyrsia is the first open-source project to introduce improvements in this area via a ‘consensus build network.’ Disruption in this area is long overdue. DeployHub is proud to be part of this innovative team.” – Steve Taylor, CTO DeployHub, Inc.

“At Docker we feel this is an exciting time for the community to work together on innovation around the supply chain and its core, critical components for build and packaging. We are excited to join and work together with the community on Project Pyrsia. There is a huge opportunity to build new kinds of infrastructure over the core container primitives that will foster innovation and better developer experiences.” – Justin Cormack, CTO, Docker

“Open-source project Pyrsia is developing a third-party attested, decentralized, distributed software package network that delivers secure, transparency and integrity for the open-source software package supply chain. Futurewei is committed to collaborating with open-source communities to accelerate the innovations for digital transformation via open-source, open standard, and open ecosystems. As open-source software becomes more pervasive, securing the open-source software supply chain becomes a critical issue. We are thrilled to be a founding member of Project Pyrsia and delighted to have the opportunity to collaborate with other members to accelerate Pyrsia for a secure and trusted open-source software supply chain ecosystem – bringing value to the open-source community.” – David Lai, Director, Cloud Infrastructure and Platform Architecture Open-Source Ecosystem Partnerships, Futurewei Technologies, Inc.

Like this story? Tweet this: [email protected] unveils new blockchain-based security validation system for open-source software components decentralization monitoring, compliance violations, & response for #developers. Learn more https://bit.ly/3Gm1JJY

About JFrog
JFrog Ltd. (NASDAQ: FROG), is on a mission to power all the world’s software updates, driven by a “Liquid Software” vision to allow the seamless, secure flow of binaries from developers to the edge. The JFrog Platform enables software creators to power their entire software supply chain throughout the full binary lifecycle, so they can build, secure, distribute, and connect any source with any production environment. JFrog’s hybrid, universal, multi-cloud DevOps platform is available as both self-managed and SaaS services across major cloud service providers. Millions of users and thousands of customers worldwide, including a majority of the Fortune 100, depend on JFrog solutions to securely manage their mission-critical software supply chain. Once you leap forward, you won’t go back. Learn more at jfrog.com and follow us on Twitter: @jfrog.

———————

Blockchaining Digest:

  • KuCoin Ventures Invests in Joyride Games, Inc., a Web3 Publishing Platform for Game Creators, Which Will Be Supported By KuCoin’s $100 Million Creators Fund
  • Venture Capital Firms Target African Blockchain Projects
  • Primitives Raises $4 Million to Redefine NFTs Through New Social Network
  • NFT Technologies Goes Public on the NEO Exchange
  • Andreessen Horowitz raises $4.5 billion crypto fund
  • Highlights: Day One of BSV Global Blockchain Convention in Dubai
  • FTX Ventures Leads $5M Seed Round for NFT Trust Layer Doppel
  • FinTech Firm Intelly to Unveil Blockchain-Based Property Investment Platform in July
  • Fairmint Launches the First Solution Enabling Community Ownership Through Equity Tokenization
  • Flowcarbon Raises $70M to Tokenize Carbon Credits and Build an On-chain Market With a16z crypto as Lead Investor

Filed Under: Cybersecurity Market

Primary Sidebar

Market Analysis

How insurers thrive in a turbulent market
Leveraging Artificial Intelligence to Drive Cost Savings and Productivity in Uncertain Times
The shipping industry is undergoing a significant change with the influx of new vessels arriving just as the growth of trade is beginning to slow down
Climate change is increasingly affecting the production of beer ingredients
Unfulfilled Dreams: The Aftermath of China’s Stalled Real Estate Developments
Huawei on the Brink: Biden Administration Considers Cutting Off the Tech Giant”
Key Fire Industry Trends for 2023

Market Research Media

Streaming video, training, and gaming coming together to form a cohesive and diverse media and entertainment ecosystem
Turn Your Story into a Game: The Art of Gamifying Your Plot
The end of cheap money is redrawing the map of corporate earnings
The Future of Virtual Reality: How VR is Changing Industries
Market Research Media Survey: The State of Streaming Services
Media measurement services provide a holistic view of cross-media consumption
Gen Z ranks top in luxury sales

Secondary Sidebar

Technologies

The low tech unemployment rate and hiring activity confirms the long-term demand for tech talent
Virgin Orbit and SatRev Sign Launch Services Agreement
Harnessing the Power of Innovation for a Better Tomorrow
Breaking Down Silos: The Need for Cross-Sector Collaboration in Tackling Global Challenges
The SPIE Prism Awards recognized the best new optics and photonics products

Venture Capital

Gradient, a company specializing in eco-friendly heating and cooling solutions, has raised $18 million in a Series A funding round
The Importance of Diversity and Inclusion in the Workplace
Sequoia Capital announces its $195 Mln dedicated seed fund
Sublime Systems Secures $40 Million Series A to Electrify and Scale Decarbonized Cement Production
actyv.ai Raises Pre-Series A Funding to Fuel Global Expansion, Product Enhancement

Footer

Recent Posts

  • The Barcelona Cybersecurity Congress, 31 JANUARY – 2 FEBRUARY 2023, BARCELONA – GRAN VIA VENUE
  • Cybertech 2023 in Tel Aviv: Day 2, January 31, 2023
  • Protecting Your Privacy: A Look at the State of GDPR in the EU
  • Cybertech 2023 in Tel Aviv: Day 1, January 30, 2023
  • Identity has become the new attack surface
  • The Cybersecurity Risks of Automated Tutoring in Higher Education
  • The Cybersecurity Landscape in the Era of 5G: Challenges and Opportunities
  • The Hidden Dangers of Public USB Charging Ports: How to Protect Your Devices
  • How to encrypt and decrypt text messages with ChatGPT
  • The Impact of Artificial Intelligence on Cybersecurity

ESN

The 2023 Beyond Service User Conference, January 8-11, 2023, Orlando
Wolves Summit, October 19th-21st, 2021, Wrocław, Poland
Lead Generation World Conference 2022, January 16-18 2022, San Diego
Kscope22, June 19-23 2022, Gaylord, Grapevine, Texas
MWC Los Angeles is taking place Oct 26-28, 2021

Calendarial

Stefan Zweig was born on this day: November 28, 1881
National Pumpkin Day, October 26, 2022
SAPinsider EMEA 2022, 15 – 17 November, 2022, Vienna, Austria
World Patients Alliance Hosts First World Patients Conference, October 15 2022, Rome, Italy
Converge conference, November 14-17 2022, Fairmont Austin Hotel, Austin, Texas

Tech Events

Current 2022, the first-ever data streaming industry event, October 4-5, 2022, Austin, Texas
Photonics Industry Summit, September 21, 2022, Washington, DC
DattoCon22, September 11-13 2022, Walter E. Washington Convention Center, Washington, D.C.
IEEE International Conference on Quantum Computing and Engineering, 18-23 September 2022, Broomfield, Colorado
DesignCon, the premier event in high-speed communications and system design, August 16-18 2021, San Jose McEnery Convention Center

Event Calendar

2022 London Book Fair, April 5-7, 2022
Electric & Hybrid Vehicle Technology Expo, September 13-15, 2022, Suburban Collection Showcase, Novi, Michigan
BIASC To Host The 2022 Building Industry Show, September 14-15 2022, Anaheim, California
ADAS & Autonomous Vehicle Technology Expo, June 21-23, 2022, Stuttgart, Germany
InfoComm, June 8-10 2022, Las Vegas

Copyright © 2022 CybersecurityMarket.com

Technologies, Market Analysis & Market Research

We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept”, you consent to the use of ALL the cookies.
Do not sell my personal information.
Cookie SettingsAccept
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT