# Jfrog

Published articles for Jfrog.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Security baked into your software supply chain: The combined benefit of JFrog and Chainguard

DevFeed: [Security baked into your software supply chain: The combined benefit of JFrog and Chainguard](<https://devfeed.tech/articles/security-baked-into-your-software-supply-chain-the-combined-benefit-of-jfrog-and-chainguard-13248.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/the-combined-benefit-of-jfrog-and-chainguard>)

Published: 2026-01-23T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Jfrog](<https://devfeed.tech/topics/jfrog.md>), [Docker Hub](<https://devfeed.tech/topics/docker-hub.md>), [AI Models](<https://devfeed.tech/topics/ai-models.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-models](<https://devfeed.tech/tags/ai-models.md>), [base-images](<https://devfeed.tech/tags/base-images.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-jfrog](<https://devfeed.tech/tags/chainguard-jfrog.md>), [chainguard-jfrog-collaboration](<https://devfeed.tech/tags/chainguard-jfrog-collaboration.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container](<https://devfeed.tech/tags/container.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [devops](<https://devfeed.tech/tags/devops.md>), [docker-hub](<https://devfeed.tech/tags/docker-hub.md>), [jfrog](<https://devfeed.tech/tags/jfrog.md>), [jfrog-artifactory](<https://devfeed.tech/tags/jfrog-artifactory.md>), [jfrog-xray](<https://devfeed.tech/tags/jfrog-xray.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This article describes a Chainguard and JFrog collaboration for securing the software supply chain through secure-by-default container base images, policy-based curation, and continuous compliance. It presents Chainguard as providing clean, continuously updated images and JFrog Curation as screening upstream components and enforcing organizational policies.

### Source excerpt

Chainguard and JFrog secure the software supply chain with secure-by-default container images, policy-based curation, and continuous compliance.

## Hugging Face and JFrog partner to make AI Security more transparent

DevFeed: [Hugging Face and JFrog partner to make AI Security more transparent](<https://devfeed.tech/articles/hugging-face-and-jfrog-partner-to-make-ai-security-more-transparent-7297.md>)

Original publisher: [Read original article](<https://huggingface.co/blog/jfrog>)

Author: Luc Georges; Shachar M

Published: 2025-03-04T00:00:00Z

Content type: news

Language: en

Sources: [Hugging Face - Blog](<https://devfeed.tech/sources/hugging-face-blog.md>)

Topics: [Jfrog](<https://devfeed.tech/topics/jfrog.md>), [Securing AI](<https://devfeed.tech/topics/securing-ai.md>), [hugging face](<https://devfeed.tech/topics/hugging-face.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [Security](<https://devfeed.tech/topics/security.md>), [Machine Learning, Security Attacks](<https://devfeed.tech/topics/machine-learning-security-attacks.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Keras](<https://devfeed.tech/topics/keras.md>)

Tags: [ai-security](<https://devfeed.tech/tags/ai-security.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [hub](<https://devfeed.tech/tags/hub.md>), [hugging-face](<https://devfeed.tech/tags/hugging-face.md>), [jfrog](<https://devfeed.tech/tags/jfrog.md>), [keras](<https://devfeed.tech/tags/keras.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [partnerships](<https://devfeed.tech/tags/partnerships.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

Hugging Face and JFrog are partnering to improve security on the Hugging Face Hub. JFrog's scanner analyzes code embedded in model weights and supports detection of malicious usage across formats, including pickle and Keras Lambda layers, while public model repositories are scanned automatically.

### Source excerpt

We're on a journey to advance and democratize artificial intelligence through open source and open science.

## Build a golden image program with Chainguard Images and JFrog Artifactory and Xray

DevFeed: [Build a golden image program with Chainguard Images and JFrog Artifactory and Xray](<https://devfeed.tech/articles/build-a-golden-image-program-with-chainguard-images-and-jfrog-artifactory-and-xray-12899.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/build-a-golden-image-program-with-chainguard-images-and-jfrog-artifactory-and-xray>)

Published: 2024-07-09T00:00:00Z

Content type: tutorial

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [container-security](<https://devfeed.tech/topics/container-security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Platform Engineering](<https://devfeed.tech/topics/platform-engineering.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [DevOps](<https://devfeed.tech/topics/devops.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [announce](<https://devfeed.tech/tags/announce.md>), [build](<https://devfeed.tech/tags/build.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container](<https://devfeed.tech/tags/container.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [cves](<https://devfeed.tech/tags/cves.md>), [developers](<https://devfeed.tech/tags/developers.md>), [development](<https://devfeed.tech/tags/development.md>), [devops](<https://devfeed.tech/tags/devops.md>), [golden-image](<https://devfeed.tech/tags/golden-image.md>), [hardened-images](<https://devfeed.tech/tags/hardened-images.md>), [integration](<https://devfeed.tech/tags/integration.md>), [jfrog](<https://devfeed.tech/tags/jfrog.md>), [jfrog-artifactory](<https://devfeed.tech/tags/jfrog-artifactory.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [platform-engineering](<https://devfeed.tech/tags/platform-engineering.md>), [safe-source-for-open-source](<https://devfeed.tech/tags/safe-source-for-open-source.md>), [xray](<https://devfeed.tech/tags/xray.md>)

### AI overview

The article explains how to build a secure golden image program by combining Chainguard Images with JFrog Artifactory and Xray. It describes using hardened container images, centralized artifact management, continuous vulnerability scanning, and a curated open source catalog to support platform and DevOps teams.

### Source excerpt

Learn how to create a secure and streamlined golden image program with Chainguard Images, JFrog Artifactory, and Xray.

## Impact of final JCenter shutdown on Gradle Plugin Portal

DevFeed: [Impact of final JCenter shutdown on Gradle Plugin Portal](<https://devfeed.tech/articles/impact-of-final-jcenter-shutdown-on-gradle-plugin-portal-24682.md>)

Original publisher: [Read original article](<https://blog.gradle.org/portal-jcenter-impact>)

Author: Louis Jacomet

Published: 2024-07-05T04:00:00Z

Content type: article

Language: en

Sources: [The Gradle Blog](<https://devfeed.tech/sources/the-gradle-blog.md>)

Topics: [Gradle](<https://devfeed.tech/topics/gradle.md>), [Maven](<https://devfeed.tech/topics/maven.md>), [Package manager](<https://devfeed.tech/topics/package-manager.md>), [configuration](<https://devfeed.tech/topics/configuration.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [blog-post](<https://devfeed.tech/tags/blog-post.md>), [build](<https://devfeed.tech/tags/build.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [gradle](<https://devfeed.tech/tags/gradle.md>), [jfrog](<https://devfeed.tech/tags/jfrog.md>), [maven-central](<https://devfeed.tech/tags/maven-central.md>), [proxy](<https://devfeed.tech/tags/proxy.md>)

### AI overview

The article analyzes the impact of JCenter becoming a permanent redirect to Maven Central on the Gradle Plugin Portal and Gradle builds. It explains the portal's move from acting as a JCenter proxy to a Maven Central proxy and identifies plugin and transitive-dependency resolution failures that users may encounter.

### Source excerpt

ℹ Update on July 15, 2024 We have found errors causing false positive in failed plugin resolution. 4 plugins have been removed from the list, resulting in 9 removed dependencies. We also added 105 plugins that depend on one or more affected plugins. These will fail to resolve transitively. Not taking exclude into account caused the first change, the second one came from not taking plugin dependencies into account. Now that JFrog has confirmed that JCenter will become a permanent redirect to Maven Central, we felt that it was important for the Gradle Plugin Portal users to understand the impact of that decision on the portal and their builds. This post follows our report after JCenter redirected to Maven Central for a day. Users still directly using JCenter should also refer to our original blog post about the changes in JCenter and their impact on Gradle builds in general. Upcoming Plugin Portal changes JCenter will become a permanent redirect to Maven Central. As a consequence, the Gradle Plugin Portal will no longer act as a JCenter proxy and will instead become a Maven Central proxy. The Gradle Plugin Portal will continue to return redirects (303 See Other) for artifact queries it cannot serve. Starting July 15, 2024, these redirects will be towards Maven Central instead of JCenter. This change might impact existing Gradle builds: Build using plugins with dependencies that are exclusively available on JCenter will fail to resolve. Builds configured to use the Gradle Plugin Portal as a regular artifact repository (which is not recommended) may be impacted. For more information, refer to our original blog post. We aim to document the potential impact on Gradle plugins provided by the Plugin Portal. Read our analysis below to learn how to minimize the impact on your builds. Impact analysis We have performed two major analyses: For all the plugins known to the Gradle Plugin Portal, determine which ones would fail to resolve if their transitive dependencies are resol

## Plugin Portal Outage Followup

DevFeed: [Plugin Portal Outage Followup](<https://devfeed.tech/articles/plugin-portal-outage-followup-24677.md>)

Original publisher: [Read original article](<https://blog.gradle.org/plugin-portal-outage-followup>)

Author: Sterling Greene

Published: 2023-06-28T04:00:00Z

Content type: article

Language: en

Sources: [The Gradle Blog](<https://devfeed.tech/sources/the-gradle-blog.md>)

Topics: [Gradle](<https://devfeed.tech/topics/gradle.md>), [Maven](<https://devfeed.tech/topics/maven.md>), [Library](<https://devfeed.tech/topics/library.md>)

Tags: [bintray](<https://devfeed.tech/tags/bintray.md>), [blog-post](<https://devfeed.tech/tags/blog-post.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [gradle](<https://devfeed.tech/tags/gradle.md>), [gradle-plugin](<https://devfeed.tech/tags/gradle-plugin.md>), [jfrog](<https://devfeed.tech/tags/jfrog.md>), [libraries](<https://devfeed.tech/tags/libraries.md>), [maven-central](<https://devfeed.tech/tags/maven-central.md>), [outage](<https://devfeed.tech/tags/outage.md>), [plugin](<https://devfeed.tech/tags/plugin.md>)

### AI overview

This follow-up explains how an unannounced JCenter change on June 23, 2023 caused Gradle users to experience failures resolving artifacts through the Gradle Plugin Portal. It describes the impact on plugin builds, missing artifacts and transitive dependencies, recovery options, and plans to reduce reliance on JCenter.

### Source excerpt

ℹ Update on July 15, 2024 See our recent blog post for up-to-date information about the Plugin Portal and JCenter. On June 23rd, 2023, at 9:00 UTC, Gradle users started experiencing issues resolving artifacts from the Gradle Plugin Portal because of changes to artifacts hosted on JCenter by JFrog. JCenter stopped serving files directly and redirected all requests to Maven Central. This was an unannounced change. We contacted JFrog, and they replied it was a test and they would revert back to having JCenter serve artifacts. Around 18:30 UTC, JCenter returned to normal behavior. This post describes the effect this outage had on builds, ways to recover from similar outages, and what we will do to eliminate the dependency on JCenter in the future. Users still directly using JCenter should also refer to our original blog post about the shutdown of JCenter on Gradle builds in general. Effects on Gradle plugins usage in builds When JFrog stopped serving artifacts from JCenter, all requests were redirected to Maven Central. This can impact builds in different ways. In this blog post, we focus on the resolution of Gradle plugins from the Plugin Portal. Background information The Plugin Portal only hosts artifacts related to Gradle plugins. The Plugin Portal redirects Gradle builds to JCenter to resolve transitive dependencies required by plugins. Some of these transitive dependencies are hosted by JCenter and some are mirrored from Maven Central. Additionally, some very old versions of Gradle plugins are also hosted on JCenter. This is because they were historically hosted on JFrog's Bintray service. Following Bintray's shutdown in May 2021, we removed the Plugin Portal's integration with Bintray, but we kept redirecting to JCenter for those artifacts because JFrog committed to keeping JCenter read-only indefinitely. When changes are made to JCenter, the Plugin Portal may no longer serve some artifacts or serve different artifacts. Missing artifacts Any artifacts only avail

## JCenter Shutdown Impact on Gradle Builds

DevFeed: [JCenter Shutdown Impact on Gradle Builds](<https://devfeed.tech/articles/jcenter-shutdown-impact-on-gradle-builds-24662.md>)

Original publisher: [Read original article](<https://blog.gradle.org/jcenter-shutdown>)

Author: Sterling Greene

Published: 2021-02-22T05:00:00Z

Content type: article

Language: en

Sources: [The Gradle Blog](<https://devfeed.tech/sources/the-gradle-blog.md>)

Topics: [Gradle](<https://devfeed.tech/topics/gradle.md>), [Maven](<https://devfeed.tech/topics/maven.md>), [Security](<https://devfeed.tech/topics/security.md>), [Git](<https://devfeed.tech/topics/git.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [bintray](<https://devfeed.tech/tags/bintray.md>), [build](<https://devfeed.tech/tags/build.md>), [central](<https://devfeed.tech/tags/central.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [documentation](<https://devfeed.tech/tags/documentation.md>), [github](<https://devfeed.tech/tags/github.md>), [gradle](<https://devfeed.tech/tags/gradle.md>), [jfrog](<https://devfeed.tech/tags/jfrog.md>), [maven-central](<https://devfeed.tech/tags/maven-central.md>), [mirror](<https://devfeed.tech/tags/mirror.md>), [packages](<https://devfeed.tech/tags/packages.md>), [pipelines](<https://devfeed.tech/tags/pipelines.md>), [release](<https://devfeed.tech/tags/release.md>), [update](<https://devfeed.tech/tags/update.md>)

### AI overview

This article explains how the shutdown of Bintray and JCenter could disrupt Gradle builds by affecting dependency resolution, plugin dependencies, and package publishing. It describes JCenter's relationship to Maven Central, notes that JCenter became read-only indefinitely, and recommends moving builds and publishing workflows to other repositories, with Maven Central becoming Gradle's default in new samples and init templates.

### Source excerpt

ℹ Update on July 15, 2024 See our recent blog post for up-to-date information about the Plugin Portal and JCenter. On February 3 2021, JFrog announced that they will be shutting down Bintray and JCenter. This post tells you what you need to know and do to avoid disruptions to your build pipelines. Your build may be affected by this shutdown in several ways: Gradle may not be able to download the dependencies used to compile, test or run your code. Gradle may not be able to download the dependencies used by plugins to configure your build. Gradle may no longer be able to publish your package to Bintray. Additionally, you should be aware of the security considerations when moving from one repository to another. UPDATE: JFrog has decided to keep JCenter as a read-only repository indefinitely. New package and versions are no longer accepted on JCenter. All Bintray services have been shutdown. Background JCenter is a central artifact repository, like Maven Central. Software projects use JCenter to distribute their software to other people. JCenter also serves as a mirror for Maven Central, so any dependencies available on Maven Central are also available on JCenter (but not vice versa). Bintray is a management layer that software projects use to publish and promote packages to JCenter. Bintray also allowed users to create public user-specific repositories that were isolated from JCenter. Both of these services are affected by the shutdown. Impact to builds By default, Gradle does not add an artifact repository to your project; however, Gradle does provide a convenient API for using the JCenter repository. The Gradle Build Init plugin produces build templates that use the JCenter repository to resolve dependencies. In many code examples and documentation, JCenter is used as an example repository. It's very likely that you have builds that rely on JCenter. We've found over a million Git repositories on GitHub that use JCenter with Gradle. To discourage new projects from u

## Migrating old artifacts from JCenter to MavenCentral

DevFeed: [Migrating old artifacts from JCenter to MavenCentral](<https://devfeed.tech/articles/migrating-old-artifacts-from-jcenter-to-mavencentral-25563.md>)

Original publisher: [Read original article](<https://www.marcogomiero.com/posts/2021/move-libray-jcenter-to-maven/>)

Author: Marco Gomiero

Published: 2021-02-11T00:00:00Z

Content type: tutorial

Language: en

Sources: [Posts on Marco Gomiero](<https://devfeed.tech/sources/posts-on-marco-gomiero.md>)

Topics: [Library](<https://devfeed.tech/topics/library.md>), [Jfrog](<https://devfeed.tech/topics/jfrog.md>), [Android Studio](<https://devfeed.tech/topics/android-studio.md>), [Android Gradle Plugin](<https://devfeed.tech/topics/android-gradle-plugin.md>), [Gradle](<https://devfeed.tech/topics/gradle.md>)

Tags: [android-gradle-plugin](<https://devfeed.tech/tags/android-gradle-plugin.md>), [android-studio](<https://devfeed.tech/tags/android-studio.md>), [article](<https://devfeed.tech/tags/article.md>), [download](<https://devfeed.tech/tags/download.md>), [files](<https://devfeed.tech/tags/files.md>), [gradle](<https://devfeed.tech/tags/gradle.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [jfrog](<https://devfeed.tech/tags/jfrog.md>), [libraries](<https://devfeed.tech/tags/libraries.md>), [signing](<https://devfeed.tech/tags/signing.md>), [sonatype](<https://devfeed.tech/tags/sonatype.md>)

### AI overview

This tutorial explains how to manually migrate existing Android library artifacts from JCenter to Maven Central after JCenter's shutdown. It covers downloading artifacts from Bintray, signing the AAR, POM, JAR, and signature files, and uploading them through Sonatype without recompiling the library.

### Source excerpt

As you may have heard, JCenter is shutting down in May 2021. Into the Sunset on May 1st: Bintray, JCenter, GoCenter, and ChartCenter https://jfrog.com/blog/into-the-sunset-bintray-jcenter-gocenter-and-chartcenter/ So, if you are using JCenter as the repository for your libraries (as me), it's time to migrate. In this article, I will not go through the publishing process of a library to MavenCentral, because there are already plenty of resources available. For example, I followed the one written by Márton Braun.

## Migrating away from JCenter

DevFeed: [Migrating away from JCenter](<https://devfeed.tech/articles/migrating-away-from-jcenter-28695.md>)

Original publisher: [Read original article](<https://jeroenmols.com/blog/2021/02/04/migratingjcenter/>)

Author: info@jeroenmols.com (Jeroen Mols)

Published: 2021-02-04T00:00:00Z

Content type: tutorial

Language: en

Sources: [Jeroen Mols](<https://devfeed.tech/sources/jeroen-mols.md>)

Topics: [Gradle](<https://devfeed.tech/topics/gradle.md>), [Maven](<https://devfeed.tech/topics/maven.md>), [Maven Central](<https://devfeed.tech/topics/maven-central.md>), [Jfrog](<https://devfeed.tech/topics/jfrog.md>)

Tags: [android](<https://devfeed.tech/tags/android.md>), [bintray](<https://devfeed.tech/tags/bintray.md>), [blogs](<https://devfeed.tech/tags/blogs.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [gradle](<https://devfeed.tech/tags/gradle.md>), [guide](<https://devfeed.tech/tags/guide.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [jcenter](<https://devfeed.tech/tags/jcenter.md>), [jfrog](<https://devfeed.tech/tags/jfrog.md>), [library](<https://devfeed.tech/tags/library.md>), [maven](<https://devfeed.tech/tags/maven.md>), [maven-central](<https://devfeed.tech/tags/maven-central.md>), [migrate](<https://devfeed.tech/tags/migrate.md>), [repository](<https://devfeed.tech/tags/repository.md>), [transitive-dependencies](<https://devfeed.tech/tags/transitive-dependencies.md>)

### AI overview

A practical guide to migrating Gradle dependencies and published artifacts away from Bintray/JCenter after JFrog announced the repository shutdown. It explains replacing JCenter with Maven Central, testing clean builds, and restricting remaining dependencies to explicit repository declarations.

### Source excerpt

This week JFrog - out of nowhere - announced to completely remove their Maven repository. Since they'll pull it offline already by May 2021 (!!!) it's time to urgently migrate away.

## Decommissioning HTTP for Gradle Services

DevFeed: [Decommissioning HTTP for Gradle Services](<https://devfeed.tech/articles/decommissioning-http-for-gradle-services-24609.md>)

Original publisher: [Read original article](<https://blog.gradle.org/decommissioning-http>)

Author: Jonathan Leitschuh

Published: 2019-10-17T04:00:00Z

Content type: article

Language: en

Sources: [The Gradle Blog](<https://devfeed.tech/sources/the-gradle-blog.md>)

Topics: [Gradle](<https://devfeed.tech/topics/gradle.md>), [HTTP](<https://devfeed.tech/topics/http.md>), [API](<https://devfeed.tech/topics/api.md>), [IntelliJ IDEA](<https://devfeed.tech/topics/intellij-idea.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [gradle](<https://devfeed.tech/tags/gradle.md>), [http](<https://devfeed.tech/tags/http.md>), [java](<https://devfeed.tech/tags/java.md>), [jfrog](<https://devfeed.tech/tags/jfrog.md>)

### AI overview

Gradle announced that its services would stop accepting HTTP requests starting in January 2020. Users and organizations mirroring Gradle services, distributions, or repositories needed to update their configurations to use HTTPS. Gradle 6.0 also deprecated HTTP resource and artifact downloads in build scripts unless explicitly enabled.

### Source excerpt

Starting in January 2020, Gradle services will only serve requests made with HTTPS. From that point on, all requests made with HTTP will be denied and any builds and artifact mirrors that use a Gradle URL with the non-secure HTTP protocol will fail. If you are proxying our services through your own artifact servers like Artifactory or Nexus, you will need to ensure that you update your mirror configurations so they are using HTTPS instead of HTTP. Gradle Services This change will impact the following services. Plugin Portal By default, the Gradle build tool uses HTTPS when resolving plugins from the Plugin Portal. You should be unaffected if you do not declare a custom plugin repository. If your organization mirrors the Plugin Portal from URL plugins.gradle.org/m2/*, you should check that your mirror is using HTTPS. Gradle Distributions Since Gradle 1.2, the Gradle wrapper has used HTTPS to download Gradle distributions. You should be unaffected if your gradle-wrapper.properties uses a HTTPS URL. Gradle distributions are served from the following URLs: services.gradle.org downloads.gradle.org downloads.gradle-dn.com If your organization mirrors Gradle distributions from any of these URLs, you should check that your mirror is using HTTPS. Other Gradle software Other Gradle, Inc. produced software is published to an Artifactory repository, such as the Gradle Tooling API. Most builds do not use this repository unless they are building tooling that integrates with Gradle (like IntelliJ IDEA). The Gradle Artifactory repository is available at repo.gradle.org. Gradle Build Tool Gradle 6.0 deprecates the use of HTTP in build scripts to download resources and artifacts without an an explict opt-in. For users that require the use of HTTP, Gradle has several new APIs to continue to allow HTTP on a case-by-case basis. Timeline To ease the transition for our users, this change is coming in a few phases. When What's changing? October 29th, 2019 Gradle will begin redirecting from

## How to publish and distribute your Android library

DevFeed: [How to publish and distribute your Android library](<https://devfeed.tech/articles/how-to-publish-and-distribute-your-android-library-25542.md>)

Original publisher: [Read original article](<https://www.marcogomiero.com/posts/2019/publish-librery-android/>)

Author: Marco Gomiero

Published: 2019-05-28T00:00:00Z

Content type: tutorial

Language: en

Sources: [Posts on Marco Gomiero](<https://devfeed.tech/sources/posts-on-marco-gomiero.md>)

Topics: [Android Library](<https://devfeed.tech/topics/android-library.md>), [Gradle](<https://devfeed.tech/topics/gradle.md>), [Android Studio](<https://devfeed.tech/topics/android-studio.md>), [Maven](<https://devfeed.tech/topics/maven.md>)

Tags: [android](<https://devfeed.tech/tags/android.md>), [android-studio](<https://devfeed.tech/tags/android-studio.md>), [build](<https://devfeed.tech/tags/build.md>), [deprecated](<https://devfeed.tech/tags/deprecated.md>), [gradle](<https://devfeed.tech/tags/gradle.md>), [guide](<https://devfeed.tech/tags/guide.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [jfrog](<https://devfeed.tech/tags/jfrog.md>), [tutorial](<https://devfeed.tech/tags/tutorial.md>), [update](<https://devfeed.tech/tags/update.md>)

### AI overview

This tutorial explains how to publish and distribute an Android library using Android Studio, Gradle, Bintray, and JCenter. A February 2021 update warns that JCenter is shutting down and says the original publishing process is no longer recommended; it points readers toward MavenCentral guidance instead.

### Source excerpt

Update - February 2021 As you may have heard, JCenter is shutting down in May 2021. Into the Sunset on May 1st: Bintray, JCenter, GoCenter, and ChartCenter https://jfrog.com/blog/into-the-sunset-bintray-jcenter-gocenter-and-chartcenter/ So, this tutorial is no longer recommended because it explains how to publish an Android library to JCenter. I suggested you follow this guide written by Márton Braun. Publishing Android libraries to MavenCentral in 2021 https://getstream.io/blog/publishing-libraries-to-mavencentral-2021/ If you have already published a library on JCenter and you want to migrate the old artifacts to MavenCentral, you can follow the guide that I've written: