# Jfrog

JFrog is a company providing a software supply chain platform for DevOps, security, artifact management, and software release governance.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Security baked into your software supply chain: The combined benefit of JFrog and Chainguard

DevFeed: [Security baked into your software supply chain: The combined benefit of JFrog and Chainguard](<https://devfeed.tech/articles/security-baked-into-your-software-supply-chain-the-combined-benefit-of-jfrog-and-chainguard-13248.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/the-combined-benefit-of-jfrog-and-chainguard>)

Published: 2026-01-23T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Jfrog](<https://devfeed.tech/topics/jfrog.md>), [Docker Hub](<https://devfeed.tech/topics/docker-hub.md>), [AI Models](<https://devfeed.tech/topics/ai-models.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-models](<https://devfeed.tech/tags/ai-models.md>), [base-images](<https://devfeed.tech/tags/base-images.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-jfrog](<https://devfeed.tech/tags/chainguard-jfrog.md>), [chainguard-jfrog-collaboration](<https://devfeed.tech/tags/chainguard-jfrog-collaboration.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container](<https://devfeed.tech/tags/container.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [devops](<https://devfeed.tech/tags/devops.md>), [docker-hub](<https://devfeed.tech/tags/docker-hub.md>), [jfrog](<https://devfeed.tech/tags/jfrog.md>), [jfrog-artifactory](<https://devfeed.tech/tags/jfrog-artifactory.md>), [jfrog-xray](<https://devfeed.tech/tags/jfrog-xray.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This article describes a Chainguard and JFrog collaboration for securing the software supply chain through secure-by-default container base images, policy-based curation, and continuous compliance. It presents Chainguard as providing clean, continuously updated images and JFrog Curation as screening upstream components and enforcing organizational policies.

### Source excerpt

Chainguard and JFrog secure the software supply chain with secure-by-default container images, policy-based curation, and continuous compliance.

## Hugging Face and JFrog partner to make AI Security more transparent

DevFeed: [Hugging Face and JFrog partner to make AI Security more transparent](<https://devfeed.tech/articles/hugging-face-and-jfrog-partner-to-make-ai-security-more-transparent-7297.md>)

Original publisher: [Read original article](<https://huggingface.co/blog/jfrog>)

Author: Luc Georges; Shachar M

Published: 2025-03-04T00:00:00Z

Content type: news

Language: en

Sources: [Hugging Face - Blog](<https://devfeed.tech/sources/hugging-face-blog.md>)

Topics: [Jfrog](<https://devfeed.tech/topics/jfrog.md>), [Securing AI](<https://devfeed.tech/topics/securing-ai.md>), [hugging face](<https://devfeed.tech/topics/hugging-face.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [Security](<https://devfeed.tech/topics/security.md>), [Machine Learning, Security Attacks](<https://devfeed.tech/topics/machine-learning-security-attacks.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Keras](<https://devfeed.tech/topics/keras.md>)

Tags: [ai-security](<https://devfeed.tech/tags/ai-security.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [hub](<https://devfeed.tech/tags/hub.md>), [hugging-face](<https://devfeed.tech/tags/hugging-face.md>), [jfrog](<https://devfeed.tech/tags/jfrog.md>), [keras](<https://devfeed.tech/tags/keras.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [partnerships](<https://devfeed.tech/tags/partnerships.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

Hugging Face and JFrog are partnering to improve security on the Hugging Face Hub. JFrog's scanner analyzes code embedded in model weights and supports detection of malicious usage across formats, including pickle and Keras Lambda layers, while public model repositories are scanned automatically.

### Source excerpt

We're on a journey to advance and democratize artificial intelligence through open source and open science.

## Migrating old artifacts from JCenter to MavenCentral

DevFeed: [Migrating old artifacts from JCenter to MavenCentral](<https://devfeed.tech/articles/migrating-old-artifacts-from-jcenter-to-mavencentral-25563.md>)

Original publisher: [Read original article](<https://www.marcogomiero.com/posts/2021/move-libray-jcenter-to-maven/>)

Author: Marco Gomiero

Published: 2021-02-11T00:00:00Z

Content type: tutorial

Language: en

Sources: [Posts on Marco Gomiero](<https://devfeed.tech/sources/posts-on-marco-gomiero.md>)

Topics: [Library](<https://devfeed.tech/topics/library.md>), [Jfrog](<https://devfeed.tech/topics/jfrog.md>), [Android Studio](<https://devfeed.tech/topics/android-studio.md>), [Android Gradle Plugin](<https://devfeed.tech/topics/android-gradle-plugin.md>), [Gradle](<https://devfeed.tech/topics/gradle.md>)

Tags: [android-gradle-plugin](<https://devfeed.tech/tags/android-gradle-plugin.md>), [android-studio](<https://devfeed.tech/tags/android-studio.md>), [article](<https://devfeed.tech/tags/article.md>), [download](<https://devfeed.tech/tags/download.md>), [files](<https://devfeed.tech/tags/files.md>), [gradle](<https://devfeed.tech/tags/gradle.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [jfrog](<https://devfeed.tech/tags/jfrog.md>), [libraries](<https://devfeed.tech/tags/libraries.md>), [signing](<https://devfeed.tech/tags/signing.md>), [sonatype](<https://devfeed.tech/tags/sonatype.md>)

### AI overview

This tutorial explains how to manually migrate existing Android library artifacts from JCenter to Maven Central after JCenter's shutdown. It covers downloading artifacts from Bintray, signing the AAR, POM, JAR, and signature files, and uploading them through Sonatype without recompiling the library.

### Source excerpt

As you may have heard, JCenter is shutting down in May 2021. Into the Sunset on May 1st: Bintray, JCenter, GoCenter, and ChartCenter https://jfrog.com/blog/into-the-sunset-bintray-jcenter-gocenter-and-chartcenter/ So, if you are using JCenter as the repository for your libraries (as me), it's time to migrate. In this article, I will not go through the publishing process of a library to MavenCentral, because there are already plenty of resources available. For example, I followed the one written by Márton Braun.

## Migrating away from JCenter

DevFeed: [Migrating away from JCenter](<https://devfeed.tech/articles/migrating-away-from-jcenter-28695.md>)

Original publisher: [Read original article](<https://jeroenmols.com/blog/2021/02/04/migratingjcenter/>)

Author: info@jeroenmols.com (Jeroen Mols)

Published: 2021-02-04T00:00:00Z

Content type: tutorial

Language: en

Sources: [Jeroen Mols](<https://devfeed.tech/sources/jeroen-mols.md>)

Topics: [Gradle](<https://devfeed.tech/topics/gradle.md>), [Maven](<https://devfeed.tech/topics/maven.md>), [Maven Central](<https://devfeed.tech/topics/maven-central.md>), [Jfrog](<https://devfeed.tech/topics/jfrog.md>)

Tags: [android](<https://devfeed.tech/tags/android.md>), [bintray](<https://devfeed.tech/tags/bintray.md>), [blogs](<https://devfeed.tech/tags/blogs.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [gradle](<https://devfeed.tech/tags/gradle.md>), [guide](<https://devfeed.tech/tags/guide.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [jcenter](<https://devfeed.tech/tags/jcenter.md>), [jfrog](<https://devfeed.tech/tags/jfrog.md>), [library](<https://devfeed.tech/tags/library.md>), [maven](<https://devfeed.tech/tags/maven.md>), [maven-central](<https://devfeed.tech/tags/maven-central.md>), [migrate](<https://devfeed.tech/tags/migrate.md>), [repository](<https://devfeed.tech/tags/repository.md>), [transitive-dependencies](<https://devfeed.tech/tags/transitive-dependencies.md>)

### AI overview

A practical guide to migrating Gradle dependencies and published artifacts away from Bintray/JCenter after JFrog announced the repository shutdown. It explains replacing JCenter with Maven Central, testing clean builds, and restricting remaining dependencies to explicit repository declarations.

### Source excerpt

This week JFrog - out of nowhere - announced to completely remove their Maven repository. Since they'll pull it offline already by May 2021 (!!!) it's time to urgently migrate away.