GitHub Integration with Yonatan Arbel at JFrog swampUP 2024
Yonatan Arbel discusses JFrog’s latest developments, including a partnership with GitHub, new runtime security offerings, and the integration of JFrog’s capabilities into GitHub’s platform to enhance developer workflows and security. Jonathan emphasizes the benefits of these integrations, highlighting how JFrog’s tools are designed to improve efficiency without disrupting a developer’s flow. They also touch on AI advancements in the field and the growing collaboration between JFrog and GitHub.
Transcript
This is Techstrong tv. com. We're back here at Swamp Up in Austin, 2024.
This happens to be, in case you don't know, the 10th Annual Swamp Up event for many years. It was in Napa Valley, which I, I'll be honest with you, I loved it in Napa. Yeah, no.
Uh, but this is, uh, the Barton Creek Omni Resort. It's a beautiful, it's amazing resort here, kind of in the hills a little bit right outta downtown here In Texas, you know? Yeah.
Everything's Bigger in Texas. That's what they say. It's, It's amazing.
It is. Um, but maybe Napper again next year in Napa. Yeah.
They say it's Seder. But anyway, let me introduce you to Jonathan ar Arbell. Yeah, Arbell.
Yeah. Yeah. I got it.
I got it. You Guys right? You got it right.
It's sounds Good. So, and for those of you not familiar, sort of with Hebrew names, Jonathan is like Jonathan. Yes.
It's Jonathan and he's, It's the version for Jonathan, right? So, and Jan Yani is, is, uh, many people are called. But yeah, you graduated.
First of all, welcome to Text on tv. Thank you For having me. Second of all, if you wouldn't mind, let the audience know what kind you're with Jfr, but what's your role with Jfr?
Well, I've been here with Jfr for the last eight years. I started as a developer, as a junior developer, and evolved myself with the time. Uh, after afterwards, I became a team leader at the infrastructure group.
And few years later, you have report say, Hey, you know how to speak Jfr. Why won't you come and, and be a Dere at Jfr? I said, you know what I mean?
It looks cool. And I love people and I love to speak with people. Yeah.
Why not? Technology and people. It's always a great, great combination, you know?
So, uh, so now you're dere. So now I became a Dere. I'm, uh, this position for the last one year, you know, having fun and you Like it.
I like it really much. Yeah. It's, it's Jfr is, has a long history of great Dev re people, right?
Yeah, yeah, yeah. Uh, Steven Chin and Baruch and, uh, Lori LaRusso. Yeah.
Yeah. It's a big shoes to come in here, the big Shoes. But it's a, it's a great role too, and especially for this company.
'cause the Jfr culture, and I tell Shlomi this all the time, they have a very unique culture that I've not seen anywhere. Absolutely. So this is, this really, it's a good thing.
Yeah, I can totally relate to that. So Big for me, there were three big stories today at Swamp Up. com if anyone's interested.
Go check it out. Uh, another was the runtime security, uh, offering, which is, you know, now part of the platform. You now have runtime, security, big story.
com, ed Security Boulevard. And then the third was the partnership with GitHub. Yes.
Uh, and it's, as we were talking a little offline, it's not, uh, a single layer. It, it's, it's layers and layers deep. Jonathan, tell us a little bit about it.
Well, so the partner, the partnership with GitHub is, as you said, it's a layer by layer. It's, it's the understanding that, you know, it's not the source code and the binary aside. And as you have said, there is chasm in between.
So we understand that we need to bring all together to give you a better, um, um, clarity of what's going on with your binaries already on the source side. So that's why we came with this integration and with, uh, several capabilities to make it, uh, very easy for developers to adapt it immediately and getting all the advantage of, uh, jfr products such as the security Artifactory, of course. And by that, get an information like if you, if you one of your binaries is vulnerable, or, uh, what are the published models that happen during your, uh, workflow and action job.
So you now get all this information in the GitHub platform because we understand, you know, it's not an ego thing. We understand that people, uh, stays a lot where they manage their source code. And that's why we understand that we want to get them all this information at the very early stage.
That's why we started with this, uh, uh, collaboration with Git. Absolutely. I I think yo said it best when he said, we don't want any silos.
There should not be silos, and there should certainly shouldn't be silos between artifacts and, and, and code. Right. I, I totally agree.
And I will add to this, that at, at first, our summary page at GitHub was the published models and then the security. And you have, you came and say, Hey, it's, it's, it's come together. Binaries and security.
Let's get it together. I mean, in terms of user experience, we want it to have side by side, the binaries and the security. So we now have a full and a full clarity of the, of the binaries with the security scan results.
You get all this in the GitHub page, in the summary page of the workflow of the specific job that you ran. And, and that's an important thing too. And you mentioned it, right?
And again, it goes back to something Shlomi said in the keynotes, right? Yeah. We don't want 20 vendors and we don't want 20 workflows, and we don't want 20 gooeys and 20 different places.
If I'm a developer and I, I choose to work in GitHub in their IDE and you know, in where and their page, I want my tools to work in that environment, not I work here, then I gotta take it there and see how it goes here. Exactly. I want it in there.
And so I think that's an important aspect of this, is that Jfr now works directly within the interface you are working in. Yeah. And, and the thing is that as a developer, I mean, some, some stuff that very, you know, painful for developers is that to lose their context, to lose their flow.
And then you, you can't remember where was the last job that you visited. Hey, this build is related to which job, which job created this build? So we came with this bidirectional, uh, linkage.
So now you can go from GitHub directly to the specific location on JO to the build info. And from the platform, we can get you back to the specific job that created this build info. And from there, of course, you can go even more to the left side and check what the exact code that trigger this build.
So it, it's all comes, connect everything together so you don't lose your context. And you, it keeps you in the flow. I always like to say it that way.
It keeps you in the flow flow and, and you always know what you are investigating and checking. I think another important piece here was, or is that the, um, everything's AI today, right? And of course, GitHub has copilot, which is probably one of the first ones that was out there for developers anyway.
Yeah. And it's great and it gets better every day, right? It's getting all these ai Yeah.
But now we have, and, and you know, it's an extension of GitHub and now we have the j uh, the Jfr extension for GitHub. So it works, you know, when Jfr has their ML ops and they're doing their generator of AI thing. So we, we envision a day when this is all right.
And like Shlomi said, it's is it gonna make developers extinct or l less developers? Well, only those who don't adapt and evolve. Yes.
But I think most developers do adapt and evolve Absolutely. And that they will incorporate these AI tools 'cause it makes them more effective. I, I totally agree with that.
And, you know, after the, the keynote that we did, some approached to me and said, Hey, you know, what I really liked about this, uh, extension is that now whether it's a junior developer in my organization, or maybe some security person or the CISO can ask any human language what's going on with my binaries and get the immediate and full picture of what's going on, he can ask, uh, if it's vulnerable, if he has some vulnerabilities in some specific packages. And, you know, behind the scenes there is the, the catalog and the curation policies and everything come together. But you just, instead of going inside the platform and search and understand, you can, I mean, you can do that, but it's very easy to, for, uh, whether if you are a technological person or not, you just ask you a question and you get an immediate answer.
And, you know, I I, I ended the, the, the keynote with I can, you know, I can imagine what future holds. And, you know, people like Yale talked about the runtime. And, and you know, I, I don't have the full roadmap here, but, but just try to imagine what you can get with this context of jfr and all the knowledge of binaries of your, in the context of your organization and connect it all together.
So, I mean, just write this in mind. It's an exciting time. I, I, and, and I think that's something I wanna emphasize.
I, I, I told you I was talking to the, uh, fellow from Deloitte Yeah. And he was saying how impressed he was with the depth of the functionality between GI, GitHub and, and Jfr. But I think that that is kind of just the beginning.
I think we'll continue to see this develop. Well, uh, first of all, the collaboration with GitHub is amazing. Uh, all the work all along the way is, is great, uh, about what future holds with the collaboration.
I mean, it's something that at, at my position, I still, uh, not super, uh, familiar with, but absolutely there is a collaboration, a good collaboration between jfo and GitHub. And, you know, the sky's the limit. I mean, yeah.
So it's gonna be interesting times for those people who aren't here. They're watching this, right? Yeah.
How can they get more information? So first of all, they can go directly in the J four website under the partnership and the integration, they can just click on the GitHub, uh, gub link. They will see it with a kind of, uh, new integration.
Mm-Hmm. And or just search, you know, Google J four GitHub. It'll get them directly to their, I mean, this is what I will do.
I will just, That's what I would do too. Yeah. Not only that, I, you probably can talk it in.
And then the thing about Google these days is they don't send you out. Yeah. Right.
They'll give you an AI response about Yeah. Yeah. Google, you know, that GitHub, we would tell you about this.
Yeah. We will tell you about it. That's the world we live in, man.
Yeah, yeah. Absolutely. Ly Anyway, yeah.
Just sorry for J four GitHub, you will get all the Information eventually. Yeah. You may have to scroll down a little bit, but you get It.
Yeah. Absolute. Yeah.
What else is exciting? You hear? Well, So, uh, the, another exciting feature is the, all this, uh, integrity thing.
And we talked about the OIDC and because, you know, today, uh, using an hardcoded token can be quite dangerous. It can maybe, Well, yeah, yeah. We covered that when they first announced it.
Yeah. So, so it, it's actually using an OIDC that we stands for open. Id connect for those who are not familiar.
Right. Uh, it's the ability to have the functionality of generating, uh, you know, dynamically a short-lived token specifically for a specific operation. I mean, you can choose whether you want this token to leave for 10 minute, one minute, one hour.
I mean, it's super flexible. And you can also decide if this ask for a token, I will give it this permission and if that rep will give this permission. And also in the context of project, I mean, if one project asks for a token, you can decide which token you want to give this, uh, workflow in context of project.
And, you know, other projects needs some different, uh, token. So you, it's super flexible. And just search for OIDC and jfr.
It'll give you all the information I wrote Ablo on it, so. Right. Jonathan, thank you so much for coming on here.
Enjoy the rest of Swamp up. Thanks for, yeah, I'm having fun. Good luck as you dere Dere Jfr.
Thank you very much. We're gonna take a break. We'll be back.
We have more guests all afternoon here from Austin. Stay tuned. You're watching Textron tv.