JFrog Runtime Security and MLOps with Yoav Landman at JFrog swampUP 2024
JFrog CTO Yoav Landman discussed the company’s launch of runtime security, providing integrated protection throughout the software supply chain from development to production environments. He also highlighted JFrog ML, a comprehensive platform for managing machine learning models following the acquisition of MLOps company Qwak. Additionally, JFrog’s enhanced GitHub integration and AI-driven Copilot extension streamline workflows and boost developer productivity by breaking down silos and offering real-time package and security insights.
Transcript
This is Techron tv. Hey, everyone. We're back here for wrapping up our day two of Swamp Up coverage.
We've saved some of the best for last though. Um, it's been a terrific, terrific swamp up, high energy, great announcements, great people. My friend Yev Laman is the CTO Co-founder of J Rog.
com, you know, Yev. Um, yo, first of all, welcome. Congratulations on an amazing swap up.
Um, I wanna go over with you a bunch of things. I know we only have limited time, so we will hop. So the first, the first thing I wanted to talk about a little was the security.
Mm-Hmm. Uh, we, we announced runtime security, uh, yesterday. It was announced.
It's a standalone product. It's ready now. But really, the, the special sauce from what I understand is that it, it's tight integration with the Jfr platform.
Exactly. So we see runtime as part of your software supply chain. And over the past, uh, couple of years, what we've been doing is we, we've been integrating security into your supply chain.
We've been shifting left and starting with curation as a kind of a perimeter level defense for, uh, what open source can get to the organization. Yep. Uh, so it's kind of a firewall, and then you have a SaaS scanning for your code for zero days in Git, uh, in your ID or in your GIT server.
And then X-Ray, which is our first landmark in security. Right. This is, uh, an SCA scanner.
Yep. And all the advanced securities that we, um, the forget advanced security that we put on top, uh, with, uh, applicability scanners that can tell you whether a CV is really applicable, whether it's, um, Exploitable Affecting your, uh, your current risking you. Um, and, uh, we left runtime or production to, to the last point.
And once we, what we introduced, uh, um, in this warm up is, uh, the connection from runtime, uh, all the way to your software supply chain. So basically, um, it's a bi-directional connection that allows you to see how things that are running in runtime impact, uh, um, impact you and how they are related to your packages, to your, uh, uh, to your bills, to your code. Uh, and by bidirectional, I mean that you can, if you take look for Jeff, for instance, you can stand on the log four jail library.
You can see which build it's part of, which container it's part of, but you can also see now which workloads in Kubernetes, it's running in, in, In, in real, in, in random, In your production, uh, uh, uh, Kubernetes Platform. So it gives, it, it extends the visibility of what you already had pre-production into the production environment. It extends the visibility, but it also gives you, uh, in terms of, uh, productivity and the ability to remi to remediate.
Um, it's not just that you are seeing your workload in production that is, uh, that is impacted. You can immediately tell where it's coming from in Artifactory, which build created it. And now, which with the GitHub integration that I'm, I'm assuming will talk a little bit, uh, uh, further, uh, you can even tell which code created this vulnerability that ended up running in production.
Got it. So that's Jeff Heim. And that's really opinionated in nutshell way to look at security as a, as part, as an integrated part of your software supply chain rather than a siloed, I think its a holistic way to look at security.
Right, exactly. Where you're looking at the whole thing from far left to, to far right. Exactly.
It's a production line at the end of the day. Yeah, absolutely. That's what it is.
Now, the same kind of scanning for CVEs and vulnerabilities and stuff that we're doing, you know, with X-Ray and some of the other, uh, pre-deployment scans we're doing in post-deployment as well. That's available for you in ran. Yeah.
Because everything is connected, all the, so it's metadata that you need to know about the ESMO of what's running in production. The applicability of vulnerabilities is that are, and that's Where the beauty of the integration into the platform is. Right?
Because, so for instance, 20 years ago when my company I, I helped co-found, uh, we did nac, right. Network work access control. Mm-Hmm.
And the beauty is we had a vulnerability man, a vulnerability scanner. So a lot of times we didn't actually have to scan because using the nac, we were able to, we already knew what was in the registry. Exactly.
So we knew what packages you had. And so I didn't need a scanner to tell me your package was vulnerable or your, it was an old package with a known bug or something. And that's sped things up a lot.
Right. That's, by the way, that's exactly the value of Artifactory here, because if you have a central control point for anything that gets into your release, including your release, how you package things up, at the end of the day when you put them in production, then you can put control points and also metadata inside Artifactory so that the only thing for you to do when it lands in runtime is actually two things. First is figure out whether it's actually loaded because we want, we don't want to alert you for nothing.
And then just link back to Artifactory and, and D one and the security and Jeff Security that has all the metadata around the artifact that's in production to give you exactly, like in the example you brought, Uh, I got it. All the information you need now, but runtime security is an individual product you could run. You don't need the rest of necess.
Theoretically you can run it independent from the rest of the Jfr platform. No, that's part of our security package. Yeah.
Um, for a reason, by the way, because we see security. You said it, it's a holistic thing. You, you want to be protecting every phase of the release, uh, uh, lifecycle.
Every phase of your software supply chain needs to be protected. Uh, it's, um, you need to start early. You need to start from the left, but you also need the visibility and the remediation on the right.
So, So yo, fantastic. And because I, I will tell you, when I first heard runtime security, I was like, oh, just what the world needs, you know, more runtime, Another runtime security. But this now makes a lot more sense to me.
The next thing I wanted to talk to you about was Frog jfr ml. Right? You guys bought the ML Lops Clark Quack.
Yes. Excuse me. Company.
And now it it's rebranded jfr. How does that fit in here? So we bought Qua, uh, that's, uh, my Israeli accent.
I'm not sure how to, what's, uh, the right way to pronounce it. But, uh, we bought Qua, uh, around two months ago. Yeah.
Uh, quack is an end-to-end solution for, uh, for machine learning. So you can take a model, uh, you can train it, you can fine tune it. Uh, it takes care of all the data ingestion that you need in order to, uh, to build your model.
And it goes all the way to the serv to serving the model, monitoring it so that you can be, you can get the feedback loop, you can do it in a matter of minutes with work. It's such a, a, a useful, that's great platform that allows you a solution that allows you, that Jeff o Gamel is more than just quack rebranded. It's not a rebranding of, of quack.
It's actually the fully experience, uh, of machine learning development in the JO platform. So it takes the days, days of using the process management, this trusted process management, uh, for machine learning, uh, coming from qac. Uh, and it merges that with the trusted asset management that JO allows you to have.
So it's the management itself, it's scanning it's curation for models, and it brings them together for full experience under one platform. 'cause that's what we're actually seeing happening in the market. That machine learning is a very new thing.
And, uh, mature DevOps practices are still not there. But we are seeing customers, uh, actually requesting us to provide the same level of maturity, the same level of trust that, uh, that they have when, when managing, uh, um, like traditional assets for machine learning assets, they came up with this phrase model as a package, uh, to describe how they're expecting to, to manage machine learning assets with versioning, with cleanups, right? With curation, with scanning.
Well, it's bringing all of that, not stability, but, but process and, and form to what was a little looser. It was a little loose in terms of how it was done. It, It's forces, its lineage.
It's also the fact that when you are creating a machine learning application, especially now with Gen ai, it's not an isolated very small application that you're running and can make like a one method prediction. It's really a full application with dependencies, with data sets that, uh, will impact the, the, the output of, uh, of your model with the containers that you're using to run it. So you need this full universal solution plus the lineage between all the different artifacts that make up your application.
Sure. So this, this is in of itself. This has truly a become a real product, much more full featured than clockwise.
It is a real product. We released it in ga, it's the first, uh, release of that. Yeah.
Yes. But, but as you said, it's not just a rebrand. There was, there was a lot of needed functionality that makes this a little bit more mature.
Yeah. It's a full experience that I don't think exists elsewhere. No.
Like I developed the model. You can curate the model. So many companies today, because machine learning is so new, they have a, an allow list of models and model versions that they allow people to use in the organization.
So it takes care of that. It's scanning the model for, for vulnerabilities based on catalog, uh, of course scanning all the other dependencies that, uh, that are part of your machine learning application. You get to see all your security results inside the same platform.
Um, yeah. And, uh, of course serving the production. I love it.
Yeah. Alright, moving on from that. There was an Nvidia, uh, partnership we spoke about with others, but I wanted to come back to the, uh, GitHub mm-hmm.
That was truly an integration here. You know, and, and GitHub, a lot of people think GitHub and they say, oh, it's the repo. Yeah, it's the repo.
It is, it's a great repo with versioning and all of that. But today, many developers actually develop inside of GitHub. Right.
And I think it was, was it last year at Swamp Up, you gave a demo of like a, an X-Ray scan inside of the IDE. Was it last year? Or am I imagining?
We, we launched, uh, the, the SaaS integration with I, with ip, sorry, with IDP against as part of, uh, Jeff Fog advanced security. And we also have, uh, uh, a Frog Bot, which is, uh, our GitHub, uh, integration with GitHub actions. Um, but this is the whole new thing, Right?
This is, that was last year. Now, this year is, it's a, you know, last year, I don't think co-pilot was out last year, but it is this year and, and the whole AI thing is, is changed. This I think was out, but what's new is the copilot extensions, right?
So maybe let's start with the beginning. So what, what's happened with the GitHub integration, that's, it's not new in this warm up. I mean, we announced it in Q2 and, uh, the background for that is that we have many joint customers with GitHub.
And, uh, given that you don't want those silos in your supply chain and that still Source and binaries are managing two different, uh, systems, our solution engineers and the GitHub solution engineers Will, will meeting to together on the same customer side, creating this integration between the platform, uh, by hand and in qto. We, in Qto, we started to productize this integration and, and we, uh, uh, formed this, uh, partnership with GitHub and we started to get feedback. So this time around, we introduced the next generation of disintegration.
So we made, uh, a lot of improvements in the OIDC mapping between, uh, jfo, uh, uh, projects and git a repositories. So it's fully dynamic. You can, um, very easily, um, create a convention for how your repository, how your repositories are mapped to GitHub, uh, how your projects are mapped to GitHub repositories, which gives your GitHub actions automatic permissions on Artifactory.
That's the, that's the goal of it, just to enable automated, uh, convention based authorization for GitHub actions. So that's one thing. We also improved the bidirectional navigability between GitHub and jfo and, and vice versa.
So it's not just an improved, uh, ui, but we are also now depositing, um, uh, building for this is our SBO that, uh, that is created automatically now from GitHub actions. And we, we send it to Artifactory, so it contains all the artifacts that were pushed to artifactory, all the dependencies that were used in your build, but it also allows us to create this navigation between code and binaries now because we know exactly which banner it was created by, which, uh, uh, by which commit. Mm-Hmm.
And now, even with Runtime, you can go back from runtime and go all the way back to your GitHub source that, uh, that, uh, ended up running in runtime. So, So let me ask you, is it fair to say what we're doing with the GitHub integration is we're making it seamless for people to work with their code and artifacts in one interface? It makes no difference whether you're in GitHub, great.
It's still going to transfer into, into Artifactory anyway, or vice versa. Yeah. You know, we, we are removing the barriers.
We are breaking down the silo. Someone Said that yesterday in the keynote. We, it's a good thing to break that good for you, break down the Silo.
So yeah. That, that's what we're doing. Uh, so we are doing that also.
I mean, PE that's how people are working. They're attacking these two best of breed platforms, integrating them together. And now we are also doing it for security, right?
So we are giving you one single pane of, uh, glass to see the GitHub scan results, uh, for code plus the JO scan results for code, but also for binaries. Uh, I don't know if you, uh, spoke about this before, but No, it's Really, really critical to scan your binaries. Of course it is.
I mean, we, well, actually, I, um, that was the, the py remember with the, with the token left in There. Yeah. That's the keys to the Python, Right?
We, we, uh, we covered, I, well, I covered it when it first came, was first disclosed. Exactly. But, Um, but It shows you that you can have a vulnerability that clips from your code to your binaries, and it's not evident anywhere in your code later on.
Right. If, if you don't scan your binaries, you are basically it amounts. Absolutely.
So some kind of a negligence, uh, like happened with the, Well, it's, again, negligence is the absence of reasonable, right? And so it's unreasonable. Now, agree, if you're not scanning your binaries, I agree.
Now my take and I sit outside, right? I'm not in Jfr, but my take is that there's more to this partnership, there's more integrations to come without giving away the farm. So of course, uh, we're try, this is like, uh, we are, first of all, we are getting customer feedback and based on the customer feedback, and there's a lot of customer feedback that we got here on the conference, uh, from customers that already adopted the, the, the integration.
Um, so we, there are things that we are planning in, uh, uh, enhancing further the user experience there. Um, I cannot say No, no, let's not get in trouble. Uh, they won't invite me back next year.
I heard it might be in Napa. I don't want to miss it. Yeah.
We, we released, um, the co-pilot extension. Yes. As, as part of that.
So obviously we're going to, uh, um, spend a lot of efforts around making this user experience with the co-pilot extension even even better. So today it allows you to consult about the, the packages that, that the selection of packages. If you remember as a developer, it's a, it's a daunting task.
It's, uh, you never know which package is going to do the right thing. You start to Google it up and you start to figure out whether it has, uh, security issues. I'm just gonna say then as soon as you pick one, you find out.
Yeah. And then you block that one has a note. The scanners.
Yeah. So here it's, it's a much easier experience. You just, you can ask about if I want to, to use a, a package that is speaking from Node with, uh, from NPM, sorry, with Redis, I can just ask for the libraries that, uh, that are doing that.
I'm going to get advice on them. I'm going to get security information about them. I'm going to even get the, the knowledge about whether or not I'm permitted to use this library because of my, uh, uh, policies in ge o curation.
Maybe it's too new. Maybe I'm not allowed to use a package that it's, uh, that is younger than two weeks. Because that's how my organization, We haven't checked it out yet.
And I can even ask questions about the usage, the, uh, uh, popularity. So I can say in the automotive industry, which version of this package is the most popular? And we, we are the only ones who can tell because absolutely we have the, the actual usage data.
Got all that data from the Repo Exactly. From a cloud. So is this in a natural language interface yet, or no?
English. English. Yeah.
English or, or, Or German or Hebrew. I heard yesterday You heard and you saw them, or, I mean, at the end of the day, it's, uh, I left before the demo, I had to come do videos, but I heard, Okay. So yeah, it, it can work with any language that, uh, the LLMs can take.
It depends on The market, and that's really great stuff. And that's really where the world is headed. Now.
I was talking to Scott Johnston from Docker earlier, I don't know, there's 27 million developers in the world now we're going to 40 million. But the beauty of, of Gen ai, quite frankly, is we could have a half a billion developers in in five years because everybody will be able to, it. It may not be a developer like you are thinking a developer, but everybody will be able to develop an app.
You just tell, tell it to what you want and it, and it does. Right. How do you as the CTO of Jfr plan for that?
So, great question. Um, so first of all, the new API is English. Yeah.
Okay. Maybe also other languages, but primarily English. Um, so I think what's, uh, what it gives you is, uh, an incredible amount of productivity around making your users much more, uh, much more productive using ai.
Again, without going, uh, too much, uh, into roadmap, uh, items. But think about the amount of, uh, of, uh, productivity you can achieve by getting instructions that are less structured and making them, converting them to structured instructions, but also predict what users will need next and doing the, doing it for them, or at least offering them what should be the next steps. So obviously that's something that occupies us a lot.
Security is also a big deal because now with the ai right, And with all those people Developing and the social capabilities. Um, so there are plenty of, uh, So enough to keep you busy. You're not retiring.
Yeah, not any, anytime Soon. Not soon. Yo, as always my friend, thank you so much.
Thank you. It's been pleasure. What a great swamp up.
We'll see you soon. Thank you. Alright.
Y Larin, CTO Co-founder at Jfr here at Swamp. Up up. We're gonna take a break.
I think we've got one more interview to go stay tuned for it.