JFrog S-1
sec.gov
sec.gov
Usually JFrog is pretty responsive on StackOverflow though for this particular question they seem a bit evasive ( https://stackoverflow.com/questions/43481238/where-is-the-ar... ).
Why do they have to?
If it's really critical, you'll do that but a company has to be really dependent on a piece of software (or unusually cognizant of the open source maintainership problem) to go the second route. Built-in defaults carry a lot of weight.
- benologist, https://news.ycombinator.com/item?id=17454032
If AWS wants to copy you, not having your source code isn't going to stop them.
Can any user here provide some context what JFrog does? The website doesn't really say much, the example pipeline files for JFrog pipelines seem more complex than GitLab CI.
Also no idea what else they do.
They also have an XRay offering for scanning things like Docker containers for vulnerabilities, although for various reasons we do not use it. I wish we did! It would keep things integrated.
The main reason why we use Artifactory, though, is because it allows us to share artifacts across different regions and environments.
The one thing I don't like is how stingy jfrog is with their licenses. It makes automatic deployments of Artifactory a bit difficult for us. Their Mission Control offering isn't enough for the way we deploy Artifactory.
It's also like a local cache of public repos. That means faster builds, some level of quality control (ie black or white list of safe libraries) as well as protection against things like the leftpad fiasco or 2016.
Packages/libraries such as those used by NPM and Pip are some examples. It may also be an entire program, an OS package, a virtual machine, a Docker image, even things like PNG images.
Artifactory has tooling to make it easy to integrate into typical build pipelines.
Last I looked, it didn't supported signing repositories (and these days, it's basically impossible to get an unsigned repo into a Debian system).
Unfortunately GitHub has been going down for multiple days this year, they've definitely outpaced our Artifactory instance in terms of downtime.
"Our business and operations have experienced rapid growth, and if we do not appropriately manage future growth, if any, or are unable to improve our systems, processes and controls, our business, financial condition, results of operations, and prospects will be adversely affected."
"Our recent rapid growth may not be indicative of our future growth, and we may not be able to sustain our revenue growth rate in the future. Our rapid growth also makes it difficult to evaluate our future prospects and may increase the risk that we will not be successful."
"We have a history of losses and may not be able to achieve profitability on a consistent basis. If we cannot achieve profitability, our business, financial condition, and results of operations may suffer."
"The markets for our products are new, unproven, and evolving and may develop more slowly or differently than we expect. Our future success depends on the growth and expansion of these markets and our ability to adapt and respond effectively to evolving markets."
"Our results of operations are likely to fluctuate from quarter to quarter, which could adversely affect the trading price of our ordinary shares."
"If we are not able to keep pace with technological and competitive developments or fail to integrate our products with a variety of technologies that are developed by others, our products may become less marketable, less competitive, or obsolete, and our results of operations may be adversely affected."
"A limited-functionality version of JFrog Artifactory is licensed under an open source license, which could negatively affect our ability to monetize our products and protect our intellectual property rights."
"The market for our products is nascent and highly fragmented, and we may not be able to compete successfully against current and future competitors, some of whom have greater financial, technical, and other resources than we do. If we do not compete successfully our business, financial condition, and results of operations could be harmed."
"JFrog Artifactory is at the core of our business and any decline in demand for JFrog Artifactory occasioned by malfunction, inferior performance, increased competition or otherwise, will impact our business, results of operations and financial condition."
"If we are unable to increase sales of our subscriptions to new customers, sell additional subscriptions to our existing customers, or expand the value of our existing customers’ subscriptions, our future revenue and results of operations will be harmed."
[0] https://www.sec.gov/Archives/edgar/data/1800667/000119312520...
Can I upload my Maven binaries to Helm? Does Helm store them? If I have a jar or war, can Helm store them? Does Helm resolve Maven dependencies if I connect to it and run mvn clean install locally?
"To err is human. To really foul things up requires a computer."
But that's assuming you use Kubernetes.
Helm is not a replacement for Artifactory, I don't know what you're going on about. They have a bit of overlap but the main use case of Artifactory is as a binary artifact repository for any environment, including non-Kubernetes ones. And there are a lot of non-Kubernetes environments out there. I'd argue that Kubernetes environments are a drop in the ocean compared to everything else.