Can any user here provide some context what JFrog does? The website doesn't really say much, the example pipeline files for JFrog pipelines seem more complex than GitLab CI.
Can any user here provide some context what JFrog does? The website doesn't really say much, the example pipeline files for JFrog pipelines seem more complex than GitLab CI.
It's also like a local cache of public repos. That means faster builds, some level of quality control (ie black or white list of safe libraries) as well as protection against things like the leftpad fiasco or 2016.
Packages/libraries such as those used by NPM and Pip are some examples. It may also be an entire program, an OS package, a virtual machine, a Docker image, even things like PNG images.
Artifactory has tooling to make it easy to integrate into typical build pipelines.
Also no idea what else they do.
They also have an XRay offering for scanning things like Docker containers for vulnerabilities, although for various reasons we do not use it. I wish we did! It would keep things integrated.
The main reason why we use Artifactory, though, is because it allows us to share artifacts across different regions and environments.
The one thing I don't like is how stingy jfrog is with their licenses. It makes automatic deployments of Artifactory a bit difficult for us. Their Mission Control offering isn't enough for the way we deploy Artifactory.