-
AppTrust Introduction 00:02:18
-
Reimagining Trust in Software Releases: A New Approach to Supply Chain Integrity (Part 1) 00:20:08
-
Reimagining Trust in Software Releases: A New Approach to Supply Chain Integrity (Part 2) 00:31:54
AppTrust Overview
Course Level: Beginner
Requirements: A foundational understanding of DevOps, application security, and software supply chain risks.
Prerequisites: No technical prerequisites are required. This course provides a high-level overview of application risk governance and the JFrog AppTrust solution.
Topics Covered:
- The Modern Risk Landscape: Understanding the "Triple Threat" of development velocity, complex supply chains, and increasing regulatory liability.
- Application Risk Governance: Defining the shift from point-in-time scanning to a continuous, unified governance layer.
- The Application Entity: How to unify repositories, builds, and security evidence into a single, business-aware context.
- Full Lifecycle Integrity: Moving beyond snapshots to govern the application's integrity from the first line of code through production.
- Evidence-Based Control Gates: Utilizing automated "Trusted Release Stamps" to ensure only compliant, certified versions are deployed.
- Multi-Persona Value: How AppTrust solves specific pain points for Security Leaders (control), DevSecOps (integration), and GRC teams (automated auditing).
- The JFrog Advantage: Comparing native SDLC integration versus external security tools that lack artifact intelligence.