IP Library Granted Patent US 12,452,291
Granted Patent B2
US 12,452,291 · App. 18/742,570 · Granted Oct 21, 2025

Software release tracking and logging

Inventor: Yoav Landman (Netanya, IL)
Assignee: JFrog Ltd.
H04L63/1433G06F8/65H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,452,291
App. No.
18/742,570
Granted
Oct 21, 2025
Kind
B2
Abstract

The present disclosure provides a method, system, and device for securely updating a software release across a network. To illustrate, a server may compile a transaction log that includes information corresponding to one or more nodes in the network to which the software release has been transmitted. The server may analyze one or more files based on vulnerability information to identify at least one file of the one or more files that poses a risk. The server may also identify at least one node of the network at which the at least one file is deployed. Based on identifying the at least one node, the server may transmit a corrective action with respect to the at least one node.

Claims (48)

1. A method for securely updating a software release across a network, the method comprising:

compiling, by one or more processors, information sufficient to identify at least one node in the network to which the software release has been transmitted;

analyzing, by the one or more processors, one or more files comprising the software release based on vulnerability information associated with the software release;

identifying, by the one or more processors, one or more nodes at which at least one file is deployed;

analyzing, by the one or more processors, a corrective action based on the vulnerability information to verify that the corrective action does not pose a risk, the corrective action analyzed prior to initiation of the corrective action; and

initiating, by the one or more processors, the corrective action.

2. The method of claim 1 , further comprising:

initiating, by the one or more processors, transmission of a notification to an entity, where the notification includes a recommendation of one or more options for the corrective action; and

receiving, by the one or more processors, an instruction from the entity, the instruction indicating the corrective action selected from the one or more options.

3. The method of claim 2 , where the one or more options comprise generating a new software release that does not include the at least one file, rolling back the software release to a previous version, requesting a more recent version of the software release, updating a license associated with the software release, or a combination thereof.

4. The method of claim 1 , where the corrective action is automatically initiated by the one or more processors based on identification of the at least one file that poses the risk.

5. The method of claim 1 , where initiating the corrective action comprises:

generating, by the one or more processors, a new version of the software release that does not include the at least one file; and

initiating, by the one or more processors, transmission of the new version of the software release to the one or more nodes.

6. The method of claim 1 , where initiating the corrective action comprises initiating, by the one or more processors, transmission of an instruction to roll back the software release to a previous version to the one or more nodes.

7. The method of claim 1 , where initiating the corrective action comprises initiating, by the one or more processors, transmission of an instruction to download a more recent version of the software release to the one or more nodes.

8. The method of claim 1 , where initiating the corrective action comprises:

initiating, by the one or more processors, transmission of a notification to a first node of the one or more nodes that is capable of receiving user input to select between options, where the notification includes a recommendation of one or more options for the corrective action; and

initiating, by the one or more processors, transmission of a different version of the software release or an instruction for automatic performance to a second node of the one or more nodes that is not capable of receiving user input to select between the options.

9. The method of claim 1 , where entry in a transaction log indicates a set of nodes that received the software release and a set of nodes that failed to receive the software release.

10. The method of claim 1 , where compiling a transaction log comprises generating, by the one or more processors, entry in the transaction log corresponding to the software release, the entry comprising a software release identifier corresponding to the software release, a version number corresponding to the software release, release information corresponding to the software release, a time corresponding to the software release, a set of target nodes corresponding to the software release, a set of nodes that received the software release, a set of nodes that failed to receive the software release, a set of nodes operating the software release, or any combination thereof.

11. A system for securely updating a software release across a network, the system comprising:

at least one memory storing instructions; and

one or more processors coupled to the at least one memory, the one or more processors configured to execute the instructions to cause the processor to:

compile information sufficient to identify at least one node in the network to which the software release has been transmitted;

analyze one or more files comprising the software release based on vulnerability information associated with the software release;

identify one or more nodes at which at least one file is deployed;

analyze a corrective action based on the vulnerability information to verify that the corrective action does not pose a risk, the corrective action analyzed prior to initiation of the corrective action; and

initiate, the corrective action.

12. The system of claim 11 , where the vulnerability information comprises one or more checksums and license information.

13. The system of claim 11 , where the vulnerability information comprises an indication that at least one of the one or more files failed to complete one or more development stages of a development process of the software release.

14. The system of claim 11 , where a transaction log records release information associated with the software release, the release information comprising:

for at least one of the one or more files, a corresponding checksum;

a bundle checksum for an entirety of the one or more files; and

metadata associated with the software release.

15. The system of claim 11 , where a transaction log comprises a software release log, a node log, and an artifact version log.

16. The system of claim 11 , where the one or more processors are configured to analyze the one or more files periodically or upon receipt of a request from an entity.

17. A non-transitory computer-readable storage medium storing instructions that, when executed by one or more processors, cause the one or more processors to perform operations for securely updating a software release across a network, the operations comprising:

compiling information sufficient to identify at least one node in the network to which the software release has been transmitted;

analyzing one or more files comprising the software release based on vulnerability information associated with the software release;

identifying one or more nodes at which at least one file is deployed;

analyzing a corrective action based on the vulnerability information to verify that the corrective action does not pose a risk, the corrective action analyzed prior to initiation of the corrective action; and

initiating the corrective action.

18. The non-transitory computer-readable storage medium of claim 17 , where analyzing the one or more files is performed based on detection of a vulnerability-related event, the vulnerability-related event comprising receipt of additional vulnerability information, detection of a change in a license, or a combination thereof.

19. The non-transitory computer-readable storage medium of claim 17 , where the operations further comprise receiving a confirmation from the at least one node, the confirmation indicating acceptance of the software release at the at least one node.

20. The non-transitory computer-readable storage medium of claim 17 , where the operations further comprise:

receiving additional vulnerability information from a third-party data source; and

combining the additional vulnerability information with the vulnerability information, where analyzing the one or more files is performed in response to combining the additional vulnerability information with the vulnerability information.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 13, 2024
From: LANDMAN, YOAV
To: JFROG LTD.
Reel/Frame 067720/0659 →
Continuity (5)
Continuation 17976843 · Oct 30, 2022
Continuation 17227069 · Apr 9, 2021
Continuation 16931898 · Jul 17, 2020
Provisional Application 62876562 · Jul 19, 2019
Related Publication 20240333754A1 · Oct 3, 2024
References Cited (149)
US 5671282A · Wolff et al. · 1997 [cited by applicant]
US 5915238A · Tjaden · 1999 [cited by applicant]
US 5931946A · Terada · 1999 [cited by examiner]
US 6604236B1 · Draper et al. · 2003 [cited by applicant]
US 6802061B1 · Parthasarathy et al. · 2004 [cited by applicant]
US 7007042B2 · Lubbers et al. · 2006 [cited by applicant]
US 7464158B2 · Albornoz · 2008 [cited by examiner]
US 8036140B2 · Rao et al. · 2011 [cited by applicant]
US 8196186B2 · Mityagin et al. · 2012 [cited by applicant]
US 8364758B2 · Hydrie et al. · 2013 [cited by applicant]
US 8510571B1 · Chang · 2013 [cited by examiner]
US 8788830B2 · Piersol · 2014 [cited by applicant]
US 9009820B1 · McDougal · 2015 [cited by examiner]
US 9053124B1 · Dornquast et al. · 2015 [cited by applicant]
US 9280339B1 · Prunicki et al. · 2016 [cited by applicant]
US 9635107B2 · Souza et al. · 2017 [cited by applicant]
US 9659155B2 · Kosovan · 2017 [cited by applicant]
US 9842062B2 · Ford et al. · 2017 [cited by applicant]
US 9946531B1 · Fields · 2018 [cited by examiner]
US 9959394B2 · Mot et al. · 2018 [cited by applicant]
US 9971594B2 · Fox et al. · 2018 [cited by applicant]
US 10091215B1 · Word · 2018 [cited by applicant]
US 10339299B1 · Magnuson et al. · 2019 [cited by applicant]
US 10387570B2 · VanBlon et al. · 2019 [cited by applicant]
US 10409838B1 · George et al. · 2019 [cited by applicant]
US 10719369B1 · Aithal et al. · 2020 [cited by applicant]
US 10754952B2 · Muller et al. · 2020 [cited by applicant]
US 10911337B1 · De Kosnik et al. · 2021 [cited by applicant]
US 10986387B1 · Parulkar et al. · 2021 [cited by applicant]
US 11048590B1 · Sapuntzakis et al. · 2021 [cited by applicant]
US 11064323B2 · Esselink et al. · 2021 [cited by applicant]
US 11249739B2 · Atkinson et al. · 2022 [cited by applicant]
US 11284258B1 · Wei et al. · 2022 [cited by applicant]
US 20020156893A1 · Pouyoul et al. · 2002 [cited by applicant]
US 20030191955A1 · Wagner et al. · 2003 [cited by applicant]
US 20030220880A1 · Lao · 2003 [cited by examiner]
US 20040064722A1 · Neelay · 2004 [cited by examiner]
US 20040181561A1 · Knox et al. · 2004 [cited by applicant]
US 20040250115A1 · Gemmel · 2004 [cited by examiner]
US 20050071385A1 · Rao · 2005 [cited by applicant]
US 20050132348A1 · Meulemans et al. · 2005 [cited by applicant]
US 20060136547A1 · Neuhaus · 2006 [cited by examiner]
US 20060236392A1 · Thomas · 2006 [cited by examiner]
US 20060259967A1 · Thomas · 2006 [cited by examiner]
US 20070169199A1 · Quinnell · 2007 [cited by examiner]
US 20070220575A1 · Cooper et al. · 2007 [cited by applicant]
US 20070294686A1 · Oh · 2007 [cited by applicant]
US 20080005113A1 · Li · 2008 [cited by applicant]
US 20080005120A1 · Li · 2008 [cited by applicant]
US 20080082648A1 · Ahmed et al. · 2008 [cited by applicant]
US 20080163374A1 · Rogers · 2008 [cited by examiner]
US 20080178287A1 · Akulavenkatavara · 2008 [cited by examiner]
US 20080294860A1 · Stakutis et al. · 2008 [cited by applicant]
US 20090013317A1 · Abfalter · 2009 [cited by examiner]
US 20090083812A1 · Tang · 2009 [cited by applicant]
US 20090119655A1 · Quilty · 2009 [cited by applicant]
US 20090210697A1 · Chen et al. · 2009 [cited by applicant]
US 20100217694A1 · Knighton · 2010 [cited by applicant]
US 20110010421A1 · Chavez et al. · 2011 [cited by applicant]
US 20110093701A1 · Etchegoyen · 2011 [cited by applicant]
US 20110107419A1 · Vidal · 2011 [cited by examiner]
US 20110113012A1 · Gruhl et al. · 2011 [cited by applicant]
US 20110225311A1 · Liu et al. · 2011 [cited by applicant]
US 20110307564A1 · Luo et al. · 2011 [cited by applicant]
US 20120090025A1 · Milner · 2012 [cited by examiner]
US 20120131566A1 · Morgan et al. · 2012 [cited by applicant]
US 20120151245A1 · Chang et al. · 2012 [cited by applicant]
US 20120222112A1 · DiFalco · 2012 [cited by examiner]
US 20120233134A1 · Barton et al. · 2012 [cited by applicant]
US 20120240096A1 · Sass · 2012 [cited by examiner]
US 20120240236A1 · Wyatt · 2012 [cited by examiner]
US 20120297405A1 · Zhang et al. · 2012 [cited by applicant]
US 20130073727A1 · Souza et al. · 2013 [cited by applicant]
US 20130081100A1 · Sreehari et al. · 2013 [cited by applicant]
US 20130132946A1 · Ma · 2013 [cited by applicant]
US 20130268927A1 · Cochran · 2013 [cited by applicant]
US 20130326481A1 · Kannan · 2013 [cited by examiner]
US 20140172972A1 · Burba et al. · 2014 [cited by applicant]
US 20140245376A1 · Hibbert · 2014 [cited by examiner]
US 20140373160A1 · Shigemoto · 2014 [cited by examiner]
US 20150003296A1 · Fan et al. · 2015 [cited by applicant]
US 20150088992A1 · Toannidis et al. · 2015 [cited by applicant]
US 20150180893A1 · Im · 2015 [cited by examiner]
US 20150268881A1 · Nielsen et al. · 2015 [cited by applicant]
US 20150301823A1 · Hatakeyama · 2015 [cited by applicant]
US 20150302037A1 · Jackson et al. · 2015 [cited by applicant]
US 20150312243A1 · Ponsford et al. · 2015 [cited by applicant]
US 20150317145A1 · Katariya et al. · 2015 [cited by applicant]
US 20160117235A1 · Mishra et al. · 2016 [cited by applicant]
US 20160124665A1 · Jain et al. · 2016 [cited by applicant]
US 20160164900A1 · Pericin · 2016 [cited by applicant]
US 20160179867A1 · Li et al. · 2016 [cited by applicant]
US 20160182494A1 · Lissounov et al. · 2016 [cited by applicant]
US 20160182556A1 · Tatourian · 2016 [cited by examiner]
US 20160234237A1 · Thakar · 2016 [cited by examiner]
US 20160266890A1 · Aleksandrov et al. · 2016 [cited by applicant]
US 20160267101A1 · Clissold et al. · 2016 [cited by applicant]
US 20160344834A1 · Das · 2016 [cited by examiner]
US 20170003951A1 · Newell et al. · 2017 [cited by applicant]
US 20170034023A1 · Nickolov et al. · 2017 [cited by applicant]
US 20170060546A1 · Prasad et al. · 2017 [cited by applicant]
US 20170147338A1 · Jackson et al. · 2017 [cited by applicant]
US 20170264588A1 · Hunt et al. · 2017 [cited by applicant]
US 20170300309A1 · Berger et al. · 2017 [cited by applicant]
US 20170357496A1 · Smith · 2017 [cited by examiner]
US 20170357807A1 · Harms · 2017 [cited by examiner]
US 20170371499A1 · Checkley et al. · 2017 [cited by applicant]
US 20180095993A1 · Clark · 2018 [cited by applicant]
US 20180136923A1 · Xiao · 2018 [cited by applicant]
US 20180189043A1 · Habayeb · 2018 [cited by applicant]
US 20180240546A1 · Pfeiffer · 2018 [cited by applicant]
US 20190050576A1 · Boulton · 2019 [cited by applicant]
US 20190080080A1 · Ogura et al. · 2019 [cited by applicant]
US 20190130114A1 · Smith et al. · 2019 [cited by applicant]
US 20190138287A1 · De Capoa et al. · 2019 [cited by applicant]
US 20190155598A1 · Bainville et al. · 2019 [cited by applicant]
US 20190205121A1 · Ericson · 2019 [cited by applicant]
US 20190303623A1 · Reddy et al. · 2019 [cited by applicant]
US 20190305957A1 · Reddy · 2019 [cited by examiner]
US 20190306173A1 · Reddy · 2019 [cited by examiner]
US 20190379723A1 · Demasi et al. · 2019 [cited by applicant]
US 20200012441A1 · Chheda · 2020 [cited by examiner]
US 20200026857A1 · Muller et al. · 2020 [cited by applicant]
US 20200076618A1 · Driever et al. · 2020 [cited by applicant]
US 20200076807A1 · Driever et al. · 2020 [cited by applicant]
US 20200177397A1 · Harrington · 2020 [cited by applicant]
US 20200213144A1 · Maloy · 2020 [cited by applicant]
US 20200252207A1 · Hanel et al. · 2020 [cited by applicant]
US 20200351089A1 · Wentz · 2020 [cited by applicant]
US 20200372183A1 · Rangaiah et al. · 2020 [cited by applicant]
US 20210021428A1 · Landman · 2021 [cited by applicant]
US 20210111875A1 · Le · 2021 [cited by applicant]
US 20210218800A1 · Landman · 2021 [cited by applicant]
US 20220150073A1 · Androulaki et al. · 2022 [cited by applicant]
WO 2012153173A2 · 2012 [cited by applicant]
Patent Cooperation Treaty, International Search Report and Written Opinion issued for PCT Application No. PCT/IB2020/056777, dated Oct. 19, 2020, 15 pages. [cited by applicant]
Li et al. “A Quantitative and Comparative Study of Network-Level Efficiency for Cloud Storage Services,” ACM Trans. Model. Perform. Eval. Comput. Syst., vol. 4, No. 1, Article 3, 2019, 32 pages. [cited by applicant]
Jana et al. “Management of Security and Privacy Issues of Application Development in Mobile Cloud Environment: A Survey,” IEEE International Conference on Recent Advances and Innovations in Engineering, May 2014, 6 page… [cited by applicant]
Patent Cooperation Treaty, International Search Report and Written Opinion issued for PCT Application No. PCT/IB2021/050134, dated Mar. 4, 2021, 14 pages. [cited by applicant]
JFrog; “Access Tokens,” https://www.jfrog.com/confluence/display/JCR6X/Access+Tokens, Jan. 29, 2020 (Year: 2020), 1 page. [cited by applicant]
Alibaba Cloud; “Alibaba Dragonfly DCOS Case Study: China Mobile (Zhejiang Branch),” https://alibaba-cloud.medium.com/ alibaba-dragonfly-dcos-case-study-china-mobile-zhejiang-branch-a13dc751a2c, Jan. 14, 2019 (Year: 2019… [cited by applicant]
eduonix.com; “Alibaba's DragonFly—A New P2P File Distribution Framework,” https://blog.eduonix.com/software-development/alibabas-dragonfly-p2p-distribution/, Jul. 4, 2018 (Year: 2018), 3 pages. [cited by applicant]
Alibaba Cloud; “Behind Alibaba's Double 11 Mysterious “Dragonfly” Technology @C PB-Grade Large-File Distribution System,” https://www.alibabacloud.com/blog/behind-alibabas-double-11-mysterious-dragonfly-technology-@c-pb… [cited by applicant]
Seneviratne, AIDK; “Enabling an Authentication Mechanism for Docker Remote API,” Mar. 2017 (Year: 2017), 70 pages. [cited by applicant]
IEEE; “FID: A Faster Image Distribution System for Docker Platform,” 2017 (Year: 2017), 8 pages. [cited by applicant]
DragonFly; “What Is DragonFly?” https://web.archive.org/web/20190501065255/https://d7y.io/enus/docs/overview/what_is_dragonfly.html, May 1, 2019 (Year: 2019), 3 pages. [cited by applicant]
Uber Engineering Blog; “Introducing Kraken, an Open Source Peer-to-Peer Docker Registry,” https://eng.uber.com/introducing-kraken/, May 5, 2019 (Year: 2019), 3 pages. [cited by applicant]
JFrog; “Searching for Artifacts,” https://www.jfrog.com/confluence/display/JCR6X/Searching+for+Artifacts, Jan. 29, 2020 (Year: 2020), 3 pages. [cited by applicant]
Yoshida et al. “Understanding the Origins of Weak Cryptographic Algorithms Used for Signing Android Apps,” 2018 42nd IEEE International Conference on Computer Software and Applications; 6 pages. [cited by applicant]