Welcome to the JFrog Blog

All Blogs

Fly Graduates: Agentic Repository Experience Lands in the JFrog Platform

Fly Graduates: Agentic Repository Experience Lands in the JFrog Platform

The way software gets built is changing faster than at any point in the last decade, and the software supply chain has to keep up. A year ago at swampUp, we introduced JFrog Fly: the first agentic repository, serving as a fast, AI-native environment to build what a modern, agentic developer workflow could look like,…
Securing the Australian Government Software Supply Chain: JFrog Completes Protected Level IRAP Assessment

Securing the Australian Government Software Supply Chain: JFrog Completes Protected Level IRAP Assessment

JFrog has reached a major milestone: An IRAP assessment at the Protected level, across the full JFrog Platform. Conducted by CyberCX, an Australian Signals Directorate (ASD)-endorsed assessor, against the ISM, it independently validates that the platform managing an agency’s software supply chain meets the bar for Australia’s most sensitive workloads. It reasserts a commitment that…
Coding Agents Just Reopened Your Software Supply Chain Blind Spot

Coding Agents Just Reopened Your Software Supply Chain Blind Spot

Most organizations spent years hardening their software supply chain. The model is familiar: dependencies flow through a controlled repository, policies determine what is allowed, scanning catches what slips through, and every action is logged for auditability. It works because human developers operate within environments that enforce these rules. AI coding agents break that assumption entirely.…
Propagating User Identity From AI Agents to Your Tools: Amazon Bedrock AgentCore Gateway and JFrog Artifactory

Propagating User Identity From AI Agents to Your Tools: Amazon Bedrock AgentCore Gateway and JFrog Artifactory

  Join us at swampUP New York, September 1-3, for our joint session Trusted AI Delivery at Scale: Securing Every Artifact from Curation to Cloud, where we walk the full chain of custody from the moment a package enters your organization to the moment your agent runs on Amazon Bedrock AgentCore. Register here. AI agents…
Frontier AI  Application Security: Every Second Counts

Frontier AI Application Security: Every Second Counts

Somewhere in the last few months, the math of application security quietly broke. Anthropic's Claude Mythos Preview didn't just analyze code, it found a 27-year-old vulnerability in OpenBSD, a 16-year-old bug in FFmpeg, and a 17-year-old remote code execution flaw in FreeBSD, entirely on its own. Then it went further: it built working exploits for…
Inside the ECB’s AI Cyber Directive: What EU Banks Need to Know

Inside the ECB’s AI Cyber Directive: What EU Banks Need to Know

A bank isn’t just a vault holding money. It is an engine powered by implicit public trust, sustained by the continuous confidence that funds remain secure and accessible on demand. When operational risks fail, whether through cyber breaches, system outages, or third-party vulnerabilities, that trust shatters, threatening not just an individual institution, but the stability…
JFrog Artifactory Now Integrates Natively with Artifact Registry in Google Cloud

JFrog Artifactory Now Integrates Natively with Artifact Registry in Google Cloud

Teams running containerized workloads on Google Cloud have long relied on JFrog as their single source of truth for container images. The missing piece has been getting Google Cloud's own runtime services — like Cloud Run and Google Kubernetes Engine (GKE) — to pull directly from JFrog for every container image pull. I’m happy to…
The Secret Sauce of SLSA: DevGovOps at the Speed of Agentic AI

The Secret Sauce of SLSA: DevGovOps at the Speed of Agentic AI

Software supply chain engineering has reached a critical inflection point. As autonomous AI coding agents transition from generating autocomplete suggestions to planning, writing, reviewing, and deploying entire software pipelines without humans in the loop, the connection between human intent and production binaries is fracturing. This shift has created a severe structural deficit across enterprise tech…