Welcome to the JFrog Blog

All Blogs

Introducing the Global Software Supply Chain Excellence Awards: Celebrating the People Behind the Software Pipelines

Introducing the Global Software Supply Chain Excellence Awards: Celebrating the People Behind the Software Pipelines

Today, JFrog is proud to introduce the Software Supply Chain Excellence Awards, the first-ever customer awards program created to spotlight the teams and individuals who are doing the hard work of securing and scaling modern software delivery. Why We Built This At JFrog, one of our core values is WIN and the belief in achieving…
Introducing Package Traffic Controller: Software Supply Chain Security at the Network Edge

Introducing Package Traffic Controller: Software Supply Chain Security at the Network Edge

Imagine this: your security team has done everything right. All development teams are using a centrally managed artifact repository with scanning in place. Your engineering organization has clear policies about where packages can come from. You feel good about your software supply chain posture. Then an incident review surfaces something nobody planned for: a compromised…
The Governance Gap Between Your Policy and Your Pipeline

The Governance Gap Between Your Policy and Your Pipeline

Security teams are under more pressure than ever, and most of them believe they're keeping up. That confidence, it turns out, may be the most consequential finding in the JFrog 2026 Software Supply Chain Security State of the Union. Across 18.2 billion artifacts analyzed, independent vulnerability research from the JFrog Security Research team, and a…
The Agent Has Entered the Supply Chain

The Agent Has Entered the Supply Chain

Software Delivery in the Age of Agents The way software gets built has fundamentally shifted. AI coding agents are no longer just autocomplete on steroids; they're resolving packages, configuring environments, selecting tools, and in some cases running the entire development lifecycle, with or without a human in the loop. But here's the problem: the tools…
Keep your Agents Under Control with agent-belt

Keep your Agents Under Control with agent-belt

You're shipping a product with an AI-facing interface, or embedding AI-facing interfaces across your existing product line - skills your customers trigger, MCP servers their agent reaches for. Indie author or enterprise, your code runs in someone else's agent runtime, against a model that updates every other day and a CLI that updates every other…
Accelerating AI Agent Development on Google Cloud with JFrog MCP Registry

Accelerating AI Agent Development on Google Cloud with JFrog MCP Registry

Developers building agentic AI on Google Cloud have powerful infrastructure at their fingertips: Gemini 3 for reasoning, Google’s Agent Development Kit (ADK) for orchestration, and a rapidly expanding ecosystem of Model Context Protocol (MCP) servers that connect agents to data and tools. So why are so many teams still waiting weeks to ship their first…
Building a Governed AI Model Supply Chain: Integrating AWS SageMaker and the JFrog Platform

Building a Governed AI Model Supply Chain: Integrating AWS SageMaker and the JFrog Platform

Amazon SageMaker accelerates the process of training and deploying machine learning models. However, as AI adoption scales from individual experiments to enterprise-wide production, the focus of leading Fortune 500 software development operations and security teams must shift from pure velocity to governance. The question is no longer just "Can we ship this model?" but "How…