Welcome to the JFrog Blog

All Blogs

JFrog Artifactory Supports LuaRocks Hosting for NGINX, OpenResty and Kong

JFrog Artifactory Supports LuaRocks Hosting for NGINX, OpenResty and Kong

If your NGINX/OpenResty servers or Kong gateways pull Lua modules straight from public luarocks.org, one upstream outage can stall every build and deploy that depends on a “rock”. With LuaRocks support in JFrog Artifactory, you host and proxy those modules from a private LuaRocks registry you control, using the native experience you expect, not a…
Extending the Single Source of Truth to the Agentic Software Supply Chain

Extending the Single Source of Truth to the Agentic Software Supply Chain

Every developer on your team now runs multiple agents. None of them are waiting for human sign-off to act. That's exactly the gap we discussed and closed at swampUP 2026. JFrog unveiled new capabilities that extend the JFrog Platform as not only the Single Source of Truth for OSS and heritage software, but now the…
Live From the Show Floor: swampUP 2026

Live From the Show Floor: swampUP 2026

Live updates from this event have concluded. swampUP 2026 is officially LIVE in New York City! Three days, one stage, one mission: rebuild trust for a software supply chain that increasingly ships itself. Keynote updates land here as they happen, September 1–3, 2026. Let’s go! Conference Day 2, September 3rd [11:00 a.m.] The Great Model…
Every New Compliance Framework Restarts the Same Fire Drill. It Doesn’t Have To.

Every New Compliance Framework Restarts the Same Fire Drill. It Doesn’t Have To.

Every compliance audit starts the same way: Someone flags a deadline, the team scrambles to pull evidence, map controls, and prove that the policies running in production actually match what the framework requires. They make it through. They exhale. Six months later, a new framework arrives, and the fire drill starts all over again. Most…
DevGovOps: How the AI Era Dictates That Governance Lives Inside the Pipeline

DevGovOps: How the AI Era Dictates That Governance Lives Inside the Pipeline

For decades, proving compliance meant having a person behind every decision - an engineer who remembered the approval, an auditor who could call someone and get an answer. That model worked because humans wrote, reviewed, and shipped every line of code. When agents do it instead, that dependency breaks. And so does your ability to…
The Evolution of JFrog AI Catalog: Your AI Control Plane for Agentic Development

The Evolution of JFrog AI Catalog: Your AI Control Plane for Agentic Development

In a single morning, a coding agent can pull an open-source model, connect to an unvetted MCP server, and execute a code-optimizing skill from the web. In the rush toward agentic automation, these AI assets quietly bypass traditional security reviews, creating new attack vectors across the software supply chain. Closing this blind spot has been…