Welcome to the JFrog Blog

All Blogs

Live From the Show Floor: swampUP 2026

Live From the Show Floor: swampUP 2026

Live updates from this event have concluded. swampUP 2026 is officially LIVE in New York City! Three days, one stage, one mission: rebuild trust for a software supply chain that increasingly ships itself. Keynote updates land here as they happen, September 1–3, 2026. Let’s go! Conference Day 2, September 3rd [11:00 a.m.] The Great Model…
DevGovOps: How the AI Era Dictates That Governance Lives inside the Pipeline

DevGovOps: How the AI Era Dictates That Governance Lives inside the Pipeline

For decades, proving compliance meant having a person behind every decision - an engineer who remembered the approval, an auditor who could call someone and get an answer. That model worked because humans wrote, reviewed, and shipped every line of code. When agents do it instead, that dependency breaks. And so does your ability to…
The Evolution of JFrog AI Catalog: Your AI Control Plane for Agentic Development

The Evolution of JFrog AI Catalog: Your AI Control Plane for Agentic Development

In a single morning, a coding agent can pull an open-source model, connect to an unvetted MCP server, and execute a code-optimizing skill from the web. In the rush toward agentic automation, these AI assets quietly bypass traditional security reviews, creating new attack vectors across the software supply chain. Closing this blind spot has been…
Securing the Australian Government Software Supply Chain: JFrog Completes Protected Level IRAP Assessment

Securing the Australian Government Software Supply Chain: JFrog Completes Protected Level IRAP Assessment

JFrog has reached a major milestone: An IRAP assessment at the Protected level, across the full JFrog Platform. Conducted by CyberCX, an Australian Signals Directorate (ASD)-endorsed assessor, against the ISM, it independently validates that the platform managing an agency’s software supply chain meets the bar for Australia’s most sensitive workloads. It reasserts a commitment that…
Coding Agents Just Reopened Your Software Supply Chain Blind Spot

Coding Agents Just Reopened Your Software Supply Chain Blind Spot

Most organizations spent years hardening their software supply chain. The model is familiar: dependencies flow through a controlled repository, policies determine what is allowed, scanning catches what slips through, and every action is logged for auditability. It works because human developers operate within environments that enforce these rules. AI coding agents break that assumption entirely.…
Propagating User Identity From AI Agents to Your Tools: Amazon Bedrock AgentCore Gateway and JFrog Artifactory

Propagating User Identity From AI Agents to Your Tools: Amazon Bedrock AgentCore Gateway and JFrog Artifactory

  Join us at swampUP New York, September 1-3, for our joint session Trusted AI Delivery at Scale: Securing Every Artifact from Curation to Cloud, where we walk the full chain of custody from the moment a package enters your organization to the moment your agent runs on Amazon Bedrock AgentCore. Register here. AI agents…
Frontier AI  Application Security: Every Second Counts

Frontier AI Application Security: Every Second Counts

Somewhere in the last few months, the math of application security quietly broke. Anthropic's Claude Mythos Preview didn't just analyze code, it found a 27-year-old vulnerability in OpenBSD, a 16-year-old bug in FFmpeg, and a 17-year-old remote code execution flaw in FreeBSD, entirely on its own. Then it went further: it built working exploits for…