Welcome to the JFrog Blog

All Blogs

JFrog Artifactory Now Integrates Natively with Artifact Registry in Google Cloud

JFrog Artifactory Now Integrates Natively with Artifact Registry in Google Cloud

Teams running containerized workloads on Google Cloud have long relied on JFrog as their single source of truth for container images. The missing piece has been getting Google Cloud's own runtime services — like Cloud Run and Google Kubernetes Engine (GKE) — to pull directly from JFrog for every container image pull. I’m happy to…
The Secret Sauce of SLSA: DevGovOps at the Speed of Agentic AI

The Secret Sauce of SLSA: DevGovOps at the Speed of Agentic AI

Software supply chain engineering has reached a critical inflection point. As autonomous AI coding agents transition from generating autocomplete suggestions to planning, writing, reviewing, and deploying entire software pipelines without humans in the loop, the connection between human intent and production binaries is fracturing. This shift has created a severe structural deficit across enterprise tech…
Scale Your Engineering Organization Without Losing Control

Scale Your Engineering Organization Without Losing Control

Growing engineering organizations all hit the same wall. More teams shipping software means more repositories, more permission requests, more onboarding cycles, and eventually one platform admin fielding every change. The platform that was supposed to accelerate delivery has now become the bottleneck. JFrog Projects is built to break that pattern. It's the organizational structure that…
Fast Remediation Is the New Trust Model: JFrog and OpenAI Collaboration on Zero-Day Security Findings

Fast Remediation Is the New Trust Model: JFrog and OpenAI Collaboration on Zero-Day Security Findings

UPDATE August 5, 2026: This week at Black Hat USA, the OpenAI team presented a detailed reconstruction of the chain of events behind the Hugging Face incident. I was glad to watch OpenAI speaking openly about it. This kind of transparency reflects the same spirit of collaboration we experienced working with their team behind the…
Why Model Routing Backfires and How to Build Agents That Don’t Burn Your Budget

Why Model Routing Backfires and How to Build Agents That Don’t Burn Your Budget

Model routing promises to cut your AI agent spend by offloading routine tasks to cheaper models like Claude Haiku while reserving frontier models like Claude Sonnet for complex reasoning. In the right configuration, routing strategies can reduce inference costs by 40–85%. But if you implement routing incorrectly in a multi-turn agent, you can end up…
The Perfect Heist: NuGet Typosquat Targets Betting Platform to Rig Results

The Perfect Heist: NuGet Typosquat Targets Betting Platform to Rig Results

The JFrog Security Research team has discovered and disclosed a typosquatted NuGet package named Newtonsoftt.Json.Net. Note the double t and the .Net suffix.  This package has been masquerading as the popular Newtonsoft.Json library while quietly shipping a trojanized fork. The trojan rigs Digitain, an online betting platform, and in later generations, exfiltrates rigged round results…