August 2026 Summaries
3 posts from JFrog
Filter
Month:
Year:
Post Summaries
Back to Blog
Agentic Development Security is presented as a practice focused on governing both the assets AI coding agents consume, such as models, MCP servers, plugins, and dependencies, and the code, builds, and releases they produce. The passage argues that detection and remediation are necessary but insufficient without prevention, because organizations can only enforce policies over inventoried and controlled artifacts. It describes JFrog’s platform as a unified system that curates and policy-gates incoming components, inventories AI development tools, intercepts unapproved package downloads, scans generated and open-source code, prioritizes exploitable risks, provides remediation within developer workflows, and enforces release gates. Artifactory is positioned as the central source of truth supporting common policies, audit trails, SBOMs, AI-BOMs, and release evidence across the agentic software supply chain.
Aug 06, 2026
1,207 words in the original blog post.
DevGovOps is presented as a software supply chain engineering discipline designed to embed continuous governance, compliance, auditability, and cryptographic traceability into DevOps pipelines as autonomous AI coding agents accelerate software delivery beyond the pace of traditional manual reviews. It operationalizes frameworks such as SLSA, the EU Cyber Resilience Act, and NIST SSDF through policy-as-code, automated release gates, signed provenance, SBOMs, and ongoing production monitoring, allowing organizations to verify what is in a release, how it was built, and who approved it. SLSA provides progressive standards for automated build documentation, hosted signed builds, and hardened isolated environments, while DevGovOps translates those requirements into enforceable controls across the development lifecycle. The approach is intended to align engineering, application security, and governance teams by reducing manual audit collection, blocking noncompliant artifacts, and providing continuous evidence for regulators and leadership. JFrog AppTrust is described as a platform component that centralizes signed evidence, binds provenance to artifacts, enforces policy gates, and supplies on-demand audit visibility, with the broader argument that dedicated DevGovOps leadership can turn automated compliance from a delivery burden into a business advantage.
Aug 05, 2026
1,496 words in the original blog post.
swampUP, JFrog’s flagship conference, is set to take place from September 1-3 in New York City and will convene leaders and practitioners from fields such as DevOps, DevSecOps, and AI to address the evolving challenges in the software supply chain, particularly the need for integrated trust and governance. As malicious packages and AI assets proliferate, enterprises are urged to shift from outdated manual security systems to automated, trust-based frameworks like JFrog's new Trust Layer, which emphasizes immunization, healing, and governance across the software lifecycle. The conference will feature keynotes from notable industry figures, including JFrog co-founder Yoav Landman, and offer hands-on Training Day sessions to tackle pressing security and compliance questions. Attendees will also have the opportunity to engage with peers and learn from leaders like Jason Clinton and Tim Brown about future directions in software security, as well as participate in the inaugural JFrog Software Supply Chain Excellence Awards and a community gala on the USS Intrepid.
Aug 04, 2026
855 words in the original blog post.