September 2026 Summaries
6 posts from JFrog
Filter
Month:
Year:
Post Summaries
Back to Blog
JFrog announced Out-of-the-Box Compliance Frameworks for its AppTrust platform at swampUP 2026, aiming to replace audit-driven, point-in-time compliance efforts with continuous governance embedded in software delivery. Initially supporting NIST SSDF and the EU Cyber Resilience Act, the feature pre-maps regulatory controls to enforceable Policy-as-Code rules, allowing AppSec teams to activate frameworks without writing Rego policies or manually translating requirements. AppTrust identifies covered and uncovered controls, uses artifact-based production data to maintain current compliance coverage, and provides traceability across AI-agent activity, commits, pull requests, Jira tickets, and shipped artifacts. The platform separates responsibility between AppSec teams, which manage applicable controls and rules, and development managers, which control application rollout and enforcement timing. JFrog positions the offering as a response to growing regulatory demands, faster AI-assisted software development, audit-evidence challenges, and potential EU CRA penalties and personal liability for security leaders; it is available through the Ultimate Security Bundle, with further frameworks under development.
Sep 02, 2026
1,117 words in the original blog post.
swampUP 2026 opened in New York City on September 2 with JFrog co-founder and CEO Shlomi Ben Haim framing the conference around rebuilding trust in a software supply chain increasingly shaped by autonomous AI. The three-day event focuses on how agents are progressing from coding assistants to systems that can write code, resolve dependencies, and produce binaries at machine speed, changing both software creation and accountability. Ben Haim argued that the industry is now centered on binaries and that everyone involved in building software participates in the “binaries business,” while emphasizing that human responsibility is increasingly focused on establishing trust in the outputs generated across this evolving supply chain.
Sep 02, 2026
222 words in the original blog post.
AI coding agents are accelerating software development by autonomously planning, writing, reviewing, and deploying code, challenging compliance models built around identifiable human approvals and slower release cycles. The passage argues that regulations including the EU Cyber Resilience Act, NIST SSDF, DORA, and FedRAMP increasingly require organizations to demonstrate continuous control over their software supply chains, particularly as AI-enabled threats and vulnerabilities can spread rapidly. It proposes DevGovOps as an approach that embeds governance directly into delivery pipelines through machine-readable policies, automatically captured cryptographic attestations, automated enforcement, and continuous post-release monitoring. JFrog positions its AppTrust platform as an implementation of this model, using Artifactory to attach provenance, ownership, risk, and compliance evidence to software artifacts, with capabilities for AI policy testing, prompt-to-release traceability, pre-mapped compliance frameworks, and post-release governance.
Sep 02, 2026
1,095 words in the original blog post.
JFrog positions its expanded AI Catalog as an AI control plane designed to secure the Agentic Development Lifecycle, where coding agents dynamically assemble models, MCP servers, skills, plugins, hooks, rules, and agent packages from potentially unvetted sources. The company argues that traditional software security controls and signature-based scans cannot adequately detect emerging threats such as malicious MCP packages and skills, which can execute harmful instructions while evading known-malware detection. The platform stores AI assets as versioned, traceable artifacts in Artifactory and adds dedicated registries for MCP servers, skills, plugins, and agent packages, alongside semantic scanning intended to inspect an asset’s instructions and shadow-AI detection for unmanaged assets. JFrog also describes runtime policy enforcement through agent plugins and Agent Guard, which restrict asset installations and MCP or skill calls across coding environments such as Claude Code, Cursor, VS Code, OpenCode, and Codex. By integrating AI governance with its existing software supply-chain tooling, RBAC, and audit records, JFrog aims to ensure that enterprise agents can access only organization-approved AI assets without requiring a separate AI security system.
Sep 02, 2026
1,478 words in the original blog post.
JFrog announced Prompt to Release Traceability for its AppTrust platform at swampUP 2026, aiming to address the difficulty of compiling compliance evidence scattered across source control, ticketing, approval, and deployment systems. The feature automatically collects, connects, signs, timestamps, and attaches Git commits, pull requests, Jira ticket transition histories, and approver records to each application release before promotion gates run, including checks for potential self-approval. JFrog argues that AI-assisted development expands the evidence gap because conventional DevOps records do not capture agent prompts, decisions, or tools used during coding sessions; forthcoming Agent Plugins are intended to record these interactions and a session bill of materials in Artifactory. The company says the capability can reduce audit-evidence assembly from weeks to minutes and supports its newly announced pre-mapped compliance controls for NIST SSDF and the EU Cyber Resilience Act. Git, pull request, Jira, and approver-chain data are generally available now, while agent-session evidence is planned for later in the year.
Sep 02, 2026
807 words in the original blog post.
No summary generated yet.
Sep 02, 2026
2,663 words in the original blog post.