Home / Companies / JFrog / Blog / Post Details
Content Deep Dive

Governance at the Speed of AI: How DevGovOps Closes the DORA Compliance Gap

Blog post from JFrog

Post Details
Company
Date Published
Author
Nir Peleg, Global Field CISO, JFrog, and Sophie Starchenko, Senior Product Manager, DevGovOps, JFrog
Word Count
1,823
Company Posts That Month
7
Language
English
Hacker News Points
-
Post removed?
No
Summary

DevGovOps is a Software Supply Chain Engineering practice that integrates continuous governance and compliance into the DevOps lifecycle, transforming policy enforcement and auditability from retrospective processes into inherent outputs of every release. This approach addresses the challenges posed by AI-driven development by ensuring a continuous and verifiable chain of custody over software, which is crucial under regulatory mandates such as the Cyber Resilience Act and NIST SSDF. As AI coding agents increasingly handle entire software pipelines, they disrupt traditional accountability structures, necessitating the development of DevGovOps to bridge the gap between engineering, security, and governance. This practice is particularly relevant for compliance with the Digital Operational Resilience Act (DORA), which demands continuous documentation of controls and accountability—a requirement that AI-driven processes can complicate. DevGovOps embeds governance directly into the software delivery pipeline, providing continuous attestation and ensuring that evidence of compliance is automatically generated and retrievable, thus enabling organizations to meet regulatory demands efficiently and effectively.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
AI Coding Assistant 6 807 220 102 -62%
AI Agents 3 3,092 648 191 -49%
Vector Search 2 1,111 224 91 -41%
LLM 1 3,751 612 168 -39%
MCP 1 3,533 369 145 -53%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.