SecurityBrief UK - Technology news for CISOs & cybersecurity decision-makers
United Kingdom
JFrog launches AI-era security tools for software supply

JFrog launches AI-era security tools for software supply

Thu, 3rd Sep 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

JFrog has introduced new software supply chain security and governance products, including DevGovOps functions in AppTrust, agent security controls, Zero-Touch Remediation and an integration with Wiz. The moves reflect rising demand for tighter oversight as AI tools take on more software development work.

The announcements address a common problem for software teams: automated coding tools and autonomous agents can build and ship code far faster than manual security reviews, compliance checks and patching processes can keep up. JFrog aims to close that gap by tying governance, risk scanning and remediation more closely to the software artefacts moving through its platform.

One part of the launch is a new set of DevGovOps features in JFrog AppTrust, designed to automate governance across the software supply chain. These tools are intended to codify policy rules, capture audit evidence automatically, enforce compliance templates and monitor supported production versions after release.

That matters as regulatory pressure on software providers grows. JFrog pointed to frameworks and rules including the EU Cyber Resilience Act, NIST SSDF and FedRAMP, which increasingly require organisations to show evidence of active compliance for supported software versions. Under the CRA, fines can reach up to €15 million or 2.5% of global annual turnover.

Shlomi Ben Haim, Co-Founder and Chief Executive Officer of JFrog, said the issue is no longer whether governance exists, but whether it can keep pace with automated development.

"AI is changing how software gets built and shipped. Autonomous agents are now first-class members of our customers' development teams, committing code and shipping releases at machine speed. The challenge is that governance and compliance still run on human timelines. Governance can't be something you do after the fact, in a spreadsheet or a quarterly audit. It must be built into the release itself," Ben Haim said.

"With JFrog AppTrust, compliance enforcement is automatic. It's not just about policies and code. It's about making sure governance keeps pace with your development velocity, whether your code comes from a human or an agent. That's the next evolution of DevGovOps," he said.

Agent controls

A second part focuses on securing AI coding agents themselves. JFrog's new AgentSecOps functions are designed to ensure agents consume only trusted and scanned artefacts, including software packages, models, plugins, prompts and other AI-related assets.

The additions include scanning for risky or malicious AI assets, a registry for agent plugins, support for the Agent Package Manager standard within Artifactory, and policy controls that can restrict which tools and dependencies an agent is allowed to use inside developer environments.

The premise is that coding agents can now search for, download and install dependencies on their own, sometimes across a wide range of public and private sources. That creates a different risk profile from traditional development, where a human developer remained in the loop.

"AI coding agents not only write software at machine speed but also consume software at scale. The DevSecOps controls we built over a decade assumed a human developer was at the keyboard. Today, that assumption has broken. A software supply chain run by agents doesn't stop for reviews. Agents make decisions about finding and pulling dependencies without a human in the loop, installing traditional packages and AI assets such as skills, context files and MCPs from various sources," said Yoav Landman, Co-Founder and Chief Technology Officer of JFrog.

"To scale agents responsibly and make sure they are compliant, those dependencies must come from a trusted source. The only way to achieve that is by ingraining an intrinsic immune layer directly into the software supply chain that guarantees every input consumed by agents originates from a single, trusted, secure system of record," Landman said.

Automated fixes

JFrog has also launched Zero-Touch Remediation and named the first partners in what it calls its self-healing software supply chain security ecosystem: Broadcom, Chainguard, Echo, IBM/Red Hat, Moderne, TuxCare and Seal Security.

The product is designed to identify an available fix for a known vulnerability from one of those partners and apply it through a customer's pipeline without forcing a version update. The approach is intended to shorten the gap between vulnerability discovery and remediation, particularly where third-party open source components are involved.

Eyal Dyment, Vice President of Security Products at JFrog, said manual patching cycles have become too slow for AI-driven threat environments.

"The traditional security playbook of finding vulnerabilities, opening tickets and waiting weeks for manual patching has become a liability in the frontier AI era. Enterprises now face adversaries who move at agentic speed and regulators who demand provable evidence at every step," Dyment said.

"Our customers need a supply chain that identifies vulnerabilities and remediates them without human intervention as soon as a fix is available, collapsing the remediation SLAs their boards now mandate from weeks to minutes. Zero-Touch Remediation makes that possible. Using Artifactory's role in the organisation as the single source of truth for all artefacts, it consumes every partner fix natively, applies the best available match, serves the fixed version to new builds and attests every action through JFrog AppTrust," he said.

Partner companies described the move as a way to bring tested fixes closer to where software packages are stored and distributed. Patrick Donahue of Chainguard said the integration would allow customers to replace vulnerable dependencies from within JFrog, while Gunnar Hellekson of Red Hat said the industry needs active remediation rather than detection alone.

Runtime view

The fourth announcement is an integration with Wiz, now part of Google Cloud, intended to combine cloud runtime findings with JFrog's software supply chain data. The goal is to help security and engineering teams see which vulnerable workloads are running in production, where the affected software originated and who is responsible for fixing it.

The integration uses an API-based workflow rather than new agents or cluster instrumentation. Wiz identifies exposed workloads in cloud environments, while JFrog links those workloads back to artefacts in Artifactory and enriches them with vulnerability, provenance and ownership data.

Gal Marder, Chief Strategy Officer of JFrog, said the main bottleneck in many organisations is now the manual work required to connect build-time and runtime security data.

"Today's enterprise security teams are caught between two sources of information: AppSec teams see what was built but lose visibility once software ships. Cloud security teams see what is running but lack the supply chain context to understand the real risks," Marder said.

"Our partnership and integration with Wiz solves this by delivering a unified view from build to production, so teams can move from detection to remediation in hours rather than days," he said.

Wiz also commented on the tie-up. "We're happy to collaborate with JFrog to bring cloud runtime visibility and software supply chain context together in one unified view," said Oron Noah, VP of Product, Extensibility & Partnerships at Wiz. "This integration helps customers spend less time on manual correlation and more time remediating risk."