
JFrog Unveils AI Software Supply Chain Controls at swampUP 2026
MarketBeat
公開日時: Sep 02, 2026, 11:03 PM
Sentiment Analysis
JFrog unveiled new AI-focused software supply-chain controls at swampUP 2026, including Package Traffic Controller, expanded Artifactory support for AI-generated assets, vulnerability remediation, and integrations with Zscaler, Netskope, Cloudflare, and Wiz. AppTrust is positioned as an automated, continuous-compliance platform.
Customer Keysight Technologies said it selected AppTrust to reduce manual compliance work, catalog software artifacts and bills of materials, and address governance challenges intensified by AI coding tools. JFrog is positioning Artifactory as a “system of trust” and AI control plane by controlling which packages agents can access, preserving release metadata, and governing the growing volume of software binaries created by AI agents.
JFrog used its swampUP 2026 investor session to outline product updates aimed at securing, remediating and governing software supply chains as enterprises deploy more AI-assisted development tools. Executives also discussed customer adoption of its AppTrust governance offering, integrations with security providers and the company’s approach to managing AI-generated software artifacts. The company framed its strategy around three themes: “protect, remediate, and control.” The event’s operator highlighted the Package Traffic Controller, integrations with SASE providers including Zscaler and Netskope, expanded support in Artifactory for AI-related assets, a Wiz integration, zero-touch vulnerability remediation capabilities and enhancements to AppTrust.
Christophe Romatier, chief information security officer at Keysight Technologies, said the test, measurement and design-solutions company has increased its software development activity and use of AI. Keysight has about 5,000 developers, according to Romatier, and its DevSecOps organization also oversees internal AI initiatives. Romatier said governance has become both a security and compliance issue, as well as a developer productivity concern. He cited the Secure Software Development Framework and the European Union’s Cyber Resilience Act as regulations that require organizations to catalog artifacts and software bills of materials alongside products.
“We don’t really want [developers] spending time capturing compliance or filling in compliance checklists,” Romatier said. “We want our developers writing code.” Keysight selected JFrog AppTrust after identifying a manual process for capturing and archiving compliance materials that was slowing research and development work, he said. Since Keysight had used JFrog Artifactory for years, the company viewed compliance evidence as another class of artifact that could reside alongside binaries and follow products through their release lifecycle. Romatier said AI coding tools increased the urgency to automate governance. Without automation, Keysight would have needed to devote more developer time to compliance activities or hire additional personnel, he said. Looking ahead, he said Keysight intends to apply governance across its applications rather than maintain separate processes for higher-sensitivity software. “Once you’ve done the work to automate the tasks that need to occur on every build, on every release, it’s no longer a question of, do I only want to apply it to this area?” Romatier said. He added that Keysight is working toward a regulatory compliance milestone in October of the following year.
Source: MarketBeat
個別の投資に関する推奨やアドバイスを提供することを意図しておりません。ここで述べられている意見や見解は、あくまでも各記事の個人的見解です。