Dive Brief:
- Software supply chain platform provider JFrog unveiled new capabilities for its governance tool AppTrust at its annual conference in New York City on Wednesday. The company aims to automate compliance for enterprises wielding agentic code generation at unprecedented speeds, as global regulators tighten software compliance requirements and high-profile AI security incidents seize the news cycle.
- The JFrog platform — which includes AppTrust and JFrog Artifactory, a warehouse for open-source and proprietary code packages — helps enterprises build, manage, govern and distribute software. The new capabilities embed compliance checks into the software development process for continuous monitoring, according to JFrog.
- “With AI, things can change in a day,” JFrog Chief Strategy Officer Gal Marder, told Channel Dive. “Coming quarterly and saying I was compliant two months ago means nothing about today. At the speed that bad things are happening, being noncompliant for a month or two is super dangerous. You cannot allow yourself the risk of not being compliant for such a big thing, for such a long time.”
Dive Insight:
AppTrust’s new capabilities operate in several steps. Companies using the JFrog platform can first codify relevant regulations in plain language, spanning evolving cybersecurity requirements from entities such as the EU Cyber Resilience Act and the National Institute of Standards and Technology in the U.S.
AppTrust then tracks builds, approvals and changes for AI and human code, creating an audit trail with no manual paperwork required, according to JFrog. Pre-codified rules are automatically enforced as software is built, and AppTrust continuously monitors software after customer release, watching for emerging security issues.
“The idea is to cover the full development lifecycle from left to right, everything in the process, with the one goal of being able to trust what you release,” Haggai Schechtman, VP of product and engineering for AppTrust, told Channel Dive. “And again, in the AI era, that's harder to do.”
AI has turned the software development process on its head. Coding agents are writing code at a superhuman speed, sometimes autonomously. But humans still have to be responsible for compliance, Schechtman said.
"You have agents literally running around and doing stuff you didn't ask them to do, because that's what we like about agents and AI," Schechtman said. "They think outside the box and they do whatever goal they were told to achieve. They achieve it, but that means we're losing control about how they're doing it, what they're bringing in."
JFrog has experienced its fair share of AI security incidents. When OpenAI’s agents broke out of a testing environment during the Hugging Face incident, JFrog’s security team helped identify how the bots exploited previously unknown security flaws in their Artifactory software.
“What we saw there was just a glimpse into our new reality,” Marder said. “AI models are going to find more vulnerabilities, and they are going to be weaponized by malicious actors in order to do bad things. The game is changing to a point that to be safe, what you have to do is monitor continuously and be able to react fast.”
In the age of AI, security and compliance is a multi-headed beast. Earlier this week, hackers exploited another critical JFrog Artifactory vulnerability to gain administrative access to the platform.
For channel partners, coding vulnerabilities among enterprises represent several key business opportunities, including building “self-healing” software supply chains and helping companies navigate continuous compliance, according to Marder.
“It's a shared responsibility,” he said. “It's the responsibility of the vendors to provide fixes promptly, and whenever these incidents occur are on-prem environments or self-hosted environments, many of which are managed by channel partners, it will be the channel partner's responsibility to be really quick with applying patches and making sure the environment is safe.”
Marder added that partners should help customers migrate from on-premises to SaaS deployments.
"The liability is too high," he said. "Serious vendors know best how to manage their own environment and to patch their own environment on time. As counterintuitive as it sounds, as a channel partner or as a consultant, I would try to push my customers to go to SaaS and help them build self-healing software chains and move them to continuous compliance.