{
  "id": 5136292,
  "title": "JFrog Moves to Secure Agentic Engineering Workflows",
  "url": "https://urgent.news/2026/09/02/jfrog-moves-to-secure-agentic-engineering-workflows",
  "topic": "ai",
  "section": "AI",
  "published": "2026-09-02T16:01:45.000Z",
  "source": {
    "name": "DevOps.com",
    "slug": "devops-com",
    "url": "https://devops.com/jfrog-moves-to-secure-agentic-engineering-workflows/"
  },
  "original_language": "en",
  "account": "At the JFrog swampUP 2026 conference, the company unveiled a suite of tools aimed at bolstering security in agentic engineering workflows. The newly introduced zero touch remediation feature ensures the most secure binary version is provided to developers, even when they request one with known vulnerabilities. JFrog is also integrating security measures to protect AI agents embedded within DevOps processes. A new AI Asset Scanning tool leverages semantic scanning techniques to detect and block malicious behavior in markdown files, skills scripts, and other AI-related components. Additionally, an Agent Guard extension safeguards JFrog's Artifactory registry by enforcing project-specific allow/deny policies for AI coding agents, ensuring adherence to organizational guidelines. JFrog has also incorporated support for Microsoft's Agent Package Manager (APM), a dependency manager for AI agents that authenticates agents and establishes a trusted path for resolving package dependencies through JFrog Artifactory. The company is further partnering with Cloudflare, Netskope, and Zscaler to leverage their Traffic Controller in blocking public registry calls and routing traffic through Artifactory. At the same time, JFrog is collaborating with Google Cloud's Wiz unit, providing DevSecOps teams with a unified view of running components, their origins, trust levels, and remediation steps. Furthermore, JFrog is expanding JFrog AppTrust, a framework for enforcing policies across the software development lifecycle, by enabling DevSecOps teams to create policies-as-code using an AI-powered tool. Additionally, the company offers compliance templates with pre-built rules aligned to regulatory standards, automatically enforced with a single click, and a monitoring system that flags compliance issues post-deployment. JFrog CTO Yoav Landman emphasized that these capabilities collectively enable JFrog to protect artifacts by limiting AI agent actions, remediate issues, and govern artifact deployments, all without human intervention. The overarching objective is to identify vulnerabilities promptly and remediate them before they can be exploited, thereby eliminating the need for manual intervention to avoid broken builds.",
  "summary": "JFrog today at its swampUP 2026 conference added a zero touch remediation capability that ensures the most secure version of a binary is provided even when application developers request a version that has known vulnerabilities. Additionally, JFrog is adding tools and capabilities to secure artificial intelligence (AI) agents that have been embedded within a DevOps […]",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}