09/09/2025 | Press release | Distributed by Public on 09/09/2025 07:10
Unifying proof from GitHub, ServiceNow, Sonar, and more, JFrog AppTrust delivers a trusted single source of truth for faster, more reliable, compliant software releases
Sunnyvale and Napa Valley, Calif. - swampUP 2025 - September 9, 2025 - JFrog Ltd. ("JFrog") (NASDAQ: FROG), the Liquid Software company and creators of the JFrog Software Supply Chain Platform, today announced its first set of Evidence Ecosystem partners to be included in JFrog AppTrust. Customers can now collectively create a centralized, trusted audit trail with clear attestations across the software development lifecycle, helping increase visibility, eliminate risk, and ensure release readiness, gaining greater confidence in each delivery.
"To enable the agentic AI revolution in software delivery, wherein every agent will require proof before moving forward with any release, organizations need a clear, auditable single source of truth of their software delivery process," said Gal Marder, Chief Strategy Officer, JFrog. "Together with our partners, we're providing a trusted, DevGovOps solution for collecting cryptographically verifiable evidence and applying compliance policies. By verifying these policies across the software supply chain, organizations can confidently deliver trustworthy, compliant, secure applications in the agentic AI era."
CISOs and DevSecOps leaders face immense pressure to meet high standards of formal as well as internal regulations and security requirements amid rapid software delivery demands. In the accelerating world of AI, automation of GRC will become more demanding, placing more complexity on delivery teams. Non-compliance poses risks to the trust of customers in the software being shipped, as well as fines, reputational damage, and legal issues. Relying on homegrown solutions and manual processes for software provenance is unsustainable, easy to challenge and wastes precious developer time. Evidence Collection within the JFrog Platform generates a comprehensive audit trail that helps customers:
To extend the richness of its evidence collection capabilities, JFrog is partnering with a dozen software leaders to create out-of-the-box evidence integrations, empowering organizations to consolidate SDLC process data into a single source of truth-crucial for GRC efforts in an era of rising security risks and regulatory scrutiny. JFrog's initial group of Evidence Ecosystem partners will collect and share important software attestations such as:
"As AI accelerates the pace of software development, developers and their organizations are struggling to ensure the highest levels of code quality and code security," said Tariq Shaukat, CEO of Sonar. "Sonar's partnership with JFrog addresses this challenge by integrating SonarQube's industry-leading code analysis with JFrog Evidence, allowing for validated verification of all code, whether AI-generated or developer-written. By working together, we are enabling organizations to build high-quality, compliant software that fully embraces the speed of AI-driven development."
Companies interested in learning more about JFrog Evidence and how it works with JFrog AppTrust should read this blog, visit our product page, or register for the "AppTrust, AI Catalog and more" webinar on October 9 at 9 AM PT. For more information on how to join JFrog's AppTrust evidence partner ecosystem visit https://jfrog.com/about/become-a-partner/.
###
Like this Story? Tweet this: In the agentic AI era, every agent must have verifiable proof before proceeding with a release. @JFrog AppTrust and its evidence ecosystem provides a trusted, auditable, single source of truth for the entire SDLC, ensuring transparency, control, and confidence at every step. Learn more https://bit.ly/45U9Ewr #DevSecOps #security #softwaresupplychain
About JFrog
JFrog Ltd. (Nasdaq: FROG), the creators of the unified DevOps, DevSecOps and MLOps platform, is on a mission to create a world of software delivered without friction from developer to production. Driven by a "Liquid Software" vision, the JFrog Software Supply Chain Platform is a single system of record that powers organizations to build, manage, and distribute software quickly and securely, that is available, traceable, and tamper-proof. Integrated security features also help identify, protect, and remediate against threats and vulnerabilities. JFrog's hybrid, universal, multi-cloud platform is available as both SaaS services across major cloud service providers and self-hosted. Millions of users and 7K+ customers worldwide, including a majority of the Fortune 100, depend on JFrog solutions to securely embrace digital transformation. Learn more at https://www.jfrog.com or follow us on X @JFrog.
This press release contains "forward-looking" statements, as that term is defined under the U.S. federal securities laws, including, but not limited to, statements regarding our expectations with respect to the anticipated performance of the JFrog AppTrust Evidence Ecosystem, and the ability of JFrog and its partners to successfully collect and share software attestations.
These forward-looking statements are based on our current assumptions, expectations and beliefs and are subject to substantial risks, uncertainties, assumptions and changes in circumstances that may cause JFrog's actual results, performance or achievements to differ materially from those expressed or implied in any forward-looking statement. There are a significant number of factors that could cause actual results, performance or achievements to differ materially from statements made in this press release, including but not limited to risks detailed in our filings with the Securities and Exchange Commission, including in our annual report on Form 10-K for the year ended December 31, 2024, our quarterly reports on Form 10-Q, and other filings and reports that we may file from time to time with the Securities and Exchange Commission. Forward-looking statements represent our beliefs and assumptions only as of the date of this press release. We disclaim any obligation to update forward-looking statements except as required by law.
Media Contact:
Siobhan Lyons, Director, Global Communications, JFrog, [email protected]
Investor Contact:
Jeff Schreiner, VP of Investor Relations, JFrog, j[email protected]