09/09/2025 | Press release | Distributed by Public on 09/09/2025 06:22
Software supply chains are the #1 attack vector for cybercriminals, and the challenge isn't just finding vulnerabilities; it's fixing them fast while ensuring security, compliance, and developer productivity. As supply chains grow in complexity, traditional tools aren't enough; organizations need intelligent, autonomous assistance embedded directly into developer workflows.
We are pleased to announce that JFrog is introducing Agentic Software Supply Chain Security to help organizations reduce risk, cut costs, and accelerate delivery. By combining JFrog's trusted platform with AI-driven automation, development teams can shift from reactive security practices to proactive, agentic software supply chain security, curating safer software packages, remediating CVEs, and coding with confidence.
Agentic Software Supply Chain Security is a culmination of various tools and capabilities within JFrog Software Supply Chain Platform as well as integrations with external partners, and includes JFrog Catalog, Curation, SAST, GitHub Copilot, and VSCode. Here's how they all work together to shift development teams from reactive security practices to proactive, agentic security.
Open source is the foundation of modern software, but with millions of packages and varying license obligations, curating safe and compliant dependencies can be daunting.
With JFrog Catalog & Curation, developers can now build with confidence. AI-powered agents, connected to JFrog security solutions via the JFrog remote MCP (Model Context Protocol), analyze package metadata, security posture, and compliance with organization policies, helping teams select the best open-source libraries at speed. By ensuring developers can only use the safest, policy-compliant packages, teams avoid failed builds from vulnerabilities and keep CI/CD pipelines running smoothly, shortening release cycles and accelerating delivery.
The result: faster innovation without sacrificing security or governance.
Security shouldn't slow developers down. Instead, it should meet them in the IDE, during coding, in a way that promotes frictionless innovation.
JFrog SAST surfaces source code vulnerabilities directly in the IDE. With agentic remediation, developers get contextual, friendly, and actionable AI-suggested code changes in real-time so that they don't have to sift through security logs or reports. The JFrog local SAST MCP connects the JFrog Platform to your chosen AI agent. The agent gets insights from the SAST engine, which scans the codebase and generates SAST findings.
This ensures teams aren't just finding problems, but are continuously writing secure code by default.
Vulnerabilities in open-source dependencies (CVEs) remain one of the most exploited attack vectors in the software supply chain. Identifying them is only half the battle; the real challenge is remediating them quickly and accurately.
The "Ask Copilot to Fix" feature is part of our VSCode extension and automatically suggests or applies patches, dependency upgrades, or safe alternatives. The "Ask Copilot to Fix" action can be triggered for various security findings, including those from SAST, Secrets Scanning, and IaC. This makes remediation seamless, efficient, and integrated directly into the developer experience.
Instead of overwhelming teams with alerts, JFrog empowers them with autonomous, agentic remediation that keeps the supply chain secure without slowing delivery.
JFrog helps teams shift from reactive to proactive agentic security. With JFrog's deep security research at its core, the JFrog platform ensures comprehensive protection and actionable intelligence. By connecting AI agents to the JFrog platform via MCP servers, and by using the JFrog VSCode plugin, developers gain:
This isn't just an AI assistant; it's agentic, autonomous remediation that transforms DevSecOps into a self-healing software supply chain. Unlike point solutions, JFrog delivers:
With JFrog, organizations can move from reactive patching to proactive, autonomous, and continuous security.
Here are the outcomes organizations can expect with Agentic Software Supply Chain Security from JFrog.
The future of DevSecOps isn't just about shifting left, it's about agentic AI: autonomous security that works as fast as your developers.
With agentic AI capabilities embedded across the JFrog Platform, developers gain:
By combining trusted DevSecOps foundations with autonomous AI agents, JFrog is making Agentic Software Supply Chain Security a reality, helping organizations deliver secure, reliable, and compliant software at the pace of innovation. To learn more, schedule a demo, take a JFrog Trial or head over to the GitHub Marketplace to connect your GitHub and JFrog instances to enjoy AI-assisted, secure coding.