Monday, 22 December 2025
27 C
Singapore
16.6 C
Thailand
26.5 C
Indonesia
26.5 C
Philippines

JFrog launches AppTrust to strengthen software release governance

JFrog introduces AppTrust, a governance solution that improves compliance, security, and trust in enterprise software releases.

JFrog has introduced AppTrust, a new solution designed to help enterprises improve governance across their software supply chains. Announced at swampUP 2025 in California on 9 September, the platform aims to address growing concerns around compliance, security, and trust in application releases.

Addressing the compliance challenge

As software development accelerates, organisations are facing increasing pressure to balance speed with regulatory compliance and security. JFrog said AppTrust provides a single system of record that captures evidence, enforces policies, and offers contextual insights into software assets. This allows development, security, and operations teams to collaborate more effectively while ensuring applications meet quality and compliance standards.

“Software is being released faster than ever, and secure updates have become the fuel powering today’s world,” said Shlomi Ben Haim, JFrog’s CEO and co-founder. “Our customers tell us that after DevOps and DevSecOps, the next big challenge is compliance. That’s why ‘DevGovOps’ must happen. With JFrog AppTrust, every release is trusted, verified, and ready for production at scale.”

AppTrust integrates with the ServiceNow AI Platform, enabling organisations to align governance with IT operations. It automates quality gates, validates evidence, and provides visibility across software dependencies, ownership, and potential risks.

Features and ecosystem partnerships

JFrog highlighted several key capabilities of AppTrust. These include automated policy enforcement through governance, risk and compliance controls; assigning assets to applications with clear ownership and context; and promotion gates that regulate how software progresses from development to release. The platform also provides an open infrastructure for storing signed evidence, alongside insights that use DORA and other metrics to identify bottlenecks and improve delivery efficiency.

Rahul Tripathi, GVP and GM of IT Service Management at ServiceNow, said: “Modern software governance depends on bringing together the right data – from development through operations – to make informed, auditable decisions at scale. With ServiceNow’s insights integrated into the JFrog ecosystem, organisations can extend visibility and control even further across their software supply chain.”

JFrog is also working with a network of partners to strengthen evidence collection across the development lifecycle. Current partners include Akto, Akuity, CoGuard, Dagger, GitHub, Gradle, NightVision, ServiceNow, Shipyard, Sonar, and Troj.ai, with more expected to join.

“As the leading provider of automated, independent code review for AI and developer-written code, SonarQube plays a vital role in helping companies achieve their governance objectives,” said Tariq Shaukat, CEO of Sonar. “We are excited to partner with JFrog to integrate SonarQube’s industry-leading findings as an additional validated source of evidence in the JFrog Platform.”

Building trust across the supply chain

Industry experts view JFrog AppTrust as an important step in bridging the gap between rapid software delivery and governance. Jim Mercer, Program Vice President of Software Development, DevOps, and DevSecOps at IDC, noted: “Organisations struggling to secure their software supply chains can benefit from these new capabilities, making practices like attestation and provenance more achievable.”

By providing application-context asset assignment, promotion gating, dependency mapping, and vulnerability analysis, AppTrust seeks to reduce the friction that has traditionally existed between development, security, and compliance teams. JFrog said the platform allows organisations to maintain application quality and performance without slowing down innovation, helping them deliver software that is secure, compliant, and ready for production.

Hot this week

Antler invests US$5.6 million across 14 AI startups with early commercial traction

Antler invests US$5.6 million in 14 AI startups with early traction, focusing on applied AI and real-world enterprise adoption.

The rise of agentic AI and what it means for enterprise leaders

Agentic AI is accelerating across Asia, pushing leaders to rethink productivity, governance, and the infrastructure needed for long-term competitiveness.

The Oscars to stream exclusively on YouTube in 2029

The Oscars will stream exclusively on YouTube from 2029, signalling a major shift in how the iconic awards reach global audiences.

Cybersecurity threats and AI disruptions top concerns for IT leaders in 2026, Veeam survey finds

Veeam survey finds cybersecurity and AI risks dominate IT leaders’ concerns for 2026, with data resilience and sovereignty rising in priority.

Huawei unveils Mate X7 foldable phone for global markets

Huawei unveils the global Mate X7 foldable phone in Dubai, detailing design updates, camera improvements, software limits and premium pricing.

Google delays Gemini takeover from Assistant on Android until 2026

Google has delayed replacing Google Assistant with Gemini on Android, extending the transition into 2026 as technical challenges persist.

Valve ends production of its last Steam Deck LCD model

Valve ends production of its last Steam Deck LCD model, leaving OLED versions as the only option and raising the entry price for new buyers.

Sony and Honda’s first electric car brings PlayStation Remote Play on the road

Sony and Honda’s Afeela EV will support PlayStation Remote Play, letting passengers stream PS5 and PS4 games to the car’s display.

Samsung unveils Exynos 2600 as first 2nm mobile processor

Samsung unveils the Exynos 2600, the world’s first 2nm mobile chip, expected to debut in the Galaxy S26 in early 2026.

Related Articles

Popular Categories