Wednesday, 10 September 2025
30.4 C
Singapore
31.9 C
Thailand
22.2 C
Indonesia
27.7 C
Philippines

JFrog launches AppTrust to strengthen software release governance

JFrog introduces AppTrust, a governance solution that improves compliance, security, and trust in enterprise software releases.

JFrog has introduced AppTrust, a new solution designed to help enterprises improve governance across their software supply chains. Announced at swampUP 2025 in California on 9 September, the platform aims to address growing concerns around compliance, security, and trust in application releases.

Addressing the compliance challenge

As software development accelerates, organisations are facing increasing pressure to balance speed with regulatory compliance and security. JFrog said AppTrust provides a single system of record that captures evidence, enforces policies, and offers contextual insights into software assets. This allows development, security, and operations teams to collaborate more effectively while ensuring applications meet quality and compliance standards.

“Software is being released faster than ever, and secure updates have become the fuel powering today’s world,” said Shlomi Ben Haim, JFrog’s CEO and co-founder. “Our customers tell us that after DevOps and DevSecOps, the next big challenge is compliance. That’s why ‘DevGovOps’ must happen. With JFrog AppTrust, every release is trusted, verified, and ready for production at scale.”

AppTrust integrates with the ServiceNow AI Platform, enabling organisations to align governance with IT operations. It automates quality gates, validates evidence, and provides visibility across software dependencies, ownership, and potential risks.

Features and ecosystem partnerships

JFrog highlighted several key capabilities of AppTrust. These include automated policy enforcement through governance, risk and compliance controls; assigning assets to applications with clear ownership and context; and promotion gates that regulate how software progresses from development to release. The platform also provides an open infrastructure for storing signed evidence, alongside insights that use DORA and other metrics to identify bottlenecks and improve delivery efficiency.

Rahul Tripathi, GVP and GM of IT Service Management at ServiceNow, said: “Modern software governance depends on bringing together the right data – from development through operations – to make informed, auditable decisions at scale. With ServiceNow’s insights integrated into the JFrog ecosystem, organisations can extend visibility and control even further across their software supply chain.”

JFrog is also working with a network of partners to strengthen evidence collection across the development lifecycle. Current partners include Akto, Akuity, CoGuard, Dagger, GitHub, Gradle, NightVision, ServiceNow, Shipyard, Sonar, and Troj.ai, with more expected to join.

“As the leading provider of automated, independent code review for AI and developer-written code, SonarQube plays a vital role in helping companies achieve their governance objectives,” said Tariq Shaukat, CEO of Sonar. “We are excited to partner with JFrog to integrate SonarQube’s industry-leading findings as an additional validated source of evidence in the JFrog Platform.”

Building trust across the supply chain

Industry experts view JFrog AppTrust as an important step in bridging the gap between rapid software delivery and governance. Jim Mercer, Program Vice President of Software Development, DevOps, and DevSecOps at IDC, noted: “Organisations struggling to secure their software supply chains can benefit from these new capabilities, making practices like attestation and provenance more achievable.”

By providing application-context asset assignment, promotion gating, dependency mapping, and vulnerability analysis, AppTrust seeks to reduce the friction that has traditionally existed between development, security, and compliance teams. JFrog said the platform allows organisations to maintain application quality and performance without slowing down innovation, helping them deliver software that is secure, compliant, and ready for production.

Hot this week

Anker unveils high-powered Prime series with new flagship power bank

Anker launches its new Prime series at IFA 2025, featuring a 300W power bank, 14-in-1 docking station, GaN charger, and Qi2 charging station.

One in three Australian workers expose company data to AI platforms, Josys warns

Over a third of Australian workers upload sensitive data to AI tools, with Josys warning of rising risks from shadow AI and weak governance.

Bose unveils second-generation QuietComfort Ultra headphones with lossless USB-C support

Bose launches its new QuietComfort Ultra headphones with USB-C lossless audio, longer battery life, and enhanced noise cancellation.

Instagram launches official app for iPad after 15 years

Instagram has finally launched a dedicated app for iPad, offering a redesigned layout, improved messaging, and a more engaging experience.

Ecovacs DEEBOT X11 wins gold award at IFA 2025

Ecovacs DEEBOT X11 wins Gold Award at IFA 2025, marking a milestone in AI-powered, sustainable home cleaning innovation.

Young Singapore inventor wins James Dyson Award for diabetes innovation

NUS graduate Zoey Chan wins James Dyson Award 2025 in Singapore for nido, a tool designed to simplify daily insulin injections.

Maxicare adopts Agentforce to streamline dental authorisations

Maxicare adopts Salesforce’s Agentforce to automate dental authorisations, improving clinic efficiency and member healthcare services.

Canon unveils next-generation video production equipment to elevate cinematic storytelling

Canon launches EOS C50, RF85mm f/1.4L VCM, and CN5x11 IAS T R1/P1 to support next-generation video production and storytelling.

Coursera launches Skill Tracks to address workplace skill gaps

Coursera launches Skill Tracks to help organisations close skill gaps with role-based, data-driven learning across IT, data, software, and GenAI.

Related Articles

Popular Categories