JFrog Ltd. has announced a major step forward in software supply chain security. The company, known as the Liquid Software provider, unveiled new integrations with Zscaler, Cloudflare, and Netskope. These three companies rank among the top Secure Access Service Edge (SASE) providers today. Together, they aim to stop malicious packages before reaching developer machines. As a result, this move strengthens software supply chain security at the network level. Consequently, organizations gain stronger protection without slowing down development.
The new JFrog Traffic Controller works alongside SASE platforms and JFrog Curation. Specifically, it reroutes software package requests through JFrog Artifactory automatically. Therefore, Artifactory becomes the single trusted source for every package. Meanwhile, developers and AI agents can continue working without interruption. Additionally, organizations gain a reliable way to prevent policy bypasses.
“JFrog Traffic Controller extends that enforcement to the network edge, creating one trusted path for software consumption with no exceptions, while developers and AI agents continue working without disruption.” – Shlomi Ben Haim, Co-Founder and CEO, JFrog
Malicious Packages Are Rising Fast
According to JFrog’s 2026 Software Supply Chain Security State of the Union, malicious packages surged 451% year over year. In fact, unique instances surpassed 171,000 during this period. However, only 40% of organizations currently have detection tools in place. Similarly, just 28% of enterprises actively monitor for exposed secrets. Clearly, the fastest-growing threats remain the least protected areas.
Furthermore, AI coding agents like Claude Code, Cursor, and Copilot now operate directly on developer systems. These agents often pull dependencies without human review. As a result, each session creates a potential unmonitored entry point. Meanwhile, attackers are exploiting vulnerabilities faster than ever before.
Reroute Instead of Block
Rather than blocking requests outright, JFrog Traffic Controller reroutes them intelligently. Specifically, JFrog Curation inspects every package against security, license, and quality policies. Consequently, compliant packages move forward without delay. Meanwhile, malicious ones get stopped immediately, and safe alternatives are offered when available.
“By partnering with Cloudflare, Netskope and Zscaler, our Traffic Controller works natively with the security infrastructure our customers already use,” said Gal Marder, Chief Strategy Officer, JFrog. “We’re making it possible for the entire software security ecosystem to enforce the same standard with zero friction: every package needs to be curated before first use, every transaction on record, no exceptions. That is how the industry builds a supply chain it can actually trust.”
Adyen Strengthens Its DevSecOps Approach
Global fintech platform Adyen already uses JFrog Curation as a real-time firewall. Therefore, developers can safely pull open-source components without introducing risks.
“JFrog Curation provides a firewall for open-source packages. You instill policies that defend the organization, but the goal isn’t to say ‘no’,” said Supun Vidana Pathiranage, DevSecOps Specialist, at Adyen. “It’s about how we can help developers continue their work without disrupting their workflow. We enable development; we don’t block it.”
“Bringing JFrog’s package intelligence into Netskope’s real-time protection policies gives joint customers a contextual, policy-driven answer to every package download, facilitating the user and agent build flow rather than a legacy solution which could only block access,” said David Willis, Vice President, Technology Alliances, Netskope.
Ultimately, this partnership-driven approach reflects a broader industry shift toward proactive, unified software supply chain security.
Explore IT Tech News for the latest advancements in Information Technology & insightful updates from industry experts!
News Source: Businesswire.com