Extending the Single Source of Truth to the Agentic Software Supply Chain
From the source: JFrog BlogEvery developer on your team now runs multiple agents. None of them are waiting for human sign-off to act. That’s exactly the gap we discussed and closed at swampUP 2026. JFrog unveiled new capabilities that extend the JFrog Platform as not only the Single Source of Truth for OSS and heritage software, but now the …
Read the full story on JFrog BlogHave you worked with this?
The story is what was announced. Nobody has discussed it yet, so if it touches your team, a short post about what you’ve seen helps the next reader.
More from JFrog
Recent updates from JFrog, so you can tell whether this is a one-off or part of a pattern.
JFrog Artifactory Supports LuaRocks Hosting for NGINX, OpenResty and Kong
If your NGINX/OpenResty servers or Kong gateways pull Lua modules straight from public luarocks.org, one upstream outage can stall every build and deploy that depends on a “rock”. With LuaRocks support in JFrog Artifactory, you host and proxy those modules from a private LuaRocks registry you control, using the native experience you expect, not a …
ParaShells: Parallels Desktop Turns Appliance Install Into a Root Shell
Your Mac runs a vulnerable version of Parallels Desktop. A malicious package, compromised CI job, or other unprivileged process is already running on it. No admin access. No Parallels-signed client. One appliance-install request later, attacker-controlled code runs as root. While testing Desktop 26.4.0 (build 57513) on Apple silicon, we found that an unprivileged local user …
Live From the Show Floor: swampUP 2026
Live updates from this event have concluded. swampUP 2026 is officially LIVE in New York City! Three days, one stage, one mission: rebuild trust for a software supply chain that increasingly ships itself. Keynote updates land here as they happen, September 1–3, 2026. Let’s go! Conference Day 2, September 3rd [11:00 a.m.] The Great Model …
More in DevOps & Platform Engineering
What other companies in DevOps & Platform Engineering are doing. The category page shows who’s active, side by side.
Secure AI agents with HashiCorp Boundary
Enable AI agents to securely access your resources while operating within enterprise identity, access, and audit controls.
Terraform provider for Google Cloud 8.0 now generally available
The Terraform provider for Google Cloud 8.0 builds on expanded infrastructure discovery workflows, modernizes provider defaults, removes support for retired Google Cloud services, and improves consistency between Terraform configurations and Google Cloud APIs.
AI agents need continuity, not just context
Pulumi Neo works on infrastructure the way an engineer does: it clones repositories, edits files, installs dependencies, runs previews, and produces intermediate work along the way. A task is not only a conversation with a model. It is also a working directory that has to survive long enough for the agent to keep making progress. Imagine asking an agent to upgrade a Pulumi provider version across…
CI/CD Security Best Practices: A 2026 Pipeline Checklist
CI/CD security best practices for 2026: secrets management, scoped access, dependency scanning, signed artifacts, and audit logging in one checklist. | Blog



