JFrog launches network-level package security tool with SASE partners
JFrog Ltd. (Nasdaq: FROG) announced a new product called JFrog Traffic Controller, which integrates with Secure Access Service Edge (SASE) providers Zscaler, Cloudflare, and Netskope to intercept and inspect software package downloads at the network level before they reach user machines.
The tool works by rerouting outbound package download requests through JFrog Artifactory, where JFrog Curation checks each package against security, license, and quality policies. Packages that pass are delivered without interruption; those flagged as malicious are blocked, and a safe approved version is served automatically when one is available. The solution is available immediately through JFrog Curation.
According to JFrog's 2026 Software Supply Chain Security State of the Union report, malicious packages increased 451% year over year, reaching more than 171,000 unique instances. The report also found that only 40% of organizations have malicious package detection in place, and secrets detection is active in just 28% of enterprises.
JFrog said the product addresses a gap created by AI coding agents such as Claude Code, Cursor, Copilot, and Kiro, which run on developer machines and can autonomously pull software dependencies directly from public registries, bypassing pipeline-level controls.
Adyen, a financial technology company, was cited as a customer already using JFrog Curation. "JFrog Curation provides a firewall for open-source packages," said Supun Vidana Pathiranage, DevSecOps Specialist at Adyen. "It's about how we can help developers continue their work without disrupting their workflow."
The three supported gateway integrations include Zscaler Internet Access, Cloudflare Gateway, and Netskope One SSE. JFrog said support for additional SASE partners is expected to follow.
