- 177,000 new malicious packages identified in 2026 (JFrog report)
- 451% year-over-year surge in malicious npm packages
- JFrog ranked highest for 'Ability to Execute' in Gartner's inaugural SSCS Magic Quadrant
Experts would likely conclude that JFrog's leadership position validates the critical need for integrated supply chain security solutions as software development accelerates with AI adoption.
JFrog Leads Inaugural Gartner Magic Quadrant for Supply Chain Security
SUNNYVALE, CA – June 22, 2026 – In a landmark moment for the cybersecurity industry, Gartner has officially recognized Software Supply Chain Security (SSCS) as a distinct market category with its first-ever Magic Quadrant report. JFrog Ltd. (Nasdaq: FROG), the "Liquid Software" company, has been positioned as a Leader, earning the highest placement for its "Ability to Execute" among all vendors evaluated. This recognition validates JFrog's long-held vision that securing the software pipeline is no longer an optional add-on but a foundational requirement for modern enterprise.
The establishment of this new Magic Quadrant signals a critical shift in how the industry perceives security. For years, the focus has been on securing applications at the perimeter or scanning code post-development. However, with the rise of complex, distributed development environments and a surge in sophisticated attacks targeting the supply chain itself, this approach has proven insufficient. JFrog's placement as a Leader underscores the market's pivot towards integrated platforms that embed security and governance directly into the flow of software development and delivery.
"We are honored to be recognized by Gartner, not simply because we believe it validates our vision, but because it reflects the trust our customers place in us every day to secure and power the world's software supply chains," said Shlomi Ben Haim, CEO of JFrog.
The Dawn of Software Supply Chain Engineering
The industry is undergoing a fundamental transformation, moving beyond the paradigms of DevOps and DevSecOps into what Ben Haim calls "software supply chain engineering." This evolution acknowledges that developers and security teams are now responsible for the entire lifecycle of software components, from their origin in open-source repositories to their final deployment. It’s a structural shift driven by the sheer velocity and complexity of modern software creation, a trend that is being supercharged by artificial intelligence.
"The AI era is accelerating software creation faster than any organization can audit," Ben Haim explained. "This movement leads to a Tsunami of binaries and a flood of vulnerabilities that make the software supply chain the primary target for attacks."
This "tsunami" is not hyperbole. According to JFrog's 2026 Software Supply Chain Security State of the Union report, the digital landscape is fraught with risk. The report identified a staggering 177,000 new malicious packages in the wild, with malicious npm packages alone surging 451% year-over-year. This data paints a clear picture: reactive scanning is a losing battle. The only viable strategy is to build trust into the supply chain from the very beginning. JFrog's philosophy, "speed without trust is a liability," resonates deeply in this new reality, advocating for a holistic platform where security, governance, and velocity operate as a single, cohesive unit.
Closing the AI Governance Gap
While AI promises unprecedented innovation and efficiency, it also introduces a new and formidable attack surface. Gartner has identified software supply chain attacks as one of the top four critical security threats, and the advent of AI is only accelerating this risk. Attackers are no longer just targeting finished applications; they are actively going after the building blocks themselves—AI models, agentic tools, and developer workflows.
A significant challenge for most organizations is the "AI governance gap." Many enterprises source AI models from untrusted public repositories, creating blind spots that traditional security tools were never designed to address. This is where JFrog's platform demonstrates its forward-thinking approach. The JFrog AI Catalog and MCP Server are designed to apply the same rigorous security and governance standards to AI assets that enterprises already use for their software artifacts. This allows organizations to gain visibility and control over the AI models and agent skills entering their environments, preventing untrusted assets from compromising their systems.
This proactive stance is complemented by JFrog Curation, a feature that acts as a gatekeeper at the front door of the software supply chain. It is designed to automatically block risky open-source components—whether due to vulnerabilities, license non-compliance, or malicious code—before they can be downloaded by developers. By guiding developers toward pre-vetted, trusted package versions, Curation prevents bad dependencies from becoming an enterprise-wide crisis, a critical capability as regulations like Europe's DORA act raise the stakes for supply chain integrity.
A Platform Built for Execution and Trust
Gartner’s "Ability to Execute" axis evaluates a vendor's products, viability, customer experience, and overall operational effectiveness. JFrog's top placement on this axis is a testament to a mature, comprehensive platform built for the operational realities of the modern enterprise. Unlike fragmented point solutions that can create more complexity, the JFrog Software Supply Chain Platform provides a unified system of record for every component, from source code to binaries to AI models.
This unified approach delivers auditable, provable security. With tools like JFrog AppTrust, the company addresses a perennial challenge for compliance teams: proving that security policies were actually enforced, not just documented. AppTrust creates immutable evidence and automated policy gates throughout the supply chain, replacing manual approvals and frantic, spreadsheet-driven audit preparations with a continuous, verifiable enforcement trail.
Furthermore, JFrog has expanded its capabilities around the Software Bill of Materials (SBOM), a critical tool for transparency and compliance. Customers and regulators now demand more than just a list of ingredients; they want proof that vulnerabilities were assessed and risk decisions were documented. JFrog’s support for VEX (Vulnerability Exploitability eXchange) within leading SBOM formats like CycloneDX and SPDX 3.0 provides organizations with the verifiable documentation needed to answer these questions with facts, ensuring they can demonstrate due diligence under scrutiny.
A New Market Takes Shape
The launch of a dedicated Magic Quadrant for Software Supply Chain Security validates a market that JFrog has been instrumental in building for years. The evaluation of 18 vendors highlights a dynamic and competitive landscape, with other leaders like Synopsys and Chainguard also making their mark. However, JFrog's distinction lies in its integrated, binary-centric approach that secures the entire lifecycle of software and AI assets across hybrid and multi-cloud environments.
By embedding trust, governance, and security directly into the software delivery process, the JFrog Platform helps enterprises secure their innovations without sacrificing developer velocity. This holistic model provides the structural foundation necessary to manage the escalating risks of the AI era, ensuring that organizations can build software that is not only fast but, more importantly, trustworthy.
