All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
This analysis is scoped to JFrog's software supply chain security line (Xray plus the ML-model malicious-code scanning sub-line).
JFrog sells software supply chain security to DevOps and security teams through Xray, which finds vulnerabilities and license issues in open-source and third-party code. Xray analyzes packages at the binary level in JFrog Artifactory, a repository for binaries, containers and models, and also detects malicious machine-learning models. Founded in 2008, JFrog listed on Nasdaq in 2020 and employs about 1,800 people. Company-wide revenue was $531.8 million in 2025, up 24%. Kroger is a named Xray customer. Gartner named JFrog a Leader in its first Magic Quadrant for software supply chain security. Because Xray runs inside Artifactory, a customer moving off it has to reconfigure its scanning policies. Developer platform and cloud registry vendors could add comparable scanning to their products.
| Description | Public software supply chain platform whose security line, JFrog Xray, performs software composition analysis on binaries and open-source dependencies and scans machine-learning models in public repositories such as Hugging Face for malicious code before they enter the supply chain. | [f1] |
|---|---|---|
| Founded | 2008 | [f2] |
| HQ | Sunnyvale, California | [f3] |
| Latest funding | Public via IPO on NASDAQ (FROG) on September 16, 2020 (market cap $9.29B at close on June 24, 2026) | [f4] |
| Product | What it does |
|---|---|
| JFrog Xray | Software composition analysis that detects, prioritizes, and remediates open-source and binary vulnerabilities across the SDLC, and scans ML models from public repositories for malicious code. |
| JFrog AI Catalog | A centralized registry for detecting shadow AI, curating machine-learning models, and applying policy-based approval, where models flagged as malicious by Xray are managed. |
| JFrog Advanced Security | Adds secrets detection, infrastructure-as-code scanning, exposed-application scanning, and software-composition risk context on top of Xray for software supply chain security. |
AI Defense Matrix
| Govern | Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|---|
| AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain. | ||||||
| AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices. | ||||||
| AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD. | ||||||
| AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic. | ||||||
| AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes. | ||||||
| Training Data Datasets used for training, fine-tuning, and continued learning. | ||||||
| Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history. | ||||||
| AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools. |
JFrog Xray automatically scans machine-learning models uploaded to public repositories such as Hugging Face for malicious code, and models it flags are managed in a centralized AI model registry. This model-scanning line defends AI model artifacts and is mapped to the AI Defense Matrix. [f5]
Cyber Defense Matrix
| Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|
| Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware. | |||||
| Applications Software, interactions, and application flows on the devices. | |||||
| Networks Connections and traffic flowing among devices and apps, plus communication paths. | |||||
| Data Content at rest, in transit, or in use across devices, apps, and networks. | |||||
| Users The people using the devices, apps, networks, and data. |
JFrog Xray performs software composition analysis on application dependencies and binaries, inventorying open-source vulnerabilities and flagging malicious packages across the SDLC. These conventional supply chain security capabilities are mapped to the Cyber Defense Matrix. [f6]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 3/5 | The buyer is named, platform and security teams owning binaries and dependencies, but the quantified pain traces to JFrog's own research re-reported by The Hacker News and SiliconANGLE (s15, s16) rather than independent quantification, holding it at present-but-unproven. The pain figure lacks the named enterprise adoption a higher score would need. [s2, s5, s10, s16] |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. | 3/5 | The model-scanning mechanism is documented in concrete detail across PyTorch, Pickle, H5, and Paddle formats with binary-header and extension detection (s3), but the supporting work is vendor-authored with no external benchmark or third-party evaluation, so depth is concrete on JFrog's own pages without independent confirmation. That holds it at 3, below the Sonatype 4 whose platform analysis drew Forrester recognition and independent TechCrunch coverage. [s3, s5, s10] |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 4/5 | Software supply chain security carries independent buyer-side timing signals, the inaugural Gartner Magic Quadrant for the category and SBOM regulatory mandates, alongside a growing attack surface as teams pull models from public hubs (s11, s15, s16). Multiple independent signal types place it at 4, with the enabler being the recent surge in public-repository model sharing (s5) rather than a confirmed victim compromise. [s5, s3, s10, s15] |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 4/5 | JFrog Security Research runs a sustained vulnerability-disclosure program with named researchers and continuous repository monitoring (s4, s5), and The Hacker News independently covered its 100-plus malicious-model research (s15), an in-domain publication record corroborated by independent press rather than a single event. [s4, s5, s7, s13] |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 3/5 | The security line names one Xray reference, a single line that Kroger uses it for software security and license compliance (s9), and the Gartner Leader placement reaches buyers through JFrog's own announcement (s11) rather than wire-reported confirmation, so it cannot lift traction past the named-reference bar. That holds it at 3, below the Checkmarx 5 and Snyk 4 whose security traction is named and independently confirmed. [s9, s11, s10] |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 2/5 | No line-level revenue, burn, or margin is disclosed for the security line and parent capitalization cannot substitute, so output per capital is unverifiable. The parent runs at a net loss while growing about 25 percent (s7) and the line shows only thin named traction, placing efficiency in the low half below the Sonatype, Checkmarx. [s7, s8] |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 4/5 | Software composition analysis and software supply chain security are established categories buyers place without coaching, and the existence of a first Gartner Magic Quadrant for the category confirms analyst recognition independent of JFrog's position in it (s2, s11). That matches the Sonatype, Checkmarx, held below 5 because JFrog is one Leader among several rather than the category definer. [s11, s10, s2] |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 2/5 | Stripped of the parent's Artifactory repository position, which sits outside the scoped security line, Xray's scanning is standard software composition analysis (s2) and its malicious-package data is aggregated from public repositories (s5), both reproducible by a funded rival or an adjacent developer platform. That makes the line a plausible feature for a platform vendor to absorb, placing it at 2 below the Sonatype 4 whose Maven Central chokepoint sits inside its own scope. [s2, s1, s9, s12] |
JFrog sells to the platform and security teams that own the binaries, open-source dependencies, and now machine-learning models flowing through an organization's software supply chain. The homepage frames the company as software supply chain solutions for both DevOps and security, and the security line addresses the risk that an open-source component or a downloaded model carries a known vulnerability or hidden malicious code into production.
The buyer is enterprise and platform-centric rather than security-team-first. JFrog reaches its security buyer through the same relationship that sells the binary repository, so the security line addresses whoever already runs JFrog for artifact management and now needs to scan what passes through it. A self-serve trial exists alongside the enterprise motion, so the addressable set spans individual teams and procurement-gated enterprises.
A newer use case is the team adopting public AI models. JFrog's research found a malicious Hugging Face model whose loading granted an attacker a shell, and Xray scans ML model artifact formats for malicious code before use, widening the relevant buyer from the dependency owner to whoever now owns the risk of an untrusted model entering the pipeline. [s1, s5, s3]
Xray is the security line's core: an enterprise software composition analysis tool that identifies, prioritizes, and remediates vulnerabilities and license issues in open-source and third-party components across the development lifecycle. It scans the binaries and dependencies that move through the JFrog Artifactory repository rather than only source code, which is the placement that distinguishes it from a standalone scanner.
The model-scanning sub-line extends that artifact scanning to machine learning. JFrog's mechanism inspects models uploaded to public repositories for malicious code across formats including PyTorch, Pickle, H5, and Paddle, identifies threats by both binary header values and file extensions, and runs an automated verification step that separates true positives from benign models that triggered a warning. JFrog also positions its AI Catalog for AI asset governance alongside this detection.
The capability rests on original research, which is the external validation point. JFrog Security Research discovered and dissected a backdoored Hugging Face model and built a scanning environment to detect the class of attack, so the model-scanning claim is backed by published work rather than marketing alone. JFrog Advanced Security adds secrets, infrastructure-as-code, and exposure scanning around Xray for broader supply chain coverage. [s2, s3, s5]
The security line competes for the supply chain security buyer against Snyk, Cycode, and Checkmarx on conventional software composition analysis, and against the model-security entrants on malicious-model scanning. Its distinguishing position is not the scanner but where the scanner sits: Xray inspects artifacts inside the JFrog Artifactory binary repository that an organization already routes its builds through, so adoption rides an existing workflow rather than adding a separate tool.
That position is also the limit of the moat. The scanning itself is reproducible, and a buyer can point a different software composition analysis tool at the same repository, so JFrog holds the buyer through Artifactory as the binary system of record rather than through Xray as a security product. The malicious-package and vulnerability data that feeds the scanning is aggregated from public repositories and global sources, which a funded rival can assemble, so it is a credibility floor rather than a security-line moat.
The structural pressure is platform bundling from below. GitHub with Microsoft already ships dependency and code scanning where developers work, and cloud registries can add model scanning, so the security line is most defensible for the buyer already standardized on JFrog Artifactory and most exposed where a developer platform folds equivalent scanning into tools the buyer already owns. [s2, s1, s9]
The named commercial proof JFrog publishes is mostly for the platform rather than the security line. The customer quotes the company features describe Enterprise+, Distribution, and Access Federation, the DevOps platform's distribution and credentialing features, and the security line surfaces a single named Xray reference: a one-line statement that Kroger uses Xray for software security and license compliance, rather than a developed case study or multiple named accounts.
Third-party category placement carries the rest of the security story. Gartner named JFrog a Leader in its first Magic Quadrant for Software Supply Chain Security, placing it highest on Ability to Execute, and a conference transcript describes security product adoption as a strategic focus with governance emerging as a differentiator. JFrog's whole-company revenue, near 563 million dollars growing about 25 percent on NASDAQ, is parent context rather than security-line traction, since the public record does not break out the security line's own revenue.
The honest read is that the security line inherits platform reach as distribution and has published only thin traction of its own. A prospect evaluating Xray on customer evidence finds one brief named reference and a wall of platform logos, which speak to artifact management rather than to whether enterprises run and rely on the security scanning, so the security-line proof is mostly indirect. [s9, s10, s7]
JFrog pairs a public company's scale with a recognized security research function. JFrog Security Research runs a sustained vulnerability-disclosure program, its research page listing discovered-by researcher names on recent vulnerability entries, and it continuously monitors public package repositories for malicious uploads it reports to maintainers and the community.
The research output is the credibility marker for the security line specifically. The team's discovery of a backdoored Hugging Face model, and the scanning environment it built in response, is original work in the exact domain the model-scanning sub-line sells into, which is a stronger signal than product leadership alone.
The company context is an established public business. JFrog was founded in 2008, went public on NASDAQ in 2020, and employs roughly 1,800 people, so the security line is built and shipped by a mature engineering organization rather than an early-stage team, though that scale is the parent's and does not by itself prove the security line's own execution. [s4, s5, s7]
JFrog presents the assurance evidence an enterprise supply chain buyer expects. Its trust certificate program lists SOC 2 Type II, SOC 3, ISO 27001, ISO 27701, ISO 27017, TISAX, CSA STAR Level 1, and Cyber Essentials, a deeper attestation set than most pure-play scanners publish, fitting a vendor that already holds enterprise procurement relationships.
Those attestations are table stakes rather than a differentiator. They are the commercial certifications a regulated buyer requires of any vendor handling its artifacts, and the fetched record shows no federal authorization such as FedRAMP that would create a procurement barrier a rival lacking it could not clear, so the certificate program clears the bar without lifting the security line above its peers.
The scanning footprint is a latent data position the record does not yet treat as a moat. Running malicious-package and model scanning across many customers' repositories gives JFrog a cross-customer view of supply chain threats that a single tenant cannot assemble, a metadata advantage that is plausible but not evidenced as a named, non-public dataset in the fetched pages, since the company describes its threat data as aggregated from global sources. [s6, s2, s4, s14]
| Company | Relationship | Note | Compare |
|---|---|---|---|
| Snyk | competes with | Developer-security platform with software composition analysis and a developer-first motion that overlaps Xray's open-source vulnerability scanning in the software supply chain. | N/AWe scored these companies at different scopes, so the totals measure different things. |
| Cycode | competes with | Application-security and code-security platform spanning SCA and the software supply chain, contesting the same dependency and pipeline-security buyer as the JFrog security line. | N/AWe scored these companies at different scopes, so the totals measure different things. |
| Checkmarx | competes with | Enterprise application-security platform with software composition analysis contesting the same open-source-risk buyer that Xray sells the SCA line to. | N/AWe scored these companies at different scopes, so the totals measure different things. |
| Sonatype | competes with | Software supply chain management and component-firewall vendor whose Nexus repository and malicious-package blocking overlap JFrog's combined artifact-repository and Xray scanning position. | N/AWe scored these companies at different scopes, so the totals measure different things. |
| GitHub | adjacent | Developer platform owned by Microsoft whose GitHub Advanced Security ships dependency and code scanning where developers work, pressuring Xray's scanning from the platform layer. |
Add analyzed competitors to compare them side by side with JFrog.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
pivot urgently
JFrog's security line reads as matchable by a funded software composition analysis rival: the scanned formats and monitored repositories are public, its own findings and claimed patents aside, and its certifications are attestations rivals can earn. What a rival cannot quickly copy is the binary repository a customer's builds flow through, built since its 2008 founding. Nothing in the record shows Xray excluding rival scanners from those repositories, so the durable hold reads as the repository, not the scanner. The model-scanning sub-line is JFrog's own work, built after its research team found a backdoored Hugging Face model. The named security proof is thin, one line citing Kroger. The line is the right call for a buyer already on JFrog, a closer contest for everyone else.
| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 | Customers buy configurable scanning software they run inside the JFrog Platform, with automated vulnerability and malicious-model detection as software output rather than a service that accepts accountability for the result. |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 | Xray embeds in the build pipeline through the Artifactory repository, so moving off it means rewiring scanning policy, but the scanner itself is not shown to be exclusive there, and the record documents no barrier to a rival scanner working against the same repository, which keeps the switching cost short of a deeper lock-in. |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 1/3 | JFrog holds SOC 2, SOC 3, ISO 27001, ISO 27701, ISO 27017, TISAX, and CSA STAR Level 1, but these are commercial certifications any vendor in the category can earn, and the fetched record shows no FedRAMP authorization that would gate a federal buyer. |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 | Software composition analysis on binaries plus malicious-model scanning across model formats including PyTorch, Pickle, H5, and Paddle by binary header and file extension, backed by original research into model-loading code execution, sits in program-analysis and binary-inspection territory that takes years of specialized expertise to build. |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 2/3 | The security line reaches regulated enterprises through the platform, but JFrog also runs a self-serve trial of Artifactory and Xray, so the buyer band reaches below the procurement-gated bar. |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 2/3 | Xray scans artifacts during the build rather than sitting inside running production software where its removal would break a live application, which places it out of the runtime path. |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 1/3 | JFrog combines indications from open-source repositories with its own findings and claims its own vulnerability database and patented detection technology, but the monitored packages and model formats are public and the record names no non-public cross-customer corpus, so the evidenced data position stays short of a corpus moat. |
JFrog's security line sells to the platform and security teams that already run JFrog to manage their binaries and now need to scan what passes through it. The company frames itself as software supply chain solutions for both DevOps and security, and the security line addresses the risk that an open-source component or a downloaded model carries a known vulnerability or hidden malicious code into production.
The buyer reaches the security line through the artifact-management relationship rather than as a standalone security purchase. JFrog runs both a self-serve trial of Artifactory and Xray and an enterprise motion, so the addressable set spans individual teams trying the scanner and the procurement-gated enterprises that standardize on the platform. The security product follows wherever the binary repository is already deployed.
A newer use case is the team pulling models from public repositories. JFrog's research found a malicious Hugging Face model whose loading granted an attacker a shell, and Xray scans ML model artifact formats for malicious code before use, widening the relevant buyer from the dependency owner to whoever now owns the risk of an untrusted model entering the pipeline.
Xray is the security line's core capability: enterprise software composition analysis that identifies, prioritizes, and remediates vulnerabilities and license issues in open-source and third-party components, run against the binaries and dependencies that move through the JFrog Artifactory repository rather than against source code alone. That placement inside the artifact flow is what distinguishes it from a scanner a team bolts on separately.
The model-scanning sub-line extends artifact scanning to machine learning, and JFrog's own research is its strongest credibility signal. The mechanism inspects models from public repositories for malicious code across formats including PyTorch, Pickle, H5, and Paddle, identifies threats by both binary header values and file extensions, and runs an automated verification step that separates real risks from benign models that merely triggered a warning. The JFrog Security Research team discovered and dissected a backdoored Hugging Face model and developed the scanning environment to combat that class of threat, so the capability rests on published work rather than marketing.
The advantage is real but bounded. JFrog combines indications from public repositories with its own findings and claims its own vulnerability database and patented detection technology, but the monitored sources and model formats are public and the record names no non-public corpus, and the published research example centers on Hugging Face. The capability is strong evidence of craft rather than a moat a funded rival could not match.
The named commercial proof JFrog publishes is mostly for the platform rather than the security line. The customer logos and testimonials the company features describe its DevOps platform and its distribution and credentialing features, and the security line surfaces a single named Xray reference, a one-line statement that Kroger uses Xray for software security and license compliance, rather than a developed case study, so its traction is mostly inherited reach rather than its own published evidence.
Third-party category placement and public-market signals carry the rest of the security story. Gartner named JFrog a Leader in its first Magic Quadrant for Software Supply Chain Security, placing it highest on Ability to Execute, and JFrog is public on NASDAQ with trailing-twelve-month revenue near 563 million dollars growing about 25 percent, signals of company-wide scale and growth, though the public record does not break out the security line's own revenue.
The go-to-market advantage is distribution, not demand proof. Because the security line attaches to the binary repository an organization already routes its builds through, JFrog can offer scanning to its platform installed base without a separate sale, but that reach is platform-wide and the record shows only one Xray-specific named reference, so a prospect evaluating the security product on its own customer evidence finds mostly platform proof rather than security-line proof.
JFrog does not publish a standalone rate card for the security line in the fetched record. The start-free page advertises a Pro entry price from fifty dollars a month for package, container, and model management and offers an Artifactory-and-Xray trial separately, while the cited record does not disclose Xray's own paid pricing structure, consistent with a vendor that sells the scanner as an attached capability of the artifact-management platform.
With Xray's paid structure undisclosed, the fetched pages leave the buying unit unstated. What they do show is the entry path: the trial arrives bundled with Artifactory, so a buyer first meets the scanner inside the platform relationship rather than as a standalone security quote.
The self-serve trial lowers the entry cost. JFrog offers a free trial of Artifactory and Xray together, so a team can evaluate the scanning without a procurement cycle, which fits the platform-led motion where the security line rides the same relationship as the repository.
The security line is delivered as software the customer configures and operates inside the JFrog Platform rather than as a managed service. Xray scans artifacts as they move through the Artifactory repository, so a team sets policy and consumes findings within the artifact workflow it already runs, and the same applies to the model-scanning sub-line, which scans models pulled into the pipeline.
Operations target automated coverage inside the existing pipeline. JFrog describes intelligently automated security and compliance designed for complex DevOps workflows, and the vendor describes the malicious-model mechanism as running an automated verification step meant to reduce false-positive noise, so the delivered artifact is automated scanning output rather than an analyst service that accepts accountability for the result.
The scanner attaches to the artifact platform the customer already operates. JFrog offers cloud and self-hosted trials of Artifactory and Xray, and because Xray scans the artifacts moving through that repository, a buyer evaluates the security capability where its binaries already live rather than standing up a separate scanning service.
JFrog presents the assurance evidence an enterprise supply chain buyer expects. Its trust certificate program lists SOC 2 Type II, SOC 3, ISO 27001, ISO 27701, ISO 27017, TISAX, CSA STAR Level 1, and Cyber Essentials, the commercial certifications a regulated buyer requires of a vendor handling its artifacts.
Those attestations are table stakes rather than a differentiator for the security line. The fetched record shows no federal authorization such as FedRAMP that would create a procurement barrier a rival lacking it could not clear, so the certificate program clears the enterprise bar without lifting the security line above its peers that hold the same commercial certifications.
The threat-monitoring footprint is a latent data position the record does not yet treat as a moat. Continuously scanning public package and model repositories for malicious uploads could let JFrog accumulate a malicious-artifact corpus that improves detection over time, but the company describes this data as aggregated from public repositories and global sources rather than as a named, non-public dataset, so it is a plausible latent advantage rather than an evidenced moat.
The security line's strongest structural asset is the platform it attaches to. JFrog Artifactory is the binary system of record that an organization routes its builds, dependencies, and releases through, and Xray scans those artifacts in place, so the security capability rides an existing workflow rather than asking a buyer to adopt a separate tool and integrate it.
That position is distribution into the buyer rather than a security-category moat. The cited record establishes the repository embedding but not scanner exclusivity, so the workflow favors JFrog's scanner without evidence that it locks the buyer to it, and the durable hold is on the repository rather than on the security product specifically.
The ecosystem reach extends to the AI supply chain. By detecting malicious machine-learning models and positioning the JFrog AI Catalog for AI asset governance, JFrog frames the platform as a control point for machine-learning artifacts as well as conventional binaries, which is a credible extension of the system-of-record role, though the published model-scanning research centers on public repositories such as Hugging Face rather than spanning every model source an enterprise uses.
JFrog pairs a public company's engineering scale with a recognized security research function. JFrog Security Research runs a sustained vulnerability-disclosure program, and its research page lists named researchers on current posts and discovered-by names on recent vulnerability entries, alongside continuous monitoring of public package repositories for malicious uploads it reports to maintainers and the community, a research record rather than a single event.
That research is the credibility marker for the security line specifically. The team's discovery of a backdoored Hugging Face model, and the scanning environment it built in response, is original work in the exact domain the model-scanning sub-line sells into, which is a stronger signal of capability than product positioning alone.
The company context is an established public business. JFrog was founded in 2008, went public on NASDAQ in 2020, and employs roughly 1,800 people, so the security line is built by a mature organization, though that scale belongs to the platform and does not by itself prove the security line's own execution and traction.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | JFrog homepage | official | 2026-06-25 |
| f2 | JFrog Ltd. FY2025 Form 10-K, Corporate Information (SEC EDGAR) | regulatory | 2026-06-27 |
| f3 | JFrog IR press release dateline (Sunnyvale, Calif.) | official | 2026-06-25 |
| f4 | StockAnalysis: JFrog Ltd. (FROG) overview | press | 2026-06-25 |
| f5 | JFrog Docs: Detect Malicious AI Models | official | 2026-06-25 |
| f6 | JFrog Xray: Software Composition Analysis (SCA) Tool | official | 2026-06-25 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | JFrog homepage (software supply chain for DevOps and security) “Software Supply Chain Solutions for DevOps & Security” | official | 2026-06-25 |
| s2 | JFrog Xray: Software Composition Analysis (SCA) Tool “JFrog Xray is an enterprise grade software composition analysis (SCA) tool that provides organizations with a simple way to identify, prioritize and remediate security vulnerabilities and license compliance issues in open source software (OSS) and third party components.” | official | 2026-06-25 |
| s3 | JFrog Docs: Detect Malicious AI Models (supported formats and verification) “The malicious model types are identified both via their binary header values and via their file extensions. H5 ... Paddle ... PyTorch ... Pickle ... distinguishes between true positives (actual security risks) and false positives (benign models that triggered a warning).” | official | 2026-06-25 |
| s4 | JFrog Security Research (vulnerability discovery, named researchers, malicious-package monitoring) “The JFrog Security research team continuously monitors popular repositories with our automated tooling, and reports malicious packages discovered ... Latest vulnerabilities discovered by the team ... Discovered By Yuval Moravchick” | official | 2026-06-25 |
| s5 | JFrog research blog: malicious Hugging Face ML model with a silent backdoor “The model’s payload grants the attacker a shell on the compromised machine, enabling them to gain full control over victims’ machines through what is commonly referred to as a “backdoor”.” | official | 2026-06-25 |
| s6 | JFrog Trust Certificate Program (information-security attestations) “SOC 2 Type II Report ... SOC 3 Report ... ISO 27001 ... ISO 27701 ... ISO 27017 ... TISAX ... CSA STAR Level 1 ... Cyber Essentials” | official | 2026-06-25 |
| s7 | StockAnalysis: JFrog Ltd. (FROG) financial overview “NASDAQ: FROG ... IPO Date Sep 16, 2020 Employees 1,800 ... Market Cap 9.29B ... Revenue (ttm) 563.41M +25.0% Net Income -61.5” | press | 2026-06-25 |
| s8 | JFrog Ltd. Investor Relations corporate profile (founded 2008, system of record) “Founded in 2008, JFrog has evolved from a position as the “database of DevOps” into the mission-critical System of Record for the global software supply chain.” | official | 2026-06-25 |
| s9 | JFrog for Software Supply Chain Security (Kroger named as an Xray reference) “Kroger uses Xray for software security and license compliance ... Intelligently automated security and compliance solutions designed for complex DevOps workflows.” | official | 2026-06-25 |
| s10 | StockAnalysis transcript feed: JFrog security product adoption and governance differentiation “JFrog Transcript: 46th Annual William Blair Growth Stock Conference ... a strategic focus on cloud migration and security product adoption. Governance is emerging as a key differentiator” | press | 2026-06-25 |
| s11 | JFrog IR press release: Leader in the first Gartner Magic Quadrant for Software Supply Chain Security (June 22, 2026) “JFrog Ltd. (Nasdaq: FROG) ... today announced it has been named a Leader in the Gartner® Magic Quadrant™ for Software Supply Chain Security, positioned the highest for Ability to Execute amongst any other vendor in the report.” | official | 2026-06-25 |
| s12 | JFrog Ltd. FY2025 Form 10-K: JFrog Xray and Advanced Security product descriptions (SEC EDGAR) “JFrog Xray analyzes software packages at a binary level, utilizing the metadata stored in JFrog Artifactory to accurately uncover potential vulnerabilities, policy violations, and open source software license compliance issues.” | regulatory | 2026-06-27 |
| s13 | TechCrunch: JFrog acquires AI-based IoT and device security specialist Vdoo for $300M “And indeed, Vdoo is not JFrog’s first foray into security, but it represents a significant step deeper into the hardware and systems that are being run on software.” | press | 2026-06-27 |
| s14 | NVD CVE-2024-4142: JFrog Artifactory improper input validation privilege escalation “An Improper input validation vulnerability that could potentially lead to privilege escalation was discovered in JFrog Artifactory. Due to this vulnerability, users with low privileges may gain administrative access to the system.” | research | 2026-06-27 |
| s15 | The Hacker News: Over 100 Malicious AI/ML Models Found on Hugging Face (JFrog research) “These include instances where loading a pickle file leads to code execution, software supply chain security firm JFrog said.” | press | 2026-06-27 |
| s16 | SiliconANGLE: JFrog report finds AI growth driving new software supply chain threats “In an example in the report, the JFrog Security Research Team detected 25,229 exposed secrets or tokens in public registries, up 64% year-over-year, of which 27% were active.” | press | 2026-06-27 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | JFrog homepage (software supply chain for DevOps and security) “Software Supply Chain Solutions for DevOps & Security” | official | 2026-06-25 |
| s2 | JFrog Xray: Software Composition Analysis (SCA) Tool “JFrog Xray is an enterprise grade software composition analysis (SCA) tool that provides organizations with a simple way to identify, prioritize and remediate security vulnerabilities and license compliance issues in open source software (OSS) and third party components.” | official | 2026-06-25 |
| s3 | JFrog Docs: Detect Malicious AI Models (supported formats and detection method) “JFrog’s Xray detects malicious machine learning models based on artifact scanning ... The malicious model types are identified both via their binary header values and via their file extensions. H5 (.h5, .hdf5) Paddle (.pdparams) PyTorch (.bin, .pt, .pth, .ckpt) Pickle (.pkl, .dat)” | official | 2026-06-25 |
| s4 | JFrog Docs: malicious-model verification and centralized model registry “This process efficiently distinguishes between true positives (actual security risks) and false positives (benign models that triggered a warning).” | official | 2026-06-25 |
| s5 | JFrog Security Research (vulnerability discovery, named researchers, malicious-package monitoring) “The JFrog Security research team continuously monitors popular repositories with our automated tooling, and reports malicious packages discovered ... Latest vulnerabilities discovered by the team ... Discovered By Yuval Moravchick” | official | 2026-06-25 |
| s6 | JFrog research blog: malicious Hugging Face ML model with a silent backdoor “The model’s payload grants the attacker a shell on the compromised machine, enabling them to gain full control over victims’ machines through what is commonly referred to as a “backdoor”.” | official | 2026-06-25 |
| s7 | JFrog Trust Certificate Program (information-security attestations) “SOC 2 Type II Report ... SOC 3 Report ... ISO 27001 ... ISO 27701 ... ISO 27017 ... TISAX ... CSA STAR Level 1 ... Cyber Essentials” | official | 2026-06-25 |
| s8 | StockAnalysis: JFrog Ltd. (FROG) financial overview “NASDAQ: FROG ... IPO Date Sep 16, 2020 Employees 1,800 ... Market Cap 9.29B ... Revenue (ttm) 563.41M +25.0% Net Income -61.5” | press | 2026-06-25 |
| s9 | JFrog Ltd. Investor Relations corporate profile (founded 2008, binary-centric system of record) “Founded in 2008, JFrog has evolved from a position as the “database of DevOps” into the mission-critical System of Record for the global software supply chain.” | official | 2026-06-25 |
| s10 | JFrog for Software Supply Chain Security (Kroger named as an Xray reference) “Kroger uses Xray for software security and license compliance ... Intelligently automated security and compliance solutions designed for complex DevOps workflows.” | official | 2026-06-25 |
| s11 | StockAnalysis transcript feed: JFrog security product adoption and governance differentiation “JFrog Transcript: 46th Annual William Blair Growth Stock Conference ... a strategic focus on cloud migration and security product adoption. Governance is emerging as a key differentiator” | press | 2026-06-25 |
| s12 | JFrog Start Free (self-serve trial and Pro entry pricing for Artifactory and Xray) “Start a Trial With Artifactory and Xray ... binary, container, and model in one place. Starting at $50/month” | official | 2026-06-25 |
| s13 | JFrog IR press release: Leader in the first Gartner Magic Quadrant for Software Supply Chain Security (June 22, 2026) “JFrog Ltd. (Nasdaq: FROG) ... today announced it has been named a Leader in the Gartner® Magic Quadrant™ for Software Supply Chain Security, positioned the highest for Ability to Execute amongst any other vendor in the report.” | official | 2026-06-25 |
| s14 | The Hacker News: Over 100 Malicious AI/ML Models Found on Hugging Face Platform “As many as 100 malicious artificial intelligence (AI)/machine learning (ML) models have been discovered in the Hugging Face platform. These include instances where loading a pickle file leads to code execution, software supply chain security firm JFrog said.” | press | 2026-06-30 |
| s15 | SecurityBrief Australia: JFrog named leader in Gartner's software security quadrant “JFrog has been named a Leader in Gartner's first Magic Quadrant for Software Supply Chain Security and ranked highest for Ability to Execute in the new category.” | press | 2026-06-30 |
| s16 | JFrog Ltd. FY2025 Form 10-K: revenue and year-over-year growth (SEC EDGAR) “We generated revenue of $531.8 million and $428.5 million for the years ended December 31, 2025 and 2024, respectively, representing year-over-year growth rate of 24%.” | regulatory | 2026-06-30 |
| s17 | NVD: CVE-2024-4142 JFrog Artifactory privilege-escalation vulnerability “An Improper input validation vulnerability that could potentially lead to privilege escalation was discovered in JFrog Artifactory. Due to this vulnerability, users with low privileges may gain administrative access to the system.” | other | 2026-06-30 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.