More on the topic...
Generating detailed summary...
Failed to generate summary. Please try again.
Developers using Claude Code can go from idea to working software in seconds, but that speed exposes gaps in security and governance. An AI agent might suggest a vulnerable library or pull a risky package before any human sees it. The JFrog plugin for Claude Code plugs your Software Supply Chain Platform directly into the coding flow, so every suggestion, dependency pull, and build step runs through existing security controls.
Once you install and authenticate the plugin, Claude Code talks to JFrog Artifactory via CLI or REST/GraphQL. You can audit CVEs, query exposure reports, manage permissions and release bundles—all through natural language prompts. Before any code downloads a package from npm, Maven, PyPI or Go, the plugin runs a JFrog Curation check against your policies. It refuses unapproved or dangerous libraries and fetches approved versions from your Artifactory caches. On top of that, Agent Guard lets you discover, install and manage only the MCP servers your team has vetted, using OAuth or API keys for authentication.
For security and platform teams, this shifts the gate left. Instead of manual reviews in CI/CD, unapproved dependencies get blocked at suggestion time. Every artifact Claude Code touches goes through Artifactory, preserving build provenance and access controls. And because JFrog plans to extend this model to GitHub Copilot, Cursor and other agents, you get a single source of record for your artifacts and AI assets—no matter which coding assistant your engineers choose.
Questions about this article
No questions yet.