JFrog has launched Traffic Controller, a network-layer enforcement system designed to give enterprises a common control point for software package downloads initiated by developers, automated tools and artificial intelligence (AI) coding agents.

The company said Thursday that the system works with its Artifactory repository and Curation service, alongside Secure Access Service Edge (SASE) platforms from Zscaler, Cloudflare and Netskope. The aim is to reroute package requests through a governed software supply-chain path before components reach users’ machines.

According to JFrog’s announcement, Traffic Controller is available immediately through JFrog Curation and initially supports Zscaler Internet Access, Cloudflare Gateway and Netskope One SSE.

Extending controls beyond the development pipeline

The launch focuses on a gap that has become more visible as AI-assisted development tools gain the ability to pull dependencies and invoke build processes directly from developer environments. Traditional software supply-chain controls are often concentrated inside continuous integration and delivery pipelines, but package requests can also originate outside those managed workflows.

JFrog said Traffic Controller intercepts relevant outbound requests at the network layer and redirects them through Artifactory, where JFrog Curation evaluates packages against configured security, license and quality policies. Packages that meet policy can proceed, while malicious or disallowed components can be stopped before entering the organization.

The company framed AI coding agents as an important part of the problem. Tools that can autonomously select, download or install libraries may not always follow the same proxy settings, approved package lists or review steps designed around human developers.

“Organizations need control over what enters their software supply chain, whether it is requested by a developer, an AI agent, or an automated tool,” JFrog Co-Founder and Chief Executive Officer Shlomi Ben Haim said in the announcement.

Malicious package growth

JFrog also cited its 2026 Software Supply Chain Security State of the Union report, which recorded a 451 percent year-on-year increase in malicious packages to more than 171,000 unique instances. The company said 40 percent of organizations in its research had malicious-package detection capabilities in place, while 28 percent had secrets detection active.

Those figures come from JFrog’s own research, but they reflect a wider concern around the growing attack surface created by open-source dependencies, automated development and faster software delivery.

The network-layer approach is intended to complement rather than replace controls already used in development pipelines. JFrog said organizations can retain their existing SASE provider while using Artifactory as the system of record for software packages and artifacts.

Initial integrations

For Zscaler Internet Access, the system identifies software package traffic and routes it through JFrog for curation. With Cloudflare Gateway, organizations can configure TLS inspection and firewall policies to redirect package requests. Netskope One SSE can apply real-time protection policies that redirect package-manager traffic while preserving browser passthrough.

JFrog said support for additional SASE providers is expected to follow.

The company also pointed to Adyen as an example of an enterprise using JFrog Curation to block malicious open-source packages while maintaining developer workflows. Traffic Controller extends that model toward software requests originating beyond the conventional pipeline, including those initiated by AI agents.

TNGlobal recently covered another software supply-chain initiative involving JFrog, with the company joining the Athena coalition for coordinated open-source defense as AI accelerates vulnerability discovery and exploitation.

Chainguard Adds New Members to Athena Coalition as Coordinated Open Source Defense Scales