Datacap - We Solve Payment Problems
Home Software Supply Chain

Take command of your software supply chain

Why ISVs must unify platforms, automate compliance, and embed security to stay ahead in the AI era.

Sonar, ServiceNow and NVIDIA

Walking into the opening keynote at JFrog swampUP 2025, I immediately sensed the urgency and gravity in the room – a palpable shift in how our industry now sees the software supply chain. Shlomi Ben Haim, JFrog’s CEO, wasted no time getting to the heart of the matter: In this era, if you’re not controlling, shifting and delivering software releases securely, you’re already behind the curve. That premise resonated deeply with me – and with just about every ISV leader present – because the threats are evolving as fast as the tools we use. Board-level pressure for robust AI adoption is pushing budgets higher, yet the real challenge is staying secure while moving at speed.

Collaboration is the new kingmaker

The real innovation, however, lies in how trusted DevOps platforms, such as JFrog, Sonar, ServiceNow, and NVIDIA, are collaborating to transform security from an afterthought to an embedded feature. Tariq Shaukat, CEO of Sonar, and Justin Boitano, VP of Enterprise AI at NVIDIA, both drove home a simple truth: Security and transparency are only possible if every artifact and every line of code is accounted for. Rahul Tripathi from ServiceNow demonstrated how automated evidence exchange and compliance are no longer just technical challenges – they have become the foundation of IT governance for large-scale ISVs.

From siloed tools to unified platforms

A core takeaway for me was the industry-wide push to replace fragmented toolchains with cohesive, platform-centric strategies. JFrog Fly, one of the headline launches, is a great example: It connects with leading AI coding tools – GitHub Copilot, Claude Code, and Software Development Lifecycle (SDLC)Cursor – to enforce semantic metadata management, optimized deployments, and consistent release integrity. Gartner’s guidance is clear: Platforms anchoring the supply chain as a single source of truth will outpace rivals.

Why provenance and traceability matter now

Gartner predicts that by 2027, over 90% of new applications will include ML models – a seismic shift that’s set to redefine the software supply chain landscape. As ISVs embed more AI and machine learning into releases, automating evidence collection and securing the integrity of every component becomes non-negotiable. The stakes are high: As attacks targeting AI agents and supply chain vulnerabilities surge (up to 75% of third-party breaches target the software and technology supply chain), traceability isn’t a nice-to-have – it’s a must.

  • For ISVs, this means automating evidence collection, generating SBOMs (software bill of materials), and enforcing policies that block suspect binaries long before they reach production – capabilities JFrog demonstrated with seamless integrations to GitHub and ServiceNow.
  • It’s no surprise that almost every hand went up when Ben Haim polled the room about AI in their software supply chains. If you’re not governing AI, your competitors – and attackers –will do it for you.

What does this mean for ISVs?

Talk to any software expert who’s deployed hundreds of build pipelines for enterprise clients, and you’ll hear the following consistent advice: Shift left, automate compliance, and treat supply chain governance as a board-level priority – not just a developer concern. The days when security was “bolted on” at release are gone. With solutions like JFrog Fly, the opportunity to anchor all supply chain evidence, automate policy enforcement, and unify workflows is here. If you haven’t made securing the software supply chain a design principle yet, consider yourself officially warned – the future belongs to those who do.


Jay McCall

As Co-founder of DevPro Journal, Jay McCall combines 25 years of experience in journalism and IT content creation with a passion for thought leadership. With a sharp focus on creating engaging, practical content, the publication addresses the unique needs of software developer leaders, offering strategies to build sustainable and fulfilling businesses.

×