About
JFrog provides software supply chain solutions that empower organizations to manage, secure, and govern their AI and software assets from a single platform. It enables users to break down software delivery silos with a centralized system of record. JFrog's solutions facilitate evidence collection for attestation and ensure software integrity and compliance through evidence-based controls and contextualized insights. Its centralized governance model enhances security over every AI workload, catering to over 80% of the Fortune 100. These features are crucial for organizations aiming to maintain compliance and security across their software supply chains.
Related Vendors

Kusari describes the Kusari Platform as a "software supply chain security platform" aimed at DevSecOps teams. The site emphasizes SBOM-related capability with phrases such as "enrich your SBOMs", "Never Drop The SBOM", and guidance on SBOM tooling. Messaging highlights visibility into "every level of your open source code and its dependencies," and positions the product to "know your software, fix what matters, and prove you’re in control." The site also references security earlier in the development lifecycle ("Security at the Pull Request") and claims to "secure every link in your software supply chain." The content references commercial and open source partners.

Wind River provides software and platform solutions for mission-critical embedded and edge systems. The record describes a Yocto Project embedded Linux subscription that includes security vulnerability monitoring, long-term maintenance and support, and materials around the software bill of materials (SBOM). Wind River also offers Studio tools to create, build and integrate software for embedded and edge systems, an embedded virtualization platform to run multiple OSes on a single SoC, and a Debian-based enterprise Linux distribution for edge computing. The company describes tooling to automate testing, deploy, orchestrate and update software for embedded devices and to analyze data across networks of distributed devices and servers.

Inedo provides self-managed DevSecOps tools for development and DevOps teams that can be installed, updated, and scaled on-premises or in hybrid cloud environments (Windows or Linux). Their product portfolio and publications focus on software supply chain problems: centralizing, curating, and governing packages to reduce security risks and compliance issues. Documentation and guides reference ProGet (package management), BuildMaster (deployment and CI/CD), migration guidance from Sonatype/JFrog, and Chocolatey. Materials mention package approvals, managing vulnerabilities, versions and licenses, and building a CI/CD pipeline for internal packages. The site also references free versions of tools and a free expert assessment to identify gaps and create a modernization roadmap.
