<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/every-release-needs-a-chain-of-custody-ai-agents-just-made-that-harder--7xm9bpgux" -->

---
title: Every Release Needs a Chain of Custody. AI Agents Just...
description: JFrog announces Prompt to Release Traceability inside JFrog AppTrust, launched at swampUP 2026, which automatically assembles and signs a chain-of-custody...
canonical: https://daily.dev/posts/every-release-needs-a-chain-of-custody-ai-agents-just-made-that-harder--7xm9bpgux
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Every Release Needs a Chain of Custody. AI Agents Just Made That Harder. | daily.dev
og:description: JFrog announces Prompt to Release Traceability inside JFrog AppTrust, launched at swampUP 2026, which automatically assembles and signs a chain-of-custody...
og:url: https://daily.dev/posts/every-release-needs-a-chain-of-custody-ai-agents-just-made-that-harder--7xm9bpgux
og:image: https://api.daily.dev/og/posts/7xM9bPGux.png
og:image:alt: Every Release Needs a Chain of Custody. AI Agents Just Made That Harder.
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Every Release Needs a Chain of Custody. AI Agents Just Made That Harder.

**[JFrog](https://daily.dev/sources/jfrog)** · 5 min read · 0 upvotes · 0 comments

## Summary

JFrog announces Prompt to Release Traceability inside JFrog AppTrust, launched at swampUP 2026, which automatically assembles and signs a chain-of-custody record for each release: validated Jira ticket transitions, signed and connected commits/PRs with approver checks, and (later this year) AI agent session evidence including prompts and the tools an agent used. The goal is to replace weeks of manual audit-trail assembly across GitHub, Jira, and Slack with a signed evidence package generated automatically at promotion time, addressing frameworks like NIST SSDF and the EU Cyber Resilience Act. Git-based evidence is available now; agent session evidence and session bill of materials ship later this year.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://jfrog.com/blog/prompt-to-release-traceability>

## Questions this post answers

### What is JFrog's Prompt to Release Traceability feature in AppTrust?

It is a feature launched at swampUP 2026 inside JFrog AppTrust that automatically assembles a signed, auditor-ready evidence chain for each release, pulling together Jira ticket transition histories, signed and connected Git commits and pull requests with approver records, and checking for self-approval violations. Git-based evidence is generally available now, while AI agent session evidence and a session bill of materials are planned for later release.

_Teams tracking software supply chain compliance changes like this can follow release evidence tooling updates on daily.dev._

### Why do AI coding agents like Cursor and Claude Code create compliance problems for release audits?

Commits produced by agentic tools such as Cursor and Claude Code often have no human author of record and leave no trace of the prompts, decisions, or intent behind them in existing DevOps pipelines, so the Git log stays complete while the compliance picture behind it does not. JFrog's answer is capturing agent session evidence, including prompts, code, and which MCPs and skills the agent used, as signed evidence.

_Developers weighing agentic coding tools against audit requirements can track this tension via daily.dev._

## Similar posts on daily.dev

- [JFrog AppTrust: A Technical Deep Dive into Building a Trusted Software Supply Chain](https://daily.dev/posts/jfrog-apptrust-a-technical-deep-dive-into-building-a-trusted-software-supply-chain-ene7ljptn) · JFrog · 0 upvotes · 0 comments
- [The Tide of AI – Surfing the Tsunami of Binaries](https://daily.dev/posts/the-tide-of-ai-surfing-the-tsunami-of-binaries-328i1uqqf) · JFrog · 1 upvotes · 0 comments

---

Tags: [#ai-agents](https://daily.dev/tags/ai-agents), [#compliance](https://daily.dev/tags/compliance), [#devsecops](https://daily.dev/tags/devsecops), [#jfrog](https://daily.dev/tags/jfrog)

[View this post on daily.dev](https://daily.dev/posts/every-release-needs-a-chain-of-custody-ai-agents-just-made-that-harder--7xm9bpgux)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Every Release Needs a Chain of Custody. AI Agents Just Made That Harder.","url":"https://daily.dev/posts/every-release-needs-a-chain-of-custody-ai-agents-just-made-that-harder--7xm9bpgux","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/every-release-needs-a-chain-of-custody-ai-agents-just-made-that-harder--7xm9bpgux"},"datePublished":"2026-09-02T11:59:58.577Z","dateModified":"2026-09-03T15:20:54.873Z","description":"JFrog announces Prompt to Release Traceability inside JFrog AppTrust, launched at swampUP 2026, which automatically assembles and signs a chain-of-custody...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/1ec440b3d36eeada23ae2199e9611e5e?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/1ec440b3d36eeada23ae2199e9611e5e?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"JFrog","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"JFrog","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/b11bf37102384ac9983be701b2cf7cd5","url":"https://daily.dev/sources/jfrog"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/every-release-needs-a-chain-of-custody-ai-agents-just-made-that-harder--7xm9bpgux","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"ai-agents,compliance,devsecops,jfrog","timeRequired":"PT5M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"JFrog","item":"https://daily.dev/sources/jfrog"},{"@type":"ListItem","position":3,"name":"Every Release Needs a Chain of Custody. AI Agents Just Made That Harder."}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/every-release-needs-a-chain-of-custody-ai-agents-just-made-that-harder--7xm9bpgux#faq","mainEntity":[{"@type":"Question","name":"What is JFrog's Prompt to Release Traceability feature in AppTrust?","acceptedAnswer":{"@type":"Answer","text":"It is a feature launched at swampUP 2026 inside JFrog AppTrust that automatically assembles a signed, auditor-ready evidence chain for each release, pulling together Jira ticket transition histories, signed and connected Git commits and pull requests with approver records, and checking for self-approval violations. Git-based evidence is generally available now, while AI agent session evidence and a session bill of materials are planned for later release. Teams tracking software supply chain compliance changes like this can follow release evidence tooling updates on daily.dev."}},{"@type":"Question","name":"Why do AI coding agents like Cursor and Claude Code create compliance problems for release audits?","acceptedAnswer":{"@type":"Answer","text":"Commits produced by agentic tools such as Cursor and Claude Code often have no human author of record and leave no trace of the prompts, decisions, or intent behind them in existing DevOps pipelines, so the Git log stays complete while the compliance picture behind it does not. JFrog's answer is capturing agent session evidence, including prompts, code, and which MCPs and skills the agent used, as signed evidence. Developers weighing agentic coding tools against audit requirements can track this tension via daily.dev."}}]}
```

