JFrog announces Platform Federation, a peer-to-peer control plane that synchronizes projects, access control, security policies, artifacts, and repositories across all sites in a multi-site JFrog deployment. It builds on existing Federated Repositories and Access Federation capabilities, extending federation to projects, curation (zero-day vulnerability blocking), and automated repository provisioning. The product targets configuration drift, compliance exposure under regulations like NIS2, cross-region egress costs, and disaster recovery scenarios, positioning itself as necessary for AI-agent-driven, always-on software delivery pipelines. JFrog states the federated model will later expand to Xray, AI Catalog, Advanced Security, and AppTrust.
Table of contents
What Manual Multi-Site Work Costs – And What Federation EliminatesThree Multi-Site Patterns Platform Federation UnlocksThe Peer Mesh Advantage: Configure Once, Enforce Everywhere in SecondsJFrog Platform Federation in Action: Three Capabilities Keeping Your Multisite Development in SyncConfigure Once, Trust Everywhere with the JFrog PlatformStop maintaining sync scripts. Start configuring once and trusting everywhere.Questions this post answers
What does JFrog Platform Federation actually synchronize across sites?
It synchronizes projects, access control, security policies, artifacts, and repositories across every connected site using an autonomous peer-to-peer mesh. This extends beyond the earlier Federated Repositories and Access Federation features, which only kept artifacts and user permissions in sync, to now include project workspaces, curation rules, and automated repository provisioning. daily.dev surfaces platform engineering updates like this for teams designing multi-region delivery pipelines.
What are the three capabilities currently available in JFrog Platform Federation?
The three available capabilities are Projects Federation, which synchronizes multi-tenant workspaces, roles, SDLC gates, and access tokens; Curation Federation, which propagates zero-day vulnerability blocking rules, waivers, and approvals globally within seconds; and Automated Repository Provisioning, which creates the correct repositories on each site based on a defined Stage-to-Site mapping. Teams evaluating supply chain tooling track feature rollouts like these on daily.dev before committing.
How much can EU NIS2 cybersecurity fines cost for unpatched vulnerability handling gaps?
NIS2 cybersecurity fines can reach up to $17 million or 2.5% of global annual turnover for gaps in vulnerability handling. This is cited as a compliance risk that arises when security policies roll out to different sites at different times, leaving temporary windows of exposure in regulated environments. Engineers weighing compliance risk against tooling costs follow regulatory context like this on daily.dev.
554 Impressions1 Comment