Singapore’s Developers Must Move Beyond Source Code to Secure Modern Applications
- By Sunny Rao, JFrog
- April 06, 2026

Singapore is abuzz with the potential of AI-assisted and automated software development. As more companies, like Singapore Airlines, adopt an AI-first software development methodology, new agentic AI tools like OpenClaw are enabling individual developers to innovate at scale and speed.
AI agents can now generate production-ready code at speed, shifting attention away from the code itself and toward what actually runs in production — the binary. Whether written by humans or AI, the binary is the asset and the true attack surface. Securing source code alone is no longer enough. Organizations must secure and govern the artifacts they build and ship through a software supply chain security platform that serves as a single system of record, ensuring every release is trusted, traceable, and compliant.
Why source code alone no longer reflect reality
Source code represents developer intent. Binaries represent execution reality.
Once code enters the CI/CD pipeline, it is transformed by build systems, dependencies, plugins and configuration files. Vulnerabilities or malicious behavior can be introduced well after code is committed through poisoned dependencies, compromised build scripts, or tampered artifacts.
This matters acutely in Singapore, where enterprises rely heavily on outsourced development, offshore build pipelines and open-source components. Without visibility into compiled outputs, security teams may pass audits while attackers slip through the cracks.
In fall 2025, the npm ecosystem was hit by the Shai-Hulud attack, a self-spreading supply chain campaign that hid malicious code inside trusted open-source packages. The attackers compromised dependencies already in use in production. This allowed malicious binaries to run inside environments without obvious changes to application code.
Traditional “shift-left” practices like static application security testing (SAST) remain important, but on their own, they are no longer sufficient. Many of today’s most damaging attacks originate in binaries, containers and third-party packages — areas that source scanning alone cannot fully inspect.
The vulnerability overload problem
As vulnerability disclosures grow year over year, treating every CVE equally leads to alert fatigue, constant fire-drill remediation, and developer burnout.
JFrog’s State of Supply Chain 2025 report found that 73% of organizations rely on seven or more security tools, with nearly half using 10 or more, creating inefficiencies and inconsistent visibility across teams.

Organizations need to prioritize, rather than focusing on size and scale. Context-aware prioritization enables teams to understand whether a vulnerability is actually reachable or exploitable within a specific app. With this approach, teams can focus on the small subset of issues that represent the real risks. Going a step further, analyzing configuration, transitive dependencies, and runtime context provides a more accurate picture of where exposure risks are, helping security and development teams align on what truly needs to be fixed.
This type of contextual intelligence is increasingly embedded within modern software supply chain security platforms, enabling organizations to move from raw vulnerability counts to policy-driven, risk-based decisions across the entire development lifecycle.
Can you stop malicious packages before they enter the SDLC?
The recent string of supply chain attacks highlighted by the Cybersecurity Agency of Singapore (CSA), which primarily target the npm registry, proves that the "front door" of your development environment is the primary gateway for risk. If a developer pulls a malicious package, the attack succeeds before the code is even scanned.
This makes preventive controls at the point of consumption critical. Verifying packages, plugins and AI models against organizational policy before they enter the SDLC can eliminate entire classes of attacks upfront. In regulated sectors, this “verify, verify, then trust before use” model is becoming essential.
What’s the value of a Single System of Record (SOR)?
Security breaks down when development, security and compliance teams operate from different versions of the truth. Fragmented tooling creates what many CISOs now describe as a “trust gap” where no one can confidently answer what is running, who approved it, or whether it meets policy.
A centralized SOR for software artifacts enables consistent policy enforcement across pipelines, continuous collection of audit evidence, and alignment among teams on risk decisions. This is especially relevant in Singapore’s compliance-driven environment, where traceability and accountability increasingly extend beyond code into AI models and data pipelines.
AI raises the stakes further
AI-driven development now extends beyond prompts into models, agents, skills, plugins and MCP gateways that execute within enterprise environments. These components are not abstract inputs. They are software artifacts that can introduce risk if not governed properly.
Without centralized governance, they can enter pipelines, developer environments and production systems without verification, provenance tracking or policy enforcement. That lack of control creates a blind spot, as in the early days of open-source adoption.
Regulatory frameworks, including Singapore’s Model AI Governance Framework for Agentic AI, signal that accountability will extend beyond source code into the broader AI software supply chain. Enterprises must treat AI artifacts with the same rigor as binaries: versioned, verified, governed and auditable within a trusted system of record.
Meeting these guidelines and safeguarding systems demands greater transparency, traceability and governance across both traditional software components and AI assets.
Securing what runs
Modern application security can no longer stop at the code level. It must reflect how software is truly built, secured, deployed, and managed today.
For Singapore organizations balancing speed, trust and compliance, a software supply chain security platform that governs binaries, AI artifacts and dependencies as a unified system of record is no longer optional. It is foundational.
The views and opinions expressed in this article are those of the author and do not necessarily reflect those of CDOTrends. Image credit: iStockphoto/Aleutie
Sunny Rao, JFrog
Sunny Rao is the senior vice president for APAC at JFrog.