JFrog Ltd., creators of the JFrog Software Supply Chain Platform, today introduced JFrog Zero-Touch Remediation and announced the initial partners in its JFrog Self-Healing Software Supply Chain Security Ecosystem at swampUP 2026. Announced from Sunnyvale, California and New York, Zero-Touch Remediation automatically finds the best available fix for a known vulnerability from any ecosystem partner and applies it through the customer's pipeline, without breaking a build, forcing a version update, or disrupting developer workflows.
The traditional security playbook of finding vulnerabilities, opening tickets, and waiting weeks for manual patching has become a liability in the frontier AI era where adversaries move at agentic speed. The JFrog Self-Healing Software Supply Chain operationalizes prevention, detection, prioritization, remediation, and provable auditability as one continuous machine-speed workflow.
Prevent blocks risky packages through JFrog Curation with Compliant Version Selection. Detect provides unified detection via JFrog Xray and Advanced Security scanning release artifacts. Prioritize cuts CVE noise through Contextual Analysis evaluating reachability and exploitability. Remediate automatically pulls best available patch from ecosystem partners for third-party packages through Zero-Touch Remediation, while Agentic Remediation generates AI-driven fixes for first-party code. Prove records cryptographically signed attestations for every action through JFrog AppTrust, delivering regulator-ready audit trail.
"The traditional security playbook – finding vulnerabilities, opening tickets, waiting weeks for manual patching – has become a liability in the frontier AI era. Enterprises now face adversaries who move at agentic speed and regulators who demand provable evidence at every step," said Eyal Dyment, Vice President of Security Products, JFrog. "Our customers need a supply chain that identifies vulnerabilities and remediates them, without human intervention, as soon as a fix is available – collapsing the remediation SLAs their boards now mandate from weeks to minutes. Zero-Touch Remediation makes that possible – using Artifactory's role in the organization as the single source of truth for all artifacts, it consumes every partner fix natively, applies the best available match, serves the fixed version to new builds and attests every action through JFrog AppTrust."
Together with Broadcom Tanzu, Chainguard, Echo, IBM/Red Hat, Moderne, Seal Security and TuxCare, JFrog Zero-Touch Remediation matches each fix to vulnerable artifact, applies it without breaking builds, and attests it through JFrog AppTrust. Broadcom provides Spring patches from maintainers built to SLSA Level 3. Chainguard Libraries offers malware-free Java, Python, and JavaScript packages with backported fixes. Echo Libraries covers npm, PyPI, Java, Go, dotnet, Perl with critical CVE patches. IBM/Red Hat Lightwell provides security remediations as collaborative clearinghouse combining AI-driven speed with trusted human expertise. Moderne Backpatch Alliance offers critical end-of-life OSS packages backpatched by original maintainers. TuxCare SecureChain delivers open-source packages rebuilt from source with Endless Lifecycle Support. Seal Security provides standalone backported patches with 72-hour SLA.
"Frontier AI has forced every enterprise to ask the same question: how do you remediate faster than an autonomous adversary can weaponize a vulnerability? No single vendor solves that challenge alone," said Gal Marder, Chief Strategy Officer, JFrog. "Each of our ecosystem partners has built differentiated patching capabilities no single company could replicate. JFrog Artifactory is the single source of truth for Artifacts – where every artifact lives – binaries, containers, libraries, AI models, MCP servers, agent skills. It is the control plane allowing organizations to serve every fix with zero-touch."
“Open source libraries have become a critical attack surface for modern applications,” said Patrick Donahue, Senior Vice President, Product, Chainguard. “By integrating Chainguard Libraries with JFrog Zero-Touch Remediation, we’re making it easy for mutual customers to replace vulnerable dependencies with Chainguard’s secure-by-default language libraries directly within JFrog, preventing malware and CVEs without adding friction for developers.”
“AI has collapsed threat timelines and accumulated security debt is now an immediate operational risk. The industry needs active remediation, not just vulnerability detection,” said Gunnar Hellekson, vice president and general manager, Lightwell Business Unit, Red Hat. “To help address this need, Lightwell serves as a collaborative clearinghouse – combining AI-driven speed with trusted human expertise to deliver tested fixes to customers and the open source community. By connecting Lightwell’s intelligence directly into the JFrog artifact workflow, we’re enabling customers to neutralize threats automatically while preserving the trust, governance, and community integrity essential to open source.”
About JFrog
JFrog Ltd. the creators of the unified DevOps, DevSecOps, DevGovOps, and AgentSecOps platform, is on a mission to create a world of trusted software delivery without friction from development to production. Driven by a “Liquid Software” vision, the JFrog Platform is a software supply chain system of record that is designed to power organizations as they build, manage, govern, and distribute secure software with speed and scale. Holistic security features help identify, protect, and remediate against threats and vulnerabilities. The universal, hybrid, multi-cloud JFrog Platform is available as both SaaS services across major cloud service providers and self-hosted. Millions of users and approximately 6,600 organizations worldwide, including a majority of the Fortune 100, depend on JFrog solutions to securely embrace digital transformation in the AI era.