JFrog Introduces Zero-Touch Remediation to its Self-Healing Software Supply Chain
JFrog Ltd., creators of the JFrog
Software Supply Chain Platform, the system of record for trusted software
artifacts, binaries, and AI assets, today introduced JFrog Zero-Touch
Remediation and announced the initial partners in its JFrog Self-Healing
Software Supply Chain Security Ecosystem. Zero-Touch Remediation automatically
finds the best available fix for a known vulnerability from any ecosystem
partner and applies it through the customer's pipeline, without breaking a
build, forcing a version update, or disrupting developer workflows. Together,
JFrog and its ecosystem partners neutralize vulnerabilities before attackers
can exploit them - shrinking the gap between discovery and remediation to
near-zero – turning the self-healing software supply chain from a concept into
a working reality.
"The traditional security
playbook – finding vulnerabilities, opening tickets, waiting weeks for manual
patching – has become a liability in the frontier AI era. Enterprises now face
adversaries who move at agentic speed and regulators who demand provable
evidence at every step," said Eyal Dyment, Vice President of Security
Products, JFrog. "Our customers need a supply chain that identifies
vulnerabilities and remediates them, without human intervention, as soon as a
fix is available – collapsing the remediation SLAs their boards now mandate
from weeks to minutes. Zero-Touch Remediation makes that possible – using
Artifactory's role in the organization as the single source of truth for all
artifacts, it consumes every partner fix natively, applies the best available
match, serves the fixed version to new builds and attests every action through
JFrog AppTrust."
The security team's job has
always been to move faster than the attacker. When AI can find and weaponize a
vulnerability in minutes and hours, that race is no longer a human-scale
problem. Gartner identified software supply chain attacks among the top four
critical security threats where attackers currently hold the advantage due to
Frontier AI – and the firm’s inaugural Magic Quadrant for Software Supply Chain
Security - in which JFrog was positioned as a Leader confirmed the industry's
shift toward dynamic, self-healing platforms
as the answer. AI has moved
from an assistant to a skilled attacker, to now autonomously finding
vulnerabilities that were previously overlooked in critical attack paths and
generating working exploits without human guidance – before any CVE is ever
published.
From Vulnerability to Fix in
Minutes, without a Human in the Loop The JFrog Self-Healing Software Supply
Chain operationalizes the five pillars of software security – prevention,
detection, prioritization, remediation, and provable auditability – as one
continuous, machine-speed workflow.
● Prevent: Stop threats before
they enter – To help developers ship secure software without adding friction,
JFrog Curation with Compliant Version Selection blocks risky packages, AI
assets, IDE extensions, and third-party components the moment a developer tries
to pull them – transparently serving the policy-compliant version instead. ● Detect:
See the full chain before the attacker does – JFrog Xray and JFrog Advanced
Security deliver unified detection from a single system of record – scanning
release artifacts for every dependency, catching vulnerable code patterns
before they ship, and surfacing exposed credentials across every artifact type.
● Prioritize: Act on real vs.
theoretical risk – Helping to cut CVE noise, JFrog Contextual Analysis
evaluates every finding for reachability and exploitability. JFrog Runtime
narrows the list further to what is actually loaded in production and JFrog
AppTrust adds business criticality – reducing thousands of tickets to a short
list of confirmed exposures.
● Remediate: Fix faster than
the threat spreads – For third-party software packages, the new JFrog
Zero-Touch Remediation automatically pulls the best available patch from
ecosystem partners and applies it transparently. For first-party code, JFrog’s
complementary Agentic Remediation enables developers to generate and validate
AI-driven fixes at the pull-request level for developers to review and validate
before merges.
● Prove: Every fix, every
attestation, one evidence chain – JFrog AppTrust automatically records
cryptographically signed attestations for every action, delivering a
comprehensive, regulator-ready audit trail of the entire software supply chain’s
status for every release, available at any point in time. This is DevGovOps:
governance ingrained into the pipeline itself, so when the auditor asks,
compliance proof is already there.
Why Only JFrog can deliver a Self-Healing Software Supply Chain
"Frontier AI has forced
every enterprise to ask the same question: how do you remediate faster than an
autonomous adversary can weaponize a vulnerability? No single vendor solves
that challenge alone," said Gal Marder, Chief Strategy Officer, JFrog. "Each
of our ecosystem partners has built differentiated patching capabilities no
single company could replicate. JFrog Artifactory is the single source of truth
for Artifacts – where every artifact lives – binaries, containers, libraries,
AI models, MCP servers, agent skills. It is the control plane allowing
organizations to serve every fix with zero-touch. We ingest each partner's fix
natively, use the customer's policy to apply the best one, and produce a
complete signed evidence chain the auditor can verify. Customers keep the
freedom to choose the best fix. JFrog delivers the governance that makes it
work."
Self-healing is what becomes
possible when every artifact in the enterprise flows through a single system of
record, which in turn acts as a single source of truth. Together with Broadcom
Tanzu, Chainguard, Echo, IBM/Red Hat, Moderne, Seal Security and TuxCare, JFrog
Zero-Touch Remediation matches each fix to the vulnerable artifact, applies it
without breaking builds, and attests it through JFrog AppTrust – regardless of
which partner produced the fix. · Broadcom: Spring patches from the
maintainers, authored before public disclosure and built to SLSA Level 3; Plus,
curated, verified builds across Java, Python, and Node.js. · Chainguard
Libraries: Malware-free Java, Python, and JavaScript packages that also have
built-from-source backported versions that fix critical and high-severity CVEs.
· Echo Libraries: Coverage for npm, PyPI, Java, Go, dotnet, Perl, and more,
with critical and high CVE patches on the versions teams already declare,
including transitive dependencies. · IBM/Red Hat Lightwell: Lightwell, a joint
initiative between Red Hat and IBM, provides organizations with critical access
to security remediations and mitigations, helping them more easily and quickly
address vulnerable third-party open-source dependencies. · Moderne Backpatch
Alliance: Critical end-of-life OSS packages backpatched by the original
maintainers, cherry-picked from upstream commits and published as standard
Maven artifacts. · TuxCare SecureChain: Open-source packages rebuilt from
source, screened for malware, and continuously patched – including Endless
Lifecycle Support after upstream maintenance ends. · Seal Security: Standalone
backported patches that keep the same version number, cryptographically signed,
with a 72-hour SLA for both high and critical CVEs.
“Open source libraries have
become a critical attack surface for modern applications,” said Patrick
Donahue, Senior Vice President, Product, Chainguard. “By integrating Chainguard
Libraries with JFrog Zero-Touch
Remediation, we’re making it easy for mutual customers to replace vulnerable
dependencies with Chainguard’s secure-by-default language libraries directly
within JFrog, preventing malware and CVEs without adding friction for
developers.”
































Leave A Comment