JFrog Ltd has launched JFrog Zero-Touch Remediation and revealed some of the initial partners for its Self-Healing Software Supply Chain Security Ecosystem. The feature automatically selects appropriate vulnerability patches provided by the ecosystem partners and deploys the same via customers’ software pipeline. This is accomplished without compromising the build, requiring any version upgrade or interfering with developers. According to JFrog, such an approach can shorten the gap between vulnerability detection and fixing almost to zero.
Machine Speed Vulnerability Fix:
Eyal Dyment, Vice President of Security Products at JFrog, noted that “the old-school approach of vulnerability scanning, ticket creation, and weeks of patching is no longer sustainable in the AI age. Enterprises need to deal with adversaries who move at agentic speeds and regulators who want proof of each step.
The supply chain our customers need will detect vulnerabilities and remedy them without human intervention as soon as a fix is available, reducing the SLAs required by their boards for the remediation from weeks to minutes. Zero-Touch Remediation will make that happen, utilizing the role that Artifactory plays within the organization as the single source of truth for all artifacts, consuming all the fixes from the partners natively, applying the best matching fix, serving the fixed artifact to new builds and attesting all actions through JFrog AppTrust.”
According to JFrog, the rise in AI-powered cyberattacks has been adding more pressure on security teams to remedy vulnerabilities faster. The company referred to Gartner research, which highlighted the importance of addressing the risks of software supply chain attacks as one of the four critical threats needing urgent improvement. In addition, JFrog referred to its placement in Gartner’s first-ever Magic Quadrant for Software Supply Chain Security as a Leader.”
Self-healing software supply chain five pillars:
The company stated that their self-healing software supply chain has a workflow that integrates prevention, detection, prioritization, remediation and auditability. The JFrog curation with compliant version selection prevents any package, AI assets, IDE extension and third-party components from being developed.
JFrog Xray and JFrog advanced security ensure unified detection of software dependencies, code patterns, credentials and release artifacts. JFrog contextual analysis evaluates the findings based on their reachability and exploitability, and JFrog runtime detects vulnerabilities in the production process.
JFrog AppTrust takes into account the business criticality and generates cryptographically signed attestations of actions performed in the software supply chain. Zero-touch remediation then applies the partner-generated fixes to third-party packages without causing interruptions to builds. Agentic Remediation provided by the company helps developers to create and validate AI-driven fixes at the pull-request level.
JFrog expands its security ecosystem
Gal Marder, Chief Strategy Officer, JFrog, said, “Frontier AI has forced every enterprise to ask the same question: how do you remediate faster than an autonomous adversary can weaponize a vulnerability? No single vendor solves that challenge alone. Each of our ecosystem partners has built differentiated patching capabilities no single company could replicate. JFrog Artifactory is the single source of truth for Artifacts – where every artifact lives – binaries, containers, libraries, AI models, MCP servers, agent skills. It is the control plane allowing organisations to serve every fix with zero-touch. We ingest each partner’s fix natively, use the customer’s policy to apply the best one, and produce a complete signed evidence chain the auditor can verify. Customers keep the freedom to choose the best fix. JFrog delivers the governance that makes it work.”
Patrick Donahue, Senior Vice President, Product, Chainguard, said, “Open source libraries have become a critical attack surface for modern applications. By integrating Chainguard Libraries with JFrog Zero-Touch Remediation, we’re making it easy for mutual customers to replace vulnerable dependencies with Chainguard’s secure-by-default language libraries directly within JFrog, preventing malware and CVEs without adding friction for developers.”
Gunnar Hellekson, Vice President & General Manager, Lightwell Business Unit, Red Hat, stated, “The threat timeline in AI has compressed to such an extent that the debt on security is a risk today. Industry requires remediation, and not just vulnerability identification. In order to address this requirement, Lightwell acts as a collaborative clearinghouse, where we combine the speed of AI and human knowledge to deliver the fix.”








