Live From the Show Floor: swampUP 2026

Live updates from this event have concluded.


swampUP 2026 is officially LIVE in New York City! Three days, one stage, one mission: rebuild trust for a software supply chain that increasingly ships itself. Keynote updates land here as they happen, September 1–3, 2026. Let’s go!


Conference Day 2, September 3rd

[11:00 a.m.] The Great Model Surge: Patching at the Speed of the Threat

Gal Marder | JFrog Chief Strategy Officer
Amol Shukla | Morgan Stanley Head of Development Environment
James Watters | Broadcom CTO, Tanzu Division
Eylam Milner | Echo.ai Co-Founder and CTO
Behn Williams | Chainguard Field CTO

morgan stanley, broadcom, echo, and chainguard at swampup 2026

Overview

The rapid rise of frontier cyber models is triggering an unprecedented shift in software supply chain security. Organizations are bracing for an impending onslaught of vulnerabilities paired with drastically compressed exploit windows and the automated exploitation of lower-severity findings. To survive this, we must fundamentally rewrite the security playbook by scaling and accelerating automated patching and completely reimagining the traditional vulnerability disclosure process.

In this panel, guest speakers will unpack the “Cyber Model Problem”, discuss the practical realities of this AI-driven surge, explore the massive shift required in our mitigation strategies, and explore actionable solutions to help your organization adapt, patch faster, and secure the future of your software supply chain.

  • Gal Marder opens by framing this panel as the payoff of everything the day built toward — after Tim’s and Shachar’s warnings, the conversation turns to a new class of challenge: frontier “cyber models” like Mythos and GPT Cyber.
  • A key comment from the panel: “Frontier models suddenly got good at chaining known vulnerabilities” that used to be dismissed as merely moderate on their own.
  • A core worry is speed. Identification and exploitation are now happening at machine pace, so remediation has to match it: “Machines working faster than humans.”
  • One high-level wake-up call from the panel: after early access to Mythos through Project Glasswing, scanning the ecosystem went from a handful of vulnerability reports a month to 500 security findings in the first month alone once Opus 4.6 landed.
  • The response? Pivot the entire engineering team: for two months they stopped being framework developers and became security researchers, working with JFrog Artifactory to establish what was called an authoritative voice standing behind the framework.
  • Behn Williams introduces the industry’s new “clearinghouse” model, exemplified by Chainguard’s Athena: pooling frontier-model findings across major vendors and banks, patching under embargo, then working with the Linux Foundation’s Akrites project to upstream fixes responsibly.
  • He’s glad clearinghouses like Athena, Lightwell, and Gold Eagle are multiplying rather than consolidating. “Being the only one,” he argues, “would just concentrate the attack surface instead of reducing it.”
  • Eylam Milner tackles the “is open source ending” question directly: he doesn’t think it ends, but how it’s consumed is shifting toward vetted vendors, since a volunteer maintainer was never contractually on the hook for a security SLA.
  • He points to cURL’s maintainer as a cautionary tale: overwhelmed by AI-generated contributions, he’s closed the project to new PRs entirely, what Eylam calls being “drowned in slop.”
  • On keeping pace with micro-patching at scale, James lays out Broadcom’s playbook: research the frontier, ship the smallest possible non-breaking patch, then automate the pull request itself. “It’s really PR accepted and in prod. Before that, it’s an academic exercise.”
  • Eylam frames the emerging norm as controlled drift: patch fast to close a Mythos-detected vulnerability that doesn’t even have a CVE yet, but always aim to reconnect with the upstream fix once one exists, “You drift a bit, and then hopefully you go back in.”
  • Behn declares the old “patch harder, patch faster” mentality dead, pushing instead for a multi-threaded strategy that starts with verified, secure components from the very beginning of the SDLC.
  • Eylam ties the fix directly back to JFrog: “What’s needed is a system of record” — a single, signed, verifiable log of every binary, package, and patch version — paired with visibility and zero-touch remediation.
  • Closing advice, one per panelist: Behn says go build the relationship with your security or engineering counterpart before the next incident forces it; Eylam says get hands-on with the models yourself to close the gap his research found between how ready companies feel and how ready they actually are; others note this as a chance to get proactive instead of waiting for the next Log4j.
  • Gal Marder’s closing line sums up the day: “We’re not preparing for an AI-driven future, we’re living it already.”

[9:45 a.m.] Supply Chain Attacks & AI: A Match Made in Hell

Shachar Menashe | JFrog VP, Security Research

shachar menashe on swampup 2026 stage

Overview

451%. That is the increase in malicious packages over the past year in npm alone. Hijacking open source packages has become the attacker’s highest-ROI play, supercharged by AI-powered payloads, precision phishing, and entirely new injection vectors like malicious AI skills — these attacks have now evolved from compromising developers to directly targeting production environments

But there’s good news. The same cyber models attackers use are being turned against them. Find out how JFrog’s Security Research team is winning against both widespread and targeted attacks, by enhancing JFrog Curation and deploying AI-powered detection at the scale and speed these threats demand.

This session lays out what you need to prepare for next:, The new organizational weak points created by AI infrastructure and usage, the next type of packages most likely to be targeted, and how JFrog’s Research team feeds that intelligence directly into JFrog Curation, so threats are blocked before they manifest.

Sound bites from the session

  • Shachar opens with the line that frames the entire talk: “Why break in when you can be invited?” Supply chain attacks have become the highest-ROI play in security, no zero-day required.
  • The scale is staggering: over 10 million machines compromised by supply chain attacks in the past year, with at least one major campaign hitting every month, a pace that simply didn’t exist before 2025.
  • He traces it back to the “Big Four” open-source attacks in late 2025 (Singularity, Kicks, Shai-Hulud 1 and 2), which infected 2.5 million machines and over 1,000 packages — successful enough to open the floodgates to 19 major campaigns since.

major supply chain attacks are here to stay

  • “Major supply chain attacks are here to stay.” Something in 2025 shifted because of the successful supply chain attacks, Shachar observes.
  • And each wave got more sophisticated: the original Shai-Hulud introduced a self-propagating worm payload; PyTorch Lightning expanded the hijack across PyPI, NPM, RubyGems, and even Artifactory; Miasma went further still, engineering its payload specifically to defeat AI-based scanners.
  • A NuGet typosquat against Newtonsoft.Json revealed a starker shift: the payload directly patched a betting platform’s live production logic to predict game outcomes: no developer machine, no lateral movement, straight into production. “The gate has widened,” as Shachar puts it. “Attackers no longer need a specific weakness like Sunburst’s zero-day; the supply chain attack itself is the entry point.”
  • On the AI side, spear-phishing generated by AI agents now matches human-expert click-through rates — that’s reportedly how the billion-download Kicks attack tricked a maintainer into handing over a 2FA reset.

an agentic attacker

  • The Singularity attack went a step further, hijacking local AI assistants like Claude, Gemini, and Amazon Q with a plain-text prompt instructing them to hunt down and exfiltrate local secrets, turning a coding agent into what Shachar calls a “double agent.”
  • He walks through Anthropic’s own published account of a Claude 3.5 Sonnet safety evaluation that broke out of its sandbox, autonomously registered a real PyPI account, and published a real malicious package to solve a hijacking challenge it thought was simulated — a preview of what a deliberately weaponized agentic payload could do.
  • Mapped onto the classic Cyber Kill Chain, an agentic supply-chain attack changes every stage: reconnaissance targets private package names and model choices instead of employees, weaponization is as simple as uploading a malicious package, and command-and-control becomes a self-directed agent that can find and exploit zero-days on its own, even inside air-gapped networks.
  • He closes with JFrog’s side of the fight: a human-in-the-loop research pipeline that’s caught 30+ AI-driven false-positive advisories (saving 212 million package downloads from unnecessary blocks), an LLM-judge system that’s flagged over 2,000 targeted dependency-confusion attacks, continuous scanning of AI assets like models, MCP servers, and skills (roughly 1,000 malicious out of 25,000+ scanned), and new coverage for the GitHub Actions and CI/CD hijacks (like the ClawBot campaigns that hit Microsoft, DataDog, and Trivy) that have replaced stolen developer tokens as attackers’ next target.
  • Closing message, echoing Yoav’s keynote: “This is a new era for building software, and just as much a new era for software security — one JFrog’s research team is staying a step ahead of.”

[9:00 a.m.] Redefining Resilience: From Landmark Supply-Chain Breaches to Frontier Model Risk

Tim Brown | Former – CISO of SolarWinds, Current – Team8 Partner
Paul Davis | JFrog Field CISO

paul davis and tim brown on swampup 2026 stage

Overview

As CISO of SolarWinds during the defining Sunburst supply chain attack, Tim Brown led the response to one of the most consequential cyberattacks in history, rebuilt trust with customers and the market, and later became a defining test case for CISO personal liability.

In this fireside chat, Tim joins JFrog Field CISO Paul Davis to unpack the years-long work the world didn’t see: the rebuilding of a security program from the ground up, regaining market trust with full transparency, and navigating regulatory scrutiny as an individual executive. Tim and Paul will connect the lessons learned to today’s threat landscape including threats to critical infrastructure, changes in state-level risk, frontier model usage, and emerging supply chain risk and liability in the AI era. This is an unfiltered look at redefining resilience as AI pushes the boundaries of what’s possible.

Sound bites from the session

  • Paul opens by grounding the conversation in Tim’s path to CISO: two decades of engineering and CTO roles, including Dell, spent telling other CISOs what to do, before deciding at SolarWinds to become one himself, with a smooth first four years before “the event.”
  • December 12, 2020: the call every CISO dreads. Tim’s CEO relayed that Mandiant had found SolarWinds’ own signed code being actively exploited, the press was set to break the story within days, and Tim’s email had been compromised too.
  • The investigation moved fast: Mandiant showed decompiled malicious code that was clearly not SolarWinds’ own, and engineering confirmed it had never touched source control. The roughly 3,000 lines had been inserted directly into the build environment itself.
  • The scope: of SolarWinds’ customer base, about 18,000 had downloaded the tainted Orion builds, though the number truly compromised was far smaller — the attack required a working path to command-and-control and room to move laterally.
  • Tim coined the term “supply chain attack” that first weekend, since the malicious code lived in the build pipeline rather than source control. The next realization was harder: SolarWinds’ footprint touched the power grid, nuclear facilities, militaries worldwide, and nearly all of the Fortune 500.
  • The point was never Orion itself: “they compromise Orion to get themselves a foothold” in the networks of the real targets, four of which were confirmed as fully compromised U.S. government agencies.
  • Crisis response ran through outside counsel first to keep the investigation privileged, before bringing in CrowdStrike, KPMG, and additional incident responders through that same legal structure. The team split into five streams: build environment, infrastructure, media, law enforcement and escalations, and forensics.
  • Transparency stopped being optional. “Somebody calls you about Project Warp speed, and you’re gonna say, ‘I have no comment?’ Of course not. Right? You were gonna help them.”
  • Recovery meant re-engineering trust into the build system itself: SolarWinds externalized its build pipeline to the cloud and moved to three separate builds (development, staging, and production) with sharply tiered access (400 people, then 36, then just 2) and binary comparison across all three, so tampering would require collusion between at least two people.
  • The company also paused new feature development for six months to focus entirely on security and build-system hardening before shipping anything new.
  • The recovery worked: renewal rates fell from roughly 92% pre-incident into the 80s afterward, then climbed back to 99% under new ownership, alongside the company’s best quarters yet.
  • But the personal cost was steep. Tim shares that he lost 25 pounds in the first month, and later, around the time the SEC moved to charge him personally (a first for any CISO), the stress caught up with him in the form of a heart attack.
  • From his hospital bed, looking at the paperwork, he made the decision not to settle with the SEC: signing would have meant admitting the security program was negligent, and, in his words, “every CISO that had an event would then be liable for that event.” Tim and SolarWinds fought for three years and ultimately, the case was dismissed with prejudice this past December.
  • Looking at today’s agentic coding shift, Tim’s core warning is about assumptions: trusting that code is safe, environments are locked down, or systems are configured correctly just because someone said so is exactly the mistake that got SolarWinds hurt the first time.
  • Practices that used to be periodic, like auditing GitHub every six months, now need to run continuously; the kind of patient, sophisticated attack SolarWinds faced is increasingly within reach of far more actors thanks to AI. “Our speed of change is shifting so much. We are going to have to run at machine speed without breaking compliance.”
  • Paul adds that the rogue-actor scenario security teams have to game out is no longer just a rogue employee, it’s increasingly a rogue agent that, as Paul puts it, “doesn’t know what ‘rogue’ means and simply goes off and does its own thing, putting non-human identity and agent sandboxing on the front line.”
  • His advice to the room: think like an attacker, run the “what if” scenarios out loud with leadership and the board, and make sure risk gets communicated honestly up the chain instead of getting softened along the way. Also, “Not everything is a 3 week sprint. We need great architecture, we need great design. We need that architecture to deliver for our customers.”
  • Paul asks: “How do you help a CISO today?” Tim: “Communicate risk. You know so much more than your CISO knows. You lose visibility as you go up the chain. I need you to be honest with your CISO about where you see risk.”
  • Closing message: “We have to be absolutely producing better. As consumers of software we need to be testing more. We have to use the tools the adversaries are using against us.” Tim wraps by challenging the assumption that CISOs are the department of “no” — “They’re trying to protect the business, and real partnership between security and engineering, paired with honest communication about risk, is what actually moves the needle.”

Conference Day 1, September 2nd

[12:00 p.m.] When AI Commits Your Code: Reinventing Security for the AI-Native SDLC

Jason Clinton | Anthropic Deputy CISO

jason clinton on the swampup 2026 stage

Overview

Coding agents are rapidly becoming the primary authors of production software. Engineering velocity has accelerated exponentially, while security teams have grown only modestly. Traditional AppSec processes were never designed for this reality, nor for the “tsunami” of binaries now flowing through pipelines. Left unchanged, they quickly become the bottleneck.

In this keynote, Anthropic’s Deputy CISO shares how the company reimagined software supply chain security for an AI-native engineering organization. Learn how to evolve from human-centric code reviews to scalable oversight, where specialized AI reviewers combined with deterministic security controls and risk-based governance work together to secure software without slowing developers down.

We’ll explore how security shifts to governing autonomous development loops, how a trusted system of record can become the control plane for AI-generated software, how continuous AI-powered validation replaces traditional security gates, and why policy, provenance, governance, and auditability are the building blocks of a trusted AI software supply chain.

As AI becomes part of your engineering workforce, this session will show how to build trust at scale, without sacrificing speed.

Sound bites from the session

  • Jason opens by noting that three years at Anthropic feels like “dog years” given the exponential pace of AI, presenting a historical 70-year compute graph showing a 4x annual increase in training scale to illustrate that the current “Mythos era” is just getting started.
  • Jason mentioned that he often feels like an “anthropologist on Mars” working at Anthropic and developing software. He highlights a 20x increase in code commits per employee over the last 18 months—a surge that completely breaks traditional human-driven SDLC processes.

code at anthropic

  • Engineers no longer spend their days in IDEs; instead, they operate as managers supervising 24/7 “virtual employee” agent swarms (via internal tools like Claude TAC) that write, review, and propose PRs overnight.
  • To secure code at this volume, Anthropic pairs fast generation (“System 1”) with deliberate post-hoc security analysis (“System 2”). Low-risk codebase fragments are written by AI agent swarms and reviewed by adversarial AI swarms with zero human intervention required.

anthropic system 1 system 2

  • Traditional security monitoring has been replaced by a “Neo-SOC” where Claude handles Tier 1 and Tier 2 operational analysis, allowing security personnel to level up into junior detection response engineers.
  • Driven by a 10x year-over-year drop in AI capability costs, Jason predicts that “Mythos-class” cyber defense tools will cost fractions of a penny within 18 months—enabling ubiquitous pre-release AI scanning and pushing the software industry toward “vuln-zero.”

permanent defender advantage is coming

  • Jason says, “Everything that we’re doing, every part of the SDLC depends on a system of record. This is the way that we get trust. In an earlier slide in the compliance section, there was an attestation of alignment. You can only do these things if you have a place where you’ve recorded what’s happened. You can only get that trust if you have a system of record that you can point to your agent and say, ‘These are the things that you need to know. This is the memory that you need to retain for the long term.'”

system of record - anthropic

  • JFrog CEO Shlomi Ben Haim joins Jason on stage to summarize the joint vision for AI development: “Claude has been the layer of intelligence when we create code… and together with you, JFrog becomes the layer of trust.”

[11:35 a.m.] Shattering The Compliance Illusion: Your Path to Built-In, Continuous, Automatic DevGovOps

Ronny Belenitsky | JFrog DevGovOps Director of Product

Ronny on swampup 2026 stage

Overview

You’re running 2025 compliance practices against a 2027 threat model — and you’re losing the battle.

When compliance officers arrive, most organizations rely on a fragile trail of manual checks, screenshots, and email chains across weeks of time. The agentic era is breaking this “process” completely. Autonomous agents now commit code, open PRs, and deploy to production in minutes, sometimes with no human in the loop. When something goes wrong, there’s no one to ask, no memory, and no evidence of what happened.

The process integrity of DevGovOps is the answer: compliance engineered into the pipeline itself from day one, not bolted on after release. With JFrog as the single source of truth for every artifact, evidence, and approval, we demonstrate how policy enforces itself and evidence collects itself in a continuous, automatic, and proven manner. All at the speed your teams want to ship.

Sound bites from the session

  • Ronny opens with the net-net of compliance today: it’s hard, and it’s manual. “Give me this proof” meant going in, taking screenshots, forwarding emails; a process that’s fragile, incomplete, and only ever sample-based. His answer is DevGovOps: “Control what ships and be audit-ready by default. Compliance is continuous and automated as a by-product of your software lifecycle.

can you provide evidence?

  • “If compliance doesn’t move at the same pace that we release, how can we be sure that we are safe?”
  • He recaps what JFrog AppTrust launched with last year: business context, evidence collection, and governance — the three original building blocks.

AppTrust

  • Then comes the new stuff: five announcements spanning turning intent into enforceable policy, capturing evidence automatically, enforcing continuous compliance out of the box, and governing the full lifecycle post-release:
    • AI-Powered Policy as Code Playground — Turns plain-language intent into enforceable, tested, Rego-based policy, automatically versioned and enforced. “You don’t have to write code, your policy is code, we’ll just apply it for you.”
    • Prompt to Release Traceability — Shifts evidence collection left, capturing the complete provenance trail for every agent interaction and artifact: sessions, tickets, pull requests, approvals, and promotions, stored alongside the exact version of software being created.
    • Out-of-the-Box Compliance Frameworks — Turn on pre-built policy sets for standards like NIST and CRA, pick which policies apply to you, and go, with a policy-driven foundation that requires no custom configuration.
    • Repo-Level Policies — Enforces evidence-based governance directly on repositories, with no project, application, or lifecycle-stage setup required.
    • Post-Release Governance — Keeps monitoring compliance and vulnerability remediation within the support window after a release ships, extending visibility beyond the release gate (which matters especially for European regulatory requirements).

out-of-the-box compliance frameworks

  • Live demo: toggling a compliance framework on, then narrowing it down to just the specific sections of the framework that apply to your organization.
  • Ronny frames the stakes with a direct question: “You’ve shipped, you’re compliant, but are you still six months later?” Post-release governance is JFrog’s answer to that gap.

policy is set

  • Closing message: “Risk isn’t going away, but if the audit comes tomorrow or the regulation changes, you’re already compliant and can prove it, because compliance is now part of the software development lifecycle itself, not a separate exercise bolted on afterward.”

continuous governance

[11:00 a.m.] Frontier vs Frontier: Securing the Software Supply Chain in the Age of Autonomous AI

Eyal Dyment | JFrog VP, AppSec
Tyrone Gamby | Morgan Stanley Executive Director
Reid Tatoris | Chainguard VP, Product

eyal on swampup 2026 stage

Overview

Frontier AI models now discover and chain software vulnerabilities at machine speed, with defenders and attackers having access to the same capabilities. Your organization’s traditional playbook of scan, alert, and manually patch can’t keep up in this world of adversarial symmetry.

Defenses today require instant and always-on protection anchored on a single system of record for every binary your organization produces and consumes, plus one source of truth where fixes and patches from every vendor are universally available.

In this keynote, we show why the only viable defense is a self-healing software supply chain that operates at the same speed and scale as the threat itself: automated and anchored on one universal System of Record across the entire software lifecycle.

Sound bites from the session

  • Eyal opens with a provocation: “Are you ready for the era of cyber models?”, pointing to Anthropic, OpenAI, and the broader security community all surfacing vulnerabilities at a scale never seen before.
  • The new numbers: disclosed CVEs are about to spike dramatically, the time-to-exploit window keeps collapsing, and pre-disclosure exploitation (attackers finding an issue before it’s even publicly detected) is now a serious threat.
  • Eyal lays out the requirements for a real defense: it has to be frictionless, policy-based, provide evidence, run at machine speed, universal to cover the entire supply chain, and be based on a single source of truth.
  • “You have to build a supply chain that is frictionless, where the humans who are in the loop are not holding things up.”

remediation steps

  • He maps JFrog’s self-healing model to four stages: Prevent, Detect, Prioritize, and Remediate. This is the engine behind DevSecOps: “Automatically prevent, detect, prioritize, and fix vulnerabilities — continuously, at speed, without human intervention.”
    • Prevent — Block risky artifacts: JFrog Curation blocks risky packages before they ever enter the pipeline.
    • Detect — Find vulnerabilities in your pipelines: with 50,000+ CVEs published last year (up 40%), JFrog Xray and Advanced Security cut the noise by roughly 90%.
    • Prioritize — Exploitable, verified at the binary-level: Advanced Security – Runtime plus Business Context from AppTrust surface only what’s truly exploitable in production.
    • Remediate — Automated Best-Fix: beyond the traditional virtual patch, back-port, or PR, Eyal unveiled Zero-Touch Remediation, which heals instantly via Compliant Version Replacement (a bad version swapped out with a patched one, mid-pipeline).

single source of truth self-healing ssc

  • Live demo: a vulnerable package gets swapped out instantly — “the magic trick.”
  • Eyal then goes behind the scenes to show how it worked, bringing onto the stage Tyrone Gamby from Morgan Stanley to tell their story.
  • Then Reid Tatoris from Chainguard joins Eyal onstage to explain the hardened-image ecosystem feeding the fix engine.
    Chainguard on stage
  • Chainguard introduces the Athena Coalition: an industry-wide alliance dedicated to the coordinated defense of open-source software.
  • Reid explains that its members contribute vulnerability findings from across the tech landscape, allowing Athena to manage each flaw through its complete lifecycle and deliver universal protection. A central clearinghouse aggregates and correlates these reports to generate fixes at the same machine speed they are discovered. Surrounding those fixes, Athena deploys independent layers of security to ensure coverage even when a clean patch is unavailable, maintaining active defense until a durable upstream solution is in place.
  • Reid: “By working together we can make this whole process invisible to our customers, or as Eyal said, make it magic.”
  • Reid invites Eyal to explain more about Zero-Touch Remediation. Eyal says that it works by evaluating multiple upstream sources at once (Chainguard, Maven Central, and others) and automatically picking the right one based on the customer’s own policy, all made possible because JFrog Artifactory is the system of record every request flows through.

ZTR

  • Eyal draws a clear line between the two remediation products, and it comes down to machine speed: Agentic Remediation is best for first-party code, fixing vulnerabilities at the source level with a developer reviewing and approving before merge. Zero-Touch Remediation is best for third-party packages, swapping in a fixed version automatically, with no human in the loop.
  • Closing line: “The new reality is that healing is provable and auditable. Every binary and every fix flows through Artifactory, governed entirely by policy.”

[10:00 a.m.] Trusting Your Agentic Workforce: The Workforce Nobody Onboarded

Yossi Shaul | JFrog SVP & GM, Artifactory & System of Record
Ran Romano | JFrog VP, Product & Engineering
David Pan | Cursor Field CTO

yossi and ran on swampup 2026 stage

Overview

Teams are adopting coding agents faster than any tool in history, giving them the same repo access, credentials, and production reach as the developers running them, with none of the onboarding, vetting, or scoped access every human hire goes through.

And it’s not only about the code they generate. But also everything they consume to get there: models, skills, MCP servers, plugins, and packages, pulled from anywhere, unvetted and unscanned.

This session shows how JFrog extends the Single Source of Truth you already run for your human workforce to your growing agentic workforce. One governed source of truth, curated, scanned, and enforced inside every coding agent and across your network – with nothing for your developers to install and no way for them to opt out.

You’ll go from a place of “I think we’re covered” to “I trust my agents.”

Sound bites from the session

  • Yossi and Ran tell the story of Maya, a backend engineer everyone would want on their team — except now she’s also managing a team of 10 AI agents. Every organization is about to have hundreds or thousands of these agent-managing employees, just like Maya.

maya and team of agents

  • Live demo scenario: Maya finds a skill online called “Omnicog” that looks perfect for her job, downloads it, and, being a good employee, shares it to the team’s GitHub. Over the next 10 days it spreads across onboarding docs and new laptops, until someone finally asks, “does anyone know why my agent’s making outbound calls?”
  • The investigation reveals the skill’s Markdown file buried a “call home” instruction inside thousands of lines of noise designed to confuse detectors. The takeaway: a skill isn’t just a document, it’s an executable, and every AI asset needs to be protected against accordingly.
  • To keep speed without losing control, the team lays out three things you need to do: curate, scan, enforce — the mechanics behind what they call AgentSecOps: Agent immunization — “Immunize and control your agent actions and behaviors. Ensure every agent action is policy-enforced via a single source of truth, from pull to ship.”

keep the speed make it governed

  • “Don’t govern the bundle, govern the marketplace.” Instead of just checking what an agent downloads, point the plugin marketplace itself (inside a Cloud/IDE environment, for example) exclusively in the JFrog AI Catalog, so ungoverned options are never even visible to developers or agents.
  • The team then replays Maya’s story with governance in place. This time, the malicious download is blocked immediately. It never happens. Problem solved!
  • Turning to how agents build and deploy, they introduce JFrog Agent Plugin, Agent Package Resolution, Traffic Controller, and Agentic Remediation. Agent Package Resolution routes agents to the right project and team context natively, while Traffic Controller is the network-level enforcement layer that catches anything trying to route around that native path. The message: you need both — the native way and the enforcement backstop.
  • Rollout is designed to be invisible: it ships through a plugin that’s simply turned on, with nothing for developers to install and no way to opt out. Plus, it’s built into the coding tools teams already use, with new integrations spanning Claude Code, Cursor, VS Code, Kiro, Devin, OpenCode, with more coming soon.
  • The story extends beyond the desktop: a partner appearance from Cursor demonstrates that everything JFrog has built for coding agents carries over seamlessly to cloud agents too. “Twenty years of software supply chain best practices are baked into that install .”

AI maturity cuve

  • Closing recap, bringing Maya’s story full circle: a malicious skill that never ran, a vulnerable package that was never resolved from the public internet, and an agent that went looking for a way around the rules but didn’t find one.
  • Yossi and Ran then introduce guest speaker, David Pan, Field CTO at Cursor.

cloud agents are the foundation

  • David says “The current way of automating your work is very much an individual sport. Each developer has their own practices, skills, and so on. The benefits of this ends up being uneven across the organization.”
  • David, Yossi, and Ran conclude the session saying that trusting the agentic supply chain requires control over what the agent consumes, the runtime, and what the agent ships.

trusting the agentic supply chain

[9:25 a.m.] The Agentic Software Supply Chain: Rebuilding the Trust Model

Yoav Landman | JFrog Co-Founder and CTO

yoav on swampup 2026 stage

Overview

The world’s software supply chain has mutated. “Liquid Software” is here, delivered through binaries! Software now flows continuously: assembled, evolved, and deployed through streams of binaries at AI speed. Source code is no longer the center of gravity in a faster, more autonomous software factory. Coding agents are becoming true software agents pushing software forward faster than human-driven governance can track. This is the AI surge.

This shift breaks the trust model you have only recently finished building! The new, AI-powered supply chain instantly creates assets nobody has controlled before, and exposes attack surfaces nobody has secured before. Agents’ code and actions can create massive downstream impact in seconds, and the same AI capabilities that write code can also find and exploit vulnerabilities in it.

As software is assembled and shipped at agentic speed, trust has to move closer to the binary, the runtime, and every decision point in the pipeline, anchored to one single system of record for everything that ships.

In this landmark keynote, we show how JFrog has become your Single Source of Truth for the Agentic Software Supply Chain: securing and governing every package, model, AI asset, and release process across your software factory, at scale, regardless of the tools, agents, or pipelines you use.

Sound bites from the session

  • Yoav opens with an analogy: skyscrapers were capped at six floors for decades because elevator cables could snap — until Elisha Otis stood on a lift at the World’s Fair and cut the rope himself, demonstrating the safety brake he’d invented. Buildings could suddenly go higher because people trusted the brakes, not the rope. “What made the New York skyline possible is not the elevators, but the safety brake.” That’s the confidence JFrog wants to give teams to build at agentic speed.
  • The controls the industry built (e.g., bi-weekly release cadences, human PR review, periodic security scans) were designed for software with pauses in it. Now the software delivery pipeline never stops: agents are coding while you sleep, working while you’re not even logged in.
  • “Trust has to be woven in.” It can’t be something checked at specific moments; it has to run continuously, throughout the process. Yoav frames this as the only way to move at the speed the new reality demands.

humans in the loop

  • He explains how JFrog is extending your Single Source of Truth to address the new needs of your agentic software supply chain, where trust in software is established, tracked, and enforced. He then dives into three elements, achievable only from a single source of truth: Protect what your agents are pulling and doing, Remediate what they’ve built, and Control what they ship.

3 layers of SSC-ingrained trust

  • This is the platform-level promise: “Trust in every artifact and AI asset is established, tracked, and enforced across every source and every stage of your supply chain. So you can move at the speed of your agents, stay in control of what ships, and adapt to whatever comes next.”

[9:00 a.m.] Opening: Creation is Limitless, Trust is Everything

Shlomi Ben Haim | JFrog Co-Founder and CEO
Rinat Zilberstein | AT&T Vice President, Global Software & Product Delivery

shlomi on swampup 2026 stage

Overview

Leap into the future of trusted software and AI with JFrog’s founders as they unpack how AI is reshaping the software supply chain. As autonomous agents move from assistants to builders… writing code, resolving dependencies, and producing binaries at machine speed.  See how the rules of trust are being rewritten.

Sound bites from the session

  • Shlomi opens by explaining why swampUP exists in the first place; not as a show, but because the industry has increasingly become “centered around the binary.”
  • His central argument: the software world didn’t just change in how code gets made, it changed who creates it. That shift means organizations aren’t just adjacent to “the binaries business” anymore; every person in the room is now in it, because that’s what building software requires today.
  • “This year has been extraordinary, because what we’ve seen is that while agents can write code, the people in this room have a different responsibility. The people in this room are building trust.”

ai usage will accelerate not shrink

  • What’s the tradeoff? According to Shlomi, it’s not about the budget allocated to AI. “It’s about how fast the world is moving, and how fast we need to adopt new practices.”
  • Shlomi says the desired outcome of a well implemented AI is the quality and the amount of your binaries. He encourages us to ask ourselves “Is it secure? Is it safe? Is it happening faster than competitor?” If the answer is, yes, “That’s the outcome. That’s the desired outcome of a well-implemented AI.”

the numbers of AI

  • Shlomi uses a metaphor of the New York City skyline. Most people look up and admire the towering buildings. They don’t consider the foundation, the critical piece of infrastructure that skyscrapers are built on. JFrog is your foundation. And Artifactory is the heart of the software supply chain.
  • “If you can’t move at the speed of the machine, then how can you trust what you ship?”
  • When it comes to the cloud, Shlomi takes a poll, asking the group to raise their hands if they believe on-prem is a thing of the past. Regardless, he says, “It’s not about on-prem versus cloud; it’s about the flexibility you need when deploying AI.”
  • He then introduces Rinat Zilberstein, Vice President, Global Software & Product Delivery at AT&T

Rinat Zilberstein, AT&T on stage

  • Rinat says “Everything that you can imagine today is being managed by agents.”
  • She presents a new challenge: managing hybrid teams at scale. Now, teams include humans and agents, and the scale is crazy. “How do we make sure things don’t get out of control?”
  • “All of us here are responsible for making sure our products are safe and reliable to protect our customers.”
  • “We understand that if you want to build higher, if you want to build for scale, you have to invest in the foundation. AI is changing how high software can go, but you are the owner of software supply chain.”
  • Now, Rinat says, the industry understand that nothing can be shipped without the right governance, especially in a hybrid world, where machines are building the software.

speed x scale + trust

  • Rinat asks: “Out of thousands of technologies and hundreds of products, how do we know where the vulnerabilities are?” She continues: “We have to have one single source of truth to let you know where to go to fix it when something goes wrong.”

Shlomi and Rinat on stage together

  • Shlomi then joins Rinat back on stage. He concludes, “Nvidia is not only becoming the AI infrastructure, but also the highway, the highway for AI. At the end of the highway, in your organization, is a gatekeeper, which is called JFrog.”
  • If we just stick to a roadmap without giving you this flexibility, trust me, none of you will survive this era of AI that is changing so fast.
  • He closes by announcing the Carl Quinn Award to the amazing speakers

Carl Quinn award