swampUP 2026 Preview: The Trust Layer for the Agentic Software Supply Chain

Malicious packages and AI assets have grown 7.4x in the last three years. And yet, four out of five enterprises have no governance framework for coding agents. The software supply chain has become agentic, yet most enterprises are still securing and governing it with the manual systems from the last era.

This moment requires a fundamental shift: not just faster tools, but trust engineered into the very fabric of how software gets built and run.

swampUP is JFrog’s premier conference for leaders building software. Taking place September 1-3 in New York, the event will bring together practitioners and leaders across DevOps, DevSecOps, platform engineering, AI, and DevGovOps.

The conference will unveil the JFrog Trust Layer that helps you build trust directly into how you build, secure and govern software.

The Trust Layer: Building Trust Into Your SSC

So what does building trust look like in practice?

At swampUP, Yoav Landman, co-founder and CTO, will take an architecture-first approach to show you how JFrog is the Trust Layer for the agentic software supply chain. JFrog product leaders will walk you through the latest product announcements that tackle trust along three dimensions:

  • Immunize. Yossi Shaul, SVP & GM of Artifactory & System of Record, and Ran Romano, VP of Product & Engineering, AI Security, will illustrate how safety has to run in both directions: what your agents consume and what they produce. They’ll show you what it looks like when every model, MCP server, skill, plugin, and package coming in is governed before it’s trusted, and everything agents pull together and ship back out is held to the same standard.
  • Heal. Frontier AI can chain together multiple lower-severity vulnerabilities into one devastating multi-step exploit faster than any human remediation process can respond. Eyal Dyment, VP of AppSec will discuss how the only way to keep pace is with a software supply chain that is self-healing, detecting and fixing what’s broken autonomously, at the same speed it was introduced.
  • Govern. Ronny Belinitsky, DevGovOps Director of Product will explain why governance can’t be bolted onto the end of a pipeline as a checkpoint, and has to be engineered into the process itself, the way JFrog AppTrust builds governance into every stage of the release lifecycle rather than gating it at the finish line.

Training Day for the Questions You Haven’t Solved Yet

Training Day on September 1st exists to answer the burning questions keeping your team up at night:

  • How do I govern AI assets before agents consume them, without adding a manual review step that agents will just route around?
  • Is it possible for vulnerable dependencies to get fixed automatically instead of generating another ticket in the backlog?
  • How do I set up compliance monitoring that satisfies auditors without becoming the thing that slows my team down?

You’ll work through these directly with JFrog Solutions Experts, and the sessions carry CPE credit. But the real value is the one-on-one interactions you’ll get with peers in the industry who are setting out to solve the same challenges. Bring your actual architecture, your real environment constraints, and business goals, and work through them together.

Training Day spots go fast, so be sure to register quickly. 

Hear From Leaders Shaping the Future of the Software Supply Chain

swampUP always brings together the leaders who are actively shaping where the industry goes next and this year is no different. You’ll hear the direction that the software supply chain is heading, from the people setting that direction.

  • Jason Clinton, Deputy CISO at Anthropic, will share how we should rethink security assumptions for the agentic development era.
  • Tim Brown, Partner at Team8 (CISO at SolarWinds during one of the most consequential cyberattacks in history), will unpack the years-long work the world didn’t see and provide an unfiltered look at redefining resilience.
  • Moderne, Echo, Chainguard, and Tanzu Division of Broadcom will join a panel on “Patching at the Speed of the Threat” to share where remediation is headed as model releases outpace traditional security cycles.
  • NVIDIA will show how JFrog works as the system of record for NIM model infrastructure.
  • AWS will talk about maintaining trust from curation through production on Amazon Bedrock AgentCore.
  • Wiz, IBM/Red Hat (Lightwell), and Echo will guide us on the future of threat detection when threats move faster than teams can respond manually.

Beyond the Sessions: Fighter Pilots, Awards, and a Night on the USS Intrepid

The three things worth clearing your calendar for.

A special talk from Carey Lohrenz, the first female F-14 Tomcat fighter pilot in U.S. Navy history, on leading through uncertainty, and building trust when the stakes are highest.

The first-ever JFrog Software Supply Chain Excellence Awards, honoring the customers who’ve meaningfully pushed this space forward.

A community gala aboard the USS Intrepid, where both moments come together.

Plus the full slate you’d expect from a conference this size: an expo hall, executive roundtables, and the hallway conversations that often turn out to matter most.

Event Details

  • Dates: September 1-3, 2026
  • Location: New York City 
  • Registration: swampUP 2026

I hope to see you there!