Live From the Show Floor: swampUP 2026

swampUP 2026 is officially LIVE in New York City! Three days, one stage, one mission: rebuild trust for a software supply chain that increasingly ships itself. Keynote updates land here as they happen, September 1–3, 2026. Let’s go!


Conference Day 1, September 2nd

[10:00 a.m.] Trusting Your Agentic Workforce: The Workforce Nobody Onboarded

Yossi Shaul | JFrog SVP & GM, Artifactory & System of Record
Ran Romano | JFrog VP, Product & Engineering

yossi and ran on swampup 2026 stage

Overview

Teams are adopting coding agents faster than any tool in history, giving them the same repo access, credentials, and production reach as the developers running them, with none of the onboarding, vetting, or scoped access every human hire goes through.

And it’s not only about the code they generate. But also everything they consume to get there: models, skills, MCP servers, plugins, and packages, pulled from anywhere, unvetted and unscanned.

This session shows how JFrog extends the Single Source of Truth you already run for your human workforce to your growing agentic workforce. One governed source of truth, curated, scanned, and enforced inside every coding agent and across your network – with nothing for your developers to install and no way for them to opt out.

You’ll go from a place of “I think we’re covered” to “I trust my agents.”

Sound bites from the session

  • Yossi and Ran tell the story of Maya, a backend engineer everyone would want on their team — except now she’s also managing a team of 10 AI agents. And it’s not just Maya: every organization is about to have hundreds or thousands of these agent-managing employees.

maya and team of agents

  • Live demo scenario: Maya finds a skill online called “Omnicog” that looks perfect for her job, downloads it, and, being a good employee, shares it to the team’s GitHub. Over the next 10 days it spreads across onboarding docs and new laptops, until someone finally asks, “does anyone know why my agent’s making outbound calls?”
  • The investigation reveals the skill’s Markdown file buried a “call home” instruction inside thousands of lines of noise designed to confuse detectors. The takeaway: a skill isn’t just a document, it’s an executable, and every AI asset needs to be protected against accordingly.
  • To keep speed without losing control, the team lays out three things you need to do: curate, scan, enforce — the mechanics behind what they call AgentSecOps: Agent immunization — “Immunize and control your agent actions and behaviors. Ensure every agent action is policy-enforced via a single source of truth, from pull to ship.”

keep the speed make it governed

  • “Don’t govern the bundle, govern the marketplace.” Instead of just checking what an agent downloads, point the plugin marketplace itself (inside a Cloud/IDE environment, for example) exclusively in the JFrog AI Catalog, so ungoverned options are never even visible to developers or agents.
  • The team then replays Maya’s story with governance in place. This time, the malicious download is blocked immediately. It never happens. Problem solved!
  • Turning to how agents build and deploy, they introduce JFrog Agent Plugin, Agent Package Resolution, Traffic Controller, and Agentic Remediation. Agent Package Resolution routes agents to the right project and team context natively, while Traffic Controller is the network-level enforcement layer that catches anything trying to route around that native path. The message: you need both — the native way and the enforcement backstop.
  • Rollout is designed to be invisible: it ships through a plugin that’s simply turned on, with nothing for developers to install and no way to opt out. Plus, it’s built into the coding tools teams already use, with new integrations spanning Claude Code, Cursor, VS Code, Kiro, Devin, OpenCode, with more coming soon.
  • The story extends beyond the desktop: a partner appearance from Cursor demonstrates that everything JFrog has built for coding agents carries over seamlessly to cloud agents too.

AI maturity cuve

  • Closing recap, bringing Maya’s story full circle: a malicious skill that never ran, a vulnerable package that was never resolved from the public internet, and an agent that went looking for a way around the rules but didn’t find one.

[9:25 a.m.] The Agentic Software Supply Chain: Rebuilding the Trust Model

Yoav Landman | JFrog Co-Founder and CTO

yoav on swampup 2026 stage

Overview

The world’s software supply chain has mutated. “Liquid Software” is here, delivered through binaries! Software now flows continuously: assembled, evolved, and deployed through streams of binaries at AI speed. Source code is no longer the center of gravity in a faster, more autonomous software factory. Coding agents are becoming true software agents pushing software forward faster than human-driven governance can track. This is the AI surge.

This shift breaks the trust model you have only recently finished building! The new, AI-powered supply chain instantly creates assets nobody has controlled before, and exposes attack surfaces nobody has secured before. Agents’ code and actions can create massive downstream impact in seconds, and the same AI capabilities that write code can also find and exploit vulnerabilities in it.

As software is assembled and shipped at agentic speed, trust has to move closer to the binary, the runtime, and every decision point in the pipeline, anchored to one single system of record for everything that ships.

In this landmark keynote, we show how JFrog has become your Single Source of Truth for the Agentic Software Supply Chain: securing and governing every package, model, AI asset, and release process across your software factory, at scale, regardless of the tools, agents, or pipelines you use.

Sound bites from the session

  • Yoav opens with an analogy: skyscrapers were capped at six floors for decades because elevator cables could snap — until Elisha Otis stood on a lift at the World’s Fair and cut the rope himself, demonstrating the safety brake he’d invented. Buildings could suddenly go higher because people trusted the brakes, not the rope. “What made the New York skyline possible is not the elevators, but the safety brake.” That’s the confidence JFrog wants to give teams to build at agentic speed.
  • The controls the industry built (e.g., bi-weekly release cadences, human PR review, periodic security scans) were designed for software with pauses in it. Now the software delivery pipeline never stops: agents are coding while you sleep, working while you’re not even logged in.
  • “Trust has to be woven in.” It can’t be something checked at specific moments; it has to run continuously, throughout the process. Yoav frames this as the only way to move at the speed the new reality demands.

humans in the loop

  • He explains how JFrog is extending your Single Source of Truth to address the new needs of your agentic software supply chain, where trust in software is established, tracked, and enforced. He then dives into three elements, achievable only from a single source of truth: Protect what your agents are pulling and doing, Remediate what they’ve built, and Control what they ship.

3 layers of SSC-ingrained trust

  • This is the platform-level promise: “Trust in every artifact and AI asset is established, tracked, and enforced across every source and every stage of your supply chain. So you can move at the speed of your agents, stay in control of what ships, and adapt to whatever comes next.”

[9:00 a.m.] Opening: Creation is Limitless, Trust is Everything

Shlomi Ben Haim | JFrog Co-Founder and CEO

shlomi on swampup 2026 stage

Overview

Leap into the future of trusted software and AI with JFrog’s founders as they unpack how AI is reshaping the software supply chain. As autonomous agents move from assistants to builders… writing code, resolving dependencies, and producing binaries at machine speed.  See how the rules of trust are being rewritten.

Sound bites from the session

  • Shlomi opens by explaining why swampUP exists in the first place; not as a show, but because the industry has increasingly become “centered around the binary.”
  • His central argument: the software world didn’t just change in how code gets made, it changed who creates it. That shift means organizations aren’t just adjacent to “the binaries business” anymore; every person in the room is now in it, because that’s what building software requires today.
  • “This year has been extraordinary, because what we’ve seen is that while agents can write code, the people in this room have a different responsibility. The people in this room are building trust.”

ai usage will accelerate not shrink

  • What’s the tradeoff? According to Shlomi, it’s not about the budget allocated to AI. “It’s about how fast the world is moving, and how fast we need to adopt new practices.”
  • Shlomi says the desired outcome of a well implemented AI is the quality and the amount of your binaries. He encourages us to ask ourselves “Is it secure? Is it safe? Is it happening faster than competitor?” If the answer is, yes, “That’s the outcome. That’s the desired outcome of a well-implemented AI.”

the numbers of AI

  • Shlomi uses a metaphor of the New York City skyline. Most people look up and admire the towering buildings. They don’t consider the foundation, the critical piece of infrastructure that skyscrapers are built on. JFrog is your foundation. And Artifactory is the heart of the software supply chain.
  • “If you can’t move at the speed of the machine, then how can you trust what you ship?”
  • When it comes to the cloud, Shlomi takes a poll, asking the group to raise their hands if they believe on-prem is a thing of the past. Regardless, he says, “It’s not about on-prem versus cloud; it’s about the flexibility you need when deploying AI.”
  • He then introduces Rinat Zilberstein, Vice President, Global Software & Product Delivery at AT&T

Rinat Zilberstein, AT&T on stage

  • Rinat says “Everything that you can imagine today is being managed by agents.”
  • She presents a new challenge: managing hybrid teams at scale. Now, teams include humans and agents, and the scale is crazy. “How do we make sure things don’t get out of control?”
  • “All of us here are responsible for making sure our products are safe and reliable to protect our customers.”
  • “We understand that if you want to build higher, if you want to build for scale, you have to invest in the foundation. AI is changing how high software can go, but you are the owner of software supply chain.”
  • Now, Rinat says, the industry understand that nothing can be shipped without the right governance, especially in a hybrid world, where machines are building the software.

speed x scale + trust

  • Rinat asks: “Out of thousands of technologies and hundreds of products, how do we know where the vulnerabilities are?” She continues: “We have to have one single source of truth to let you know where to go to fix it when something goes wrong.”

Shlomi and Rinat on stage together

  • Shlomi then joins Rinat back on stage. He concludes, “Nvidia is not only becoming the AI infrastructure, but also the highway, the highway for AI. At the end of the highway, in your organization, is a gatekeeper, which is called JFrog.”
  • If we just stick to a roadmap without giving you this flexibility, trust me, none of you will survive this era of AI that is changing so fast.
  • He closes by announcing the Carl Quinn Award to the amazing speakers

Carl Quinn award