Meet AI-Era
Remediation SLAs
The exposure window has collapsed.
Frontier AI creates new risks at speed and scale never seen before.
By the time you read this, Zero-Touch Remediation already fixed them.
What is Zero-Touch Remediation?
Zero-Touch Remediation automatically swaps risky packages in your pipelines with the best available patched versions, without interrupting development or breaking builds. Patches are sourced from hardened images, fixed OS packages, libraries, and maintainer releases.
Currently in Beta, GA in October 2026.
Policy-Driven Fixes From Every Available Source
JFrog is universal – connected to every available fix source, from hardened images and fixed OS libraries and packages to maintainer releases. It automatically selects and inserts the right one for your specific environment, governed by your policies.
Developers Keep Working, Builds Don’t Break
The vulnerable package is replaced transparently through Compliant Version Replacement: The developer requests a risky version, but receives a clean one instead, without slowing anything down.
A Critical Component of a
Self-Healing Supply Chain
Automated remediation is powerful, but a self-healing supply chain goes further. It brings prevention, detection, and prioritization together on one platform, running continuously and automatically
Made Possible Because JFrog Is the System of Record
Every artifact in your organization, from packages requested to binaries and components promoted to production, flows through JFrog. JFrog doesn't just see the artifacts, it governs them, and that governance is what makes automated remediation possible.
-
Zero-Touch Remediation is a JFrog capability that automatically replaces vulnerable packages in your CI/CD pipelines with the best available patched versions, governed by policy, without interrupting development or breaking builds. It is currently in Beta as of September 2026, with General Availability targeted for October 2026.
-
When JFrog Xray and JFrog Advanced Security detect an applicable and exploitable risky package in your pipeline, Zero-Touch Remediation matches it to the best patched version available from sources like hardened images, fixed OS packages, and maintainer releases. The replacement is applied automatically, governed by your policies, and logged with a cryptographically signed attestation.
-
Zero-Touch Remediation pulls patches from every available fix source: hardened images, fixed OS packages, and maintainer releases. Because JFrog is universal and connects to all of them, the platform can autonomously select the right patched version for your specific environment without requiring manual triage across multiple upstream feeds.
-
No. Zero-Touch Remediation uses Compliant Version Replacement, which means the developer requests a risky version and transparently receives a clean one instead. Builds continue running at normal speed, developers keep working without intervention, and the replacement is invisible to their workflow.
-
Traditional scanners detect vulnerabilities and generate an alert for a human to act on. Zero-Touch Remediation goes further by automatically replacing the vulnerable package with a patched version, with no human in the loop. Detection, prioritization, and fixing all happen on one platform at machine speed, with cryptographic proof of every change.
-
Compliant Version Replacement is the mechanism Zero-Touch Remediation uses to swap vulnerable packages for patched ones without disrupting developers. When a developer requests a risky version, the platform silently substitutes an approved, policy-compliant version. The build proceeds normally, and no manual intervention is required.
-
Zero-Touch Remediation entered Beta in September 2026 alongside its public announcement at JFrog’s swampUP event. General Availability is targeted for October 2026. Customers interested in early access during Beta can book a demo to see the product in action and discuss enrollment.
-
Yes. Zero-Touch Remediation is designed to work with JFrog Xray and JFrog Advanced Security, which detect and prioritize the vulnerabilities that get autonomously remediated. Contextual Analysis within JFrog Advanced Security reduces vulnerability noise by up to 90%, so remediation focuses only on packages that are actually exploitable.