Zero-Touch Remediation

This page lists the latest new features and enhancements for Zero-Touch Remediation.
For the complete Zero-Touch Remediation documentation, see Zero-Touch Remediation Overview.

September 2, 2026

New Features and Enhancements

  • Introducing Zero-Touch Remediation
    Zero-Touch Remediation adds Self-Healing, which automatically replaces vulnerable Maven and npm package versions with verified, drop-in secure patches at resolution time. You govern remediation through scoped automations. Fixes can come from connected clearing-house vendors or from Maven local patches your organization rebuilt and registered.
  • Added Maven remediation through Artifactory virtual repository interception. When a suitable patched candidate reduces CVE exposure, Artifactory serves it at the originally requested coordinate.
  • Added npm lockfile remediation through JFrog CLI, which rewrites package-lock.json with patched versions that resolve from the same Artifactory virtual repository. A standard npm install does not invoke lockfile healing.
  • Added support for patched versions from Chainguard (Maven), Echo, TuxCare, and Seal Security, and from registered local Maven patches.
  • Added Zero-Touch automations with virtual repository scope, vendor priority, and the Least Vulnerable patch selection strategy.
  • Added the Remediation Requests page so you can audit healed, skipped, and not required events. Xray scan results show a Patched status for remediated components.

Did this page help you?