Features and Capabilities
Learn JFrog Xray Zero-Touch Remediation capabilities for Maven and npm, including vendor rebuilds, local patches, automations, and request audit lineage.
JFrog Zero-Touch Remediation remediates vulnerable Maven and npm packages at resolution time through the following capabilities. The following table summarizes those capability areas.
| Capability area | What it covers |
|---|---|
| Resolution-time remediation | Maven download interception and npm lockfile healing |
| Fix sources | Clearing-house vendors and local Maven patches |
| Automation management | Virtual repository scope, vendor priority, Fix all CVEs, and Least Vulnerable |
| Audit and scan results | Remediation Requests and requested versus served version lineage |
Resolution-Time Remediation
Resolution-time remediation is how Zero-Touch Remediation applies a patched package when Maven or npm resolves a dependency.
- Maven download interception: JFrog Artifactory asks JFrog Xray whether a patched replacement is available, then serves the selected artifact through the same virtual repository at the original coordinate.
- npm lockfile healing: A JFrog CLI version that supports lockfile healing sends
package-lock.jsonto Xray and writes back a rewritten lockfile. A standardnpm installdoesn't invoke healing.
Fix Sources
Fix sources are the patched artifacts Zero-Touch Remediation can serve when a matching automation applies.
- Clearing-house vendors: Chainguard for Maven, Echo, TuxCare, and Seal Security. A vendor participates only when the covered virtual repository includes that vendor's remote repository.
- Local Maven patches: You can register rebuilt Maven artifacts so Zero-Touch Remediation can serve local bytes at the original coordinate. npm lockfile healing doesn't consume local patches. For more information, see Register Local Patches.
Automation Management
Automations define which virtual repositories Zero-Touch Remediation covers and how vendors are ordered.
- You can create, edit, and activate automations that set Maven or npm virtual repository scope and vendor priority.
- Automations keep Fix all CVEs and the Least Vulnerable patch selection strategy. For more information, see Configure Zero-Touch Remediation Automations.
Audit and Scan Results
Audit and scan results show whether a request was healed and which version was served.
- Remediation Requests: Per-event detail and candidate version scoring for healed, skipped, and not-required outcomes. For more information, see View Remediation Requests.
- Scan results lineage: Requested versus served version after healing, including how Xray presents the remediated state. For more information, see Interpreting Remediation in Scan Results.
For how Maven and npm flows differ, supported vendors, and prerequisites, see Zero-Touch Remediation Overview.
Updated about 2 hours ago
