Zero-Touch Remediation
JFrog Zero-Touch Remediation closes the gap between vulnerability detection and a usable fix. When a developer or CI pipeline requests a vulnerable package from an Artifactory virtual repository covered by a Zero-Touch Remediation automation, Zero-Touch Remediation provides a verified patched version without a manual dependency upgrade.
You govern remediation through scoped automations that define the covered virtual repositories and vendor priority. Fixes can come from connected clearing-house vendors or from local Maven patches your organization rebuilt and registered. The goal is to shorten exposure windows while keeping builds green.
Zero-Touch Remediation does not block downloads the way Xray watches or Curation policies do. Blocking enforcement stays with those products. Zero-Touch Remediation serves a less-vulnerable patched package when one is available.
Where Zero-Touch Remediation Fits in the Security Timeline
Zero-Touch Remediation runs at package resolution time, after Catalog intelligence and Xray detection are in place. The following table shows where Zero-Touch Remediation fits in the JFrog security timeline.
| Stage | Zero-Touch Remediation's Role |
|---|---|
| Package resolution (Maven) | Intercepts the download from a covered Artifactory virtual repository and serves a patched artifact at the original coordinate. |
| Package resolution (npm) | Rewrites package-lock.json through JFrog CLI lockfile healing so the install uses patched tarballs from the same virtual repository. |
| Audit and scan results | Records healed, skipped, and not-required events, and shows requested versus served version lineage in Xray scan results. |
For the full remediation flow, vendors, local patches, and prerequisites, see Zero-Touch Remediation Overview.
Key Benefits of Zero-Touch Remediation
1. Faster Time to a Safer Package
- Replaces a vulnerable Maven or npm package at resolution time instead of waiting for a manual upgrade.
- Serves Maven patches at the original coordinate, so you don't have to change
pom.xmlto consume the fix. - For npm, heals the lockfile while
package.jsoncontinues to declare the original package name and version.
2. Builds Stay Green
- Provides a less-vulnerable patched package when a suitable candidate exists.
- If no candidate reduces CVE exposure, Artifactory serves the originally requested artifact.
- Does not fail the download the way a blocking Xray or Curation policy can.
3. Choice of Fix Sources
- Selects verified rebuilds from clearing-house vendors connected to the covered virtual repository: Chainguard (Maven), Echo, TuxCare, and Seal Security.
- Can serve Maven artifacts you rebuilt and registered as local patches.
- Uses the Least Vulnerable strategy, with a registered local patch ranking above a vendor rebuild when scores are equal.
4. Visible Outcomes
- Review healed, skipped, and not-required events on the Remediation Requests page.
- See requested versus served version lineage in scan results after a package is healed.
Updated 19 days ago
