Zero-Touch Remediation

JFrog Zero-Touch Remediation closes the gap between vulnerability detection and a usable fix. When a developer or CI pipeline requests a vulnerable package from an Artifactory virtual repository covered by a Zero-Touch Remediation automation, Zero-Touch Remediation provides a verified patched version without a manual dependency upgrade.

You govern remediation through scoped automations that define the covered virtual repositories and vendor priority. Fixes can come from connected clearing-house vendors or from local Maven patches your organization rebuilt and registered. The goal is to shorten exposure windows while keeping builds green.

Zero-Touch Remediation does not block downloads the way Xray watches or Curation policies do. Blocking enforcement stays with those products. Zero-Touch Remediation serves a less-vulnerable patched package when one is available.

Where Zero-Touch Remediation Fits in the Security Timeline

Zero-Touch Remediation runs at package resolution time, after Catalog intelligence and Xray detection are in place. The following table shows where Zero-Touch Remediation fits in the JFrog security timeline.

StageZero-Touch Remediation's Role
Package resolution (Maven)Intercepts the download from a covered Artifactory virtual repository and serves a patched artifact at the original coordinate.
Package resolution (npm)Rewrites package-lock.json through JFrog CLI lockfile healing so the install uses patched tarballs from the same virtual repository.
Audit and scan resultsRecords healed, skipped, and not-required events, and shows requested versus served version lineage in Xray scan results.

For the full remediation flow, vendors, local patches, and prerequisites, see Zero-Touch Remediation Overview.

Key Benefits of Zero-Touch Remediation

1. Faster Time to a Safer Package

  • Replaces a vulnerable Maven or npm package at resolution time instead of waiting for a manual upgrade.
  • Serves Maven patches at the original coordinate, so you don't have to change pom.xml to consume the fix.
  • For npm, heals the lockfile while package.json continues to declare the original package name and version.

2. Builds Stay Green

  • Provides a less-vulnerable patched package when a suitable candidate exists.
  • If no candidate reduces CVE exposure, Artifactory serves the originally requested artifact.
  • Does not fail the download the way a blocking Xray or Curation policy can.

3. Choice of Fix Sources

  • Selects verified rebuilds from clearing-house vendors connected to the covered virtual repository: Chainguard (Maven), Echo, TuxCare, and Seal Security.
  • Can serve Maven artifacts you rebuilt and registered as local patches.
  • Uses the Least Vulnerable strategy, with a registered local patch ranking above a vendor rebuild when scores are equal.

4. Visible Outcomes

  • Review healed, skipped, and not-required events on the Remediation Requests page.
  • See requested versus served version lineage in scan results after a package is healed.

Did this page help you?