Agenda

Hands-on Training | Keynotes | Breakout Sessions | Networking
Barcelona
October 20-22, 2026
Training Day
October 20th
Tuesday
Conference Day 1
October 21st
Wednesday
Conference Day 2
October 22nd
Thursday
CyberFrog
Room
MatrixFrog
Room
NeoFrog
Room
TronFrog
Room
8:00 AM
8:00 AM 1 session

0

BREAK Registration & Breakfast
8:00 AM – 9:00 AM
9:00 AM
9:00 AM 4 sessions

1

AI/ML INTERMEDIATE
JFrog AI Masterclass: Governance & Security in the Agentic SDLC
Optimizing Management, Security, and Governance for every AI asset in the Agentic Workflows. This course provides a deep dive into the industry's most complete AI registry solution. Learn how to transform your agentic supply chain by establishing a single system of record for centralized governance. We will guide you from discovering hidden Shadow AI blind spots to building a trusted, unified organizational hub for managing ML models, MCP servers, and more. What You Will Learn: - Building a Unified AI Architecture: Discover how to use the JFrog AI Catalog as your centralized "Single Source of Truth" for AI Assets including Models, External Model APIs, MCPs and more - Proactive Security & Scanning: Leverage JFrog’s advanced security features to detect Shadow AI usage, block malicious models, surface critical vulnerabilities (CVEs), and enforce strict license compliance - Full-Spectrum AI Governance: Learn how to discover, curate, and "Allow List" approved AI assets using automated, enterprise-grade policy enforcement to stop non-compliant AI Assets at the gate - Secure Agentic Workflows: Master the management of MCP servers to safely bridge AI assistants (like Cursor and Claude) with your private enterprise data - without compromising security or bypassing governance.
9:00 AM – 12:30 PM

2

AUTOMATION INTERMEDIATE
JFrog at Global Scale: Architecting to Make the Complex Simple
Optimizing the Software Supply Chain Workflow, Multi-Site Sync, and Automated Policy Enforcement. This full-day course covers follow the evolution of an organization. Learn to architect a unified platform that integrates disparate sites or teams, synchronizes artifacts globally, and enforces a "Trusted Release" lifecycle that evolves with the business at any scale. This will be a comprehensive deep dive into the latest JFrog Platform and capabilities. What You Will Learn: - Global Integration (Scale & Storage Optimization): How to implement Federated Repositories and JFrog Bridge for bi-directional synchronization and Advanced Retention Policies. - Proactive Security & Remediation: Deploying JFrog Curation to block malicious packages at the perimeter and Frogbot for automated, developer-centric vulnerability patching within the SCM. - Contextual Security & AI Governance: Utilizing Xray for runtime vulnerability prioritization and centralization the AI lifecycle via the JFrog AI Catalog to secure model usage and agentic workflows. - AppTrust & The Trusted Release: How to master evidence-based governance using GraphQL and automated security gates to ensure only compliant, signed binaries reach production.
9:00 AM – 4:00 PM

3

AUTOMATION INTERMEDIATE
Artifactory & Xray Automation Masterclass: Terraform & Advanced Orchestration
Advanced Lifecycle Automation using Terraform, JFrog MCP Server, and One Model GraphQL. This session focuses on building a high-performance automation frameworks using Terraform and the JFrog CLI, enabling DevOps teams to orchestrate complex Project environments and AI workflows with zero manual friction. What You Will Learn: - Scalable Project Management: Implementing JFrog Projects to automate resource isolation, quota management, and delegated administration for growing organizations. - The Terraform Blueprint: Master the JFrog Terraform Provider to provision repositories, security policies, and user permissions as a repeatable service. - Use JFrog MCP Server to manage your software supply chain and security via natural language, right from your IDE. - Advanced Querying & Auth: How to leverage One Model GraphQL Authentication to perform high-performance, cross-product queries - getting deep insights into artifact metadata and security evidence through a single, secure endpoint.
9:00 AM – 12:30 PM

4

DEVSECOPS INTERMEDIATE
JFrog Security Full Shift: Leveraging JFrog Curation for Automated Remediation
Combine JFrog Curation with local SAST (via MCP), Frogbot, and Snippet Detection to bridge the gap between policy enforcement and seamless violation fixes. Course Objective - Learn to deploy a "Developer-First" security strategy that blocks malicious packages before they hit your cache and uses AI-powered agents to detect plagiarized code in real-time. Bridge the gap between Security and Development by stopping threats at the front door and automating fixes directly in the SCM. What You Will Learn: - JFrog Curation: How to proactively block malicious or non-compliant open-source packages at the point of download. - IDE & Git Integration: How to use Frogbot to scan Pull Requests and provide instant feedback to developers before code is merged. - Developer-Centric SAST: Identify "exposed secrets" and security flaws in proprietary code during the initial coding stage and apply agentic remidiation - with MCP. - Early Remediation: Utilize JFrog’s contextual analysis to fix the most critical issues early, saving time upstream and reducing downstream friction.
9:00 AM – 12:30 PM
12:30 PM
12:30 PM 1 session

5

BREAK Lunch
12:30 PM – 1:30 PM
1:30 PM
1:30 PM 3 sessions

6

DEVGOVOPS INTERMEDIATE
AppTrust Essentials: Get CRA and SLSA Ready - Mastering DevGovOps & Supply Chain Integrity
Driving Compliant Releases with Evidence-Based Controls, Rego Policies, and ServiceNow Integration. We will focus on the transition from reactive security to proactive, automated governance. This course provides the technical blueprint for using JFrog AppTrust as the orchestration layer for "Trusted Releases," binding technical security metadata to business-ready compliance evidence that satisfies NIST and CRA mandates. What You Will Learn: - Identity & provenance (SLSA): Using build attestations to cryptographically prove the origin and integrity of every artifact in your supply chain. - Mastering the SBOM lifecycle: Generating, managing, and exporting enriched Software Bill of Materials (SBOMs) to meet global regulatory transparency requirements (RCA). - Automated trust policies: Setting the "Minimum Bar" for your organization using policy as code to automate complex approval logic and security gates. - ServiceNow ITSM integration: Automating the bridge between DevOps and IT operations by triggering ServiceNow change requests and status updates based on real-time security evidence and AppTrust gates.
1:30 PM – 5:00 PM

7

DEVOPS INTERMEDIATE
JFrog Multi-Site Architecture for the Agentic SDLC Era
Learn how to federate your Curation and govern your AI/ML and MCP-driven pipelines, at enterprise scale with zero downtime. Agentic SDLC and AI-driven pipelines are only as reliable as the infrastructure underneath them. This session delivers a technical blueprint for building the resilient, high-availability JFrog platform global enterprises need - distributing artifacts fast, enforcing security uniformly, and never going down, whether serving traditional builds or ML model pipelines. What You Will Learn: - HA Clusters for Always-On Delivery: Tune multi-node environments for zero-downtime load balancing - the foundation for any agentic era CI/CD pipeline. - Federated Repositories & Bi-Directional Sync: Real-time, multi-site synchronization across packages, containers and AI/ML models. - Federated Curation & Unified Security Policies: Consistent governance across every global site - blocking malicious packages, ML models and any non-compliant AI assets at once. - JFrog Bridge for restricted networks: Distribute artifacts and AI model updates across egress-only environments without compromising isolation. - Disaster Recovery Architecture: Redundant failover protocols protecting mission-critical binaries and AI pipeline dependencies.
1:30 PM – 5:00 PM

8

DEVSECOPS ADVANCED
Intelligence-Driven Vulnerability Management: Context to Runtime
About this session: Embedding Continuous Security Across Your Artifact Lifecycle Course Objective: Master the integration of vulnerability detection with contextual analysis to eliminate false positives and focus remediation efforts on exploitable risks. This advanced course teaches practitioners how to combine JFrog Xray's comprehensive artifact scanning with JFrog Advanced Security's Contextual Analysis, and JFrog Runtime's integrity validation capabilities to build an intelligence-driven security program. What You Will Learn: Implement a unified approach across the entire software supply chain Using Xray for deep recursive scanning Leveraging Advanced Security to validate vulnerability applicability through contextual analysis Detect exposed secrets and Infrastructure as Code (IaC) misconfigurations Utilizing JFrog Runtime to verify artifact integrity and monitor which validated images are actually running in production environments.
1:30 PM – 5:00 PM
6:00 PM
6:00 PM 1 session

9

BREAK Welcome Reception
6:00 PM – 7:00 PM
CyberFrog
Room
MatrixFrog
Room
NeoFrog
Room
TronFrog
Room
8:00 AM
8:00 AM 1 session

10

BREAK Registration & Breakfast Hop in, grab your badge, and fuel up. Coffee’s hot, breakfast is served, and the day is ready to take off.
8:00 AM – 9:00 AM
9:00 AM
9:00 AM 1 session

11

KEYNOTE
Creation is Limitless, Trust is Everything
Leap into the future of trusted software and AI with JFrog’s founders as they unpack how AI is reshaping the software supply chain. As autonomous agents move from assistants to builders… writing code, resolving dependencies, and producing binaries at machine speed. Join us to see how the rules of trust are being rewritten.
FrogHall
9:00 AM – 9:45 AM
9:45 AM
9:45 AM 1 session

12

KEYNOTE
The Agentic Software Supply Chain: Rebuilding the Trust Model
The world’s software supply chain has mutated. "Liquid Software" is here, delivered through binaries! Software now flows continuously: assembled, evolved, and deployed through streams of binaries at AI speed. Source code is no longer the center of gravity; it is becoming an intermediate representation in a faster, more autonomous software factory. Coding agents are becoming true software agents, assembling releases, combining open source and proprietary packages, pulling in AI assets, and pushing software forward faster than human-driven governance can track. This is the AI surge. This shift breaks the trust model the industry only recently finished building! The new supply chain introduces new assets to control, new attack surfaces to secure, and risks that do not fit yesterday’s tools. AI-generated code can create massive downstream impact in seconds, while cyber models challenge open source ecosystems by finding and exploiting unknown vulnerabilities. Traditional governance and audit systems are losing their anchor points, and standards are already behind. In this reality, protection, remediation, and governance must be instant. JFrog saw this coming. As software is assembled at agentic speed, trust must move closer to the binary, the runtime, and every decision point in the pipeline. Mastering the AI surge means applying trust in compressed time and across a rapidly expanding attack surface. In this keynote, we will show how JFrog becomes the modern trust layer – the universal protector of the Agentic Software Supply Chain: securing every package, model, AI asset, and release across the new software factory, at scale, regardless of the tools, agents, or pipelines you use.
FrogHall
9:45 AM – 10:30 AM
10:30 AM
10:30 AM 1 session

13

KEYNOTE
Trusting Your AI Workforce: From the Assets They Pull to the Code They Ship
Enterprises are adopting coding agents faster than any developer tool in history. Claude Code, Cursor, Windsurf, VS Code, Kiro - they're already running across your organization, invoking tools, installing MCPs, pulling skills, and writing code that ships to production. And right now, it's the wild west. It's 10pm, do you know where your agents are? Which MCPs ran on your developers' machines last week? Which skills shaped the code your agents wrote? Where did any of it come from, and who approved it? For most enterprises, the honest answer is - nobody knows. For over a decade, JFrog has answered one question for the enterprise: can you trust what goes into your software? The question hasn't changed, just the artifacts and the blast radius. Even when the output isn't code, your coding agents still write code to get there. This session shows how JFrog extends the trust you already depend on across everything your agents touch - the assets they consume and the code they produce. Not point fixes for one tool or one asset type, but one proven supply-chain chain applied universally: every asset, every agent, governance that can't be bypassed. It's the only way to trust an AI workforce - and the only platform that does it. You'll leave knowing how to go from "nobody knows" to full control across your org.
FrogHall
10:30 AM – 11:15 AM
11:15 AM
11:15 AM 1 session

14

BREAK Coffee Break
11:15 AM – 11:45 AM
11:45 AM
11:45 AM 1 session

15

KEYNOTE
The New Frontier: Software Supply Chain Security in the Age of Autonomous AI
Frontier AI models - Mythos, GPT 5.5-Cyber - now discover and chain software vulnerabilities at machine speed - and attackers will have access to the same capabilities. The traditional DevSecOps playbook of scan, alert, and manually patch can't keep up. The new world requires continuously executing pre- and post-release defences anchored on a single system of record for every binary your organization produces and consumes and a single hub where fixes from every vendor are available. Pre-release: stop risk before it ships. The supply chain faces threats beyond CVEs - malicious packages, leaked secrets, insecure code, and vulnerable dependencies. We'll show how JFrog blocks, detects, and gates these risks before anything reaches production. Post-release: self-heal at machine speed. When a vulnerability is disclosed after deployment, today's response - emergency rebuilds, weeks of exposure - is no longer acceptable. We'll present JFrog's vision for a self-healing supply chain that aggregates fixes from any source, selects the right one, and remediates automatically - for known CVEs and for threats that don't yet have one. We'll also cover how provenance and signed evidence ensure every fix is auditable - so you can prove what was remediated, when, and from which source. Because every binary and every fix flows through one system of record, JFrog can secure both sides of the software lifecycle on a single platform.
FrogHall
11:45 AM – 12:30 PM
12:30 PM
12:30 PM 1 session

16

KEYNOTE
When AI Commits Your Code: Reinventing Security for the AI-Native SDLC
Coding agents are rapidly becoming the primary authors of production software. Engineering velocity has accelerated exponentially, while security teams have grown only modestly. Traditional AppSec processes were never designed for this reality, nor for the “tsunami” of binaries now flowing through pipelines. Left unchanged, they quickly become the bottleneck. In this keynote, Oliver Grubin, from Anthropic shares how the company reimagined software supply chain security for an AI-native engineering organization. Learn how to evolve from human-centric code reviews to scalable oversight, where specialized AI reviewers combined with deterministic security controls and risk-based governance work together to secure software without slowing developers down. We'll explore how security shifts to governing autonomous development loops, how a trusted system of record can become the control plane for AI-generated software, how continuous AI-powered validation replaces traditional security gates, and why policy, provenance, governance, and auditability are the building blocks of a trusted AI software supply chain. As AI becomes part of your engineering workforce, this session will show how to build trust at scale, without sacrificing speed.
FrogHall
12:30 PM – 1:00 PM
1:00 PM
1:00 PM 1 session

17

BREAK Lunch Take a breather, grab a bite, and make a few new connections.
1:00 PM – 2:00 PM
2:00 PM
2:00 PM 4 sessions

18

CLOUD INTERMEDIATE
Trusted AI Delivery at Scale: Securing Every Artifact from Curation to AWS AgentCore
Our AI supply chain is only as trustworthy as its weakest artifact. As teams race to build and deploy AI agents, every dependency they pull- Python packages, container images, agent tooling- becomes an attack vector. A single poisoned package can compromise everything downstream, and most teams never see it coming. This session walks through how JFrog's platform gives you complete chain-of-custody, from the moment a developer triggers a build in their local IDE to the moment an AI agent runs in production on Amazon Bedrock AgentCore. We'll build a real Strands SDK agent in Kiro IDE, then trigger a single build command. The full supply-chain pipeline unfolds: Curation evaluates every pip package against policy before Artifactory caches it; Artifactory resolves only approved dependencies into the Docker image; Xray scans the resulting container and fails the build on critical vulnerabilities- blocking promotion to ECR. A known-vulnerable dependency in the requirements file stops the pipeline cold; the agent never reaches production. Only when every gate is green does the image land on Amazon ECR and go live on AgentCore. JFrog Curation, Artifactory, and Xray- three layers of trust, enforced automatically, invisible to the developer until something goes wrong. That's the point
2:00 PM – 2:40 PM

19

CLOUD ALL LEVELS
SEB’s Technical Transformation: Securing the Supply Chain
The growth of software supply chain security complexity and threats, especially with advanced AI models like Mythos and Fable, is driving a more urgent need for companies to fix vulnerabilities in their systems. In a big enterprise like SEB, the technical landscape is complex, with many technologies and tools in use and complex internal processes to meet regulations like DORA. This makes it even harder to cyber-secure the systems at speed. This session will focus on SEB's current software supply chain security journey - the challenges, what was done, what they want to do, and the outcomes they hope to achieve through initiatives such as JFrog Curation and other security solutions.
2:00 PM – 2:40 PM

20

AUTOMATION ALL LEVELS
Achieving Scalable Security: Vanderlande’s Enterprise Journey to SaaS
Vanderlande, a global leader in logistics process automation for airports, warehousing, and parcel, has evolved from a traditional manufacturing powerhouse into a software-driven intelligent logistics solutions provider. This transformation created the need for a modern, secure, and scalable software supply chain. Before their migration, Vanderlande operated three self-hosted JFrog instances across Veghel, Dortmund, and Quebec. This model created operational challenges around VM-based scaling, manual Xray operations, application upgrades, limited access segregation, shared internal accounts, and incomplete adoption of advanced security capabilities such as JFrog Curation and Xray. To support ISO-aligned security goals across 100+ global teams, we moved toward JFrog Artifactory SaaS and redesigned our operating model. This session shares how Vanderlande migrated from a repo-stage model to a project-based governance model aligned with agile release trains. The company implemented SSO and AD-based access control, project-level ownership, service account standards, and regional JPD considerations for global performance. A major focus of the journey was scaling advanced security. Vanderlande rolled out JFrog Curation and Xray policies across teams with different SDLC maturity levels and many legacy applications. Full-scale enablement surfaced thousands of legacy references, curation blocks, and Xray violations. Rather than relying on a big-bang blocking approach, they adopted a phased model using dry-run, notifications, waivers, ignore rules, and JIRA-based remediation. They also promoted shift-left practices using JFrog CLI, Curation audit, build scans, Frogbot, and release bundle workflows. To manage the SaaS era, Vanderlande built custom Grafana dashboards using JFrog APIs for data transfer, storage hotspots, repository usage, and account privilege audits. These dashboards helped track monthly transfer volumes, optimize storage and retention, and identify over-privileged or incorrectly configured service accounts.
2:00 PM – 2:40 PM

21

AFTERNOON NOVICE
JFrog Jumpstart Masterclass: Driving Successful Platform Adoption (By Invite Only)
Course Objective: This session focuses on guiding new JFrog customers through a practical, hands-on deployment framework moving organizations away from fragmented point solutions toward a unified, secure DevSecOps platform built on JFrog Artifactory, Xray, and Distribution. What You Will Learn: - Foundational Platform Architecture: Map organizational entities and business units to JFrog Projects, and design scalable repository structures with fine-tuned access controls for multi-team environments. - Leverage JFrog Curation to block malicious or non-compliant packages before they ever reach local caches. Developer-Centric Onboarding: Use the JFrog CLI and onboarding templates to reduce friction, and shift security left with IDE-based SAST scanning and Frogbot integration in pull requests. - Agentic AI & skill Integration: Leverage the JFrog Skill Server to securely expose Artifactory data as a context source for LLMs, enabling AI coding assistants to inspect packages, query dependency trees, and surface vulnerabilities through natural language. This session includes hands-on labs throughout, giving you the opportunity to practice each concept directly in a live JFrog environment as you learn it.
2:00 PM – 5:30 PM
2:45 PM
2:45 PM 3 sessions

22

CLOUD ALL LEVELS
The Vulnerability Tsunami: Securing the Software Supply Chain at Scale
Over the past year, Nationwide moved beyond building a multi-cloud JFrog platform to solving a harder problem: operating a secure, compliant, and scalable software supply chain in the face of rapidly expanding threat volumes. In this session, we'll discuss how Nationwide delivered a comprehensive supply chain security roadmap across a large regulated financial services organization. This includes token automation, hardened container images, Xray-based vulnerability management enforcement, artifact curation, and a fully evidence-driven approach to provenance, SBOMs, and signing. The session will cover the rollout of JFrog Xray enforcement at scale, with centralized reporting, alerting, and managed dispensations, and the introduction of Curation as a secure-by-default control plane to protect the organization from malicious and vulnerable open source dependencies at the perimeter. A key theme throughout is moving from visibility to enforcement. Nationwide uses JFrog Build Info as the authoritative record of build-time truth, binding together dependencies, provenance, scans, and attestations into enforceable policy decisions. At the same time, they are evolving SBOMs from static artifacts into operational control points, embedded into build pipelines, evidence services, and release governance. Finally, this session will address the emerging challenge facing all organizations: the “tsunami" of vulnerabilities driven by AI-assisted development and increasingly complex dependency ecosystems. This is forcing a fundamental rethink in patching strategies, prioritization, and change management. We’ll share how the company is adapting its platform, processes, and operating model to cope with this shift at scale.
2:45 PM – 3:25 PM

23

AUTOMATION INTERMEDIATE
The Architect's Playbook: Unlocking the Full Potential of the JFrog Platform
Software delivery is accelerating in the age of AI, and the demands on every part of the SDLC are growing with it. For organizations using the JFrog Platform, this is the moment to move beyond artifact storage and start leveraging the platform as a central pillar of their software delivery strategy — a source of truth that drives decisions, enforces governance, and delivers measurable value. In this session I'll share the architect's playbook — the best practices and advanced patterns we recommend in JFrog Professional Services, demonstrated live in the system. You'll see: - How to manage the JFrog Platform at scale by tackling the challenges every platform team faces, using what actually works, proven over time. - How to use build-info, properties, and evidence to bake governance into your pipelines — setting you up for success in the realm of DevGovOps and AppTrust. - How to implement "build once" workflows by using the JFrog Platform as a source for dynamic decision-making — the same artifact you build once is the one promoted all the way to production. - How to avoid common performance traps and implement retention and cleanup strategies that keep the platform healthy at scale. - How to derive real, measurable value from the data your platform already holds — from findings routed to the right people to KPIs and actionable insights for every stakeholder. You'll walk away understanding which best practices matter most and why, where the biggest opportunities for improvement are across platform management, performance, governance, and value extraction — and with a practical blueprint you can start applying immediately. Who should attend? DevOps engineers, platform engineers, DevSecOps architects, CI/CD pipeline owners, engineering leaders, and CISO office stakeholders who are using the JFrog Platform and want to move beyond basic artifact management toward advanced, scalable, governance-driven usage that delivers measurable value.
2:45 PM – 3:25 PM

24

DEVSECOPS INTERMEDIATE
Success Story: How Körber streamlined the DevOps process
Körber, a global technology group with 13,000 users, has been transforming from a mechanically rooted organization into a software-driven business. As each business unit advanced at its own pace, tools and development practices became fragmented. In 2024, Körber launched a common platform to unify development, improve visibility, and enable stronger collaboration across the Group. More than a platform rollout, this was a strategic shift-left step: introducing automated, continuous code verification as a foundation for secure SDLC and improved operational performance. The result is a stronger basis for scaling software engineering, increasing transparency, and driving Körber’s evolution into a modern software-enabled technology company.
2:45 PM – 3:25 PM
3:25 PM
3:25 PM 1 session

25

BREAK Coffee Break
3:25 PM – 3:55 PM
3:55 PM
3:55 PM 3 sessions

26

SESSION INTERMEDIATE
Your AI is a Toddler with Root Access: Why Kubernetes Policies Are Your Last Line of Defense
We've spent years teaching humans not to deploy on Fridays, to follow naming conventions, and to respect resource limits. Now we're handing the keys to AI agents that can generate and deploy resources at superhuman speed. What could possibly go wrong? As AI copilots and autonomous agents increasingly take the wheel in Kubernetes operations, we're witnessing a paradox: the very tools designed to eliminate human error are creating new categories of chaos at unprecedented scale. Your AI assistant doesn't get tired, doesn't need coffee breaks, and definitely doesn't read your runbooks. It can spawn a thousand misconfigured pods before you've finished reading this abstract. This talk explores why Kubernetes admission policies (from OPA to Kyverno to native Validating Admission Policies) must urgently evolve from "nice-to-have guardrails" to "absolutely critical blast doors" in the age of AI-driven operations. We'll examine real-world scenarios where AI-generated manifests have gone spectacularly wrong, and demonstrate how policy-as-code can no longer be just about preventing bad configurations. It must transform into a new discipline: teaching our silicon colleagues the unwritten rules that humans learned through painful experience, while adapting to threats we've never faced before.
3:55 PM – 4:35 PM

27

SUPPLY CHAIN SECURITY ALL LEVELS
Securing the Software Supply Chain Without Compromising Developer Experience - DevSecOps Journey
Software supply chain attacks are no longer theoretical. From dependency confusion to malicious packages slipping through undetected, the threat is real, active, and growing. Most organizations know they need to act, but the moment security starts slowing developers down, it stops being adopted. This tension is exactly what Husqvarna Group set out to solve. Husqvarna's engineering organization spans a broad, multi-platform ecosystem across multiple languages and stacks. At this scale, the challenges are familiar to many - security tooling that grows organically, visibility fragmented across multiple screens and systems, and no single end-to-end view of supply chain risk. Developer experience feels the pressure of context-switching, alert fatigue, and security processes that drift away from how engineers actually work. Add CRA and NIS2 obligations to the mix, and the case for a more coherent, integrated approach becomes hard to ignore. This session tells the story of how Husqvarna built a DevSecOps practice with one non-negotiable principle - security had to work with developers, not against them. That meant rethinking what shifting left actually looks like in practice and co-designing the workflow with engineering teams from day one, surfacing the right vulnerabilities in the right context, and distinguishing between what exists and what is actually applicable, so developers act on signal, not noise. You'll leave this session with - A clear picture of how JFrog Advanced Security and Curator can be applied in real enterprise use cases - Practical lessons on co-designing security workflows that work for both developers and security teams - An honest view of where the friction still lives and how we handled it - A sense of how getting supply chain security right also quietly takes care of a lot of what compliance asks for.
3:55 PM – 4:35 PM

28

CLOUD INTERMEDIATE
Closing the Gap Between Runtime and Fix: A Look At JFrog and Wiz Integrate
Cloud Security and AppSec teams see the same problem from opposite ends. Cloud Security sees what's running in production but not where it came from or whether it was built and scanned correctly. AppSec has full context through build and scan, but that context doesn't travel with the artifact once it deploys to production. That visibility gap is one of the critical gaps DevSecOps and Cloud Security teams face in the Frontier AI-era MTTR equation. JFrog and Wiz have partnered on a bi-directional integration that makes SDLC-to-production security actually work as one loop, not two. Wiz pulls JFrog Xray's security posture into its Security Graph, giving every production workload the full security context Xray already tracks. JFrog pulls deployment data back, correlating it with Artifactory and Xray. Join this session to see the integration complete the full journey: detecting a critical CVE in runtime, tracing it back through the image, the build, and the source code, all the way to the pull request that remediates it, with Xray powering the fix. Full traceability, full context, from production to SDLC.
3:55 PM – 4:35 PM
4:40 PM
4:40 PM 3 sessions

29

DEVSECOPS NOVICE
Designing DevSecOps for Reality: Bootstrapping a Secure Software Supply Chain
Most DevSecOps talks focus on finished implementations, but what about getting started in a real enterprise environment? In this session, Vattenfall shares how they are designing and bootstrapping a secure software supply chain using JFrog Artifactory and Xray. We’ll walk through Vattenfall's current challenges, architectural decisions, and early implementation steps to integrate security into CI/CD and Kubernetes workflows. Learn how Vattenfall approaches policy-as-code, automations, vulnerability management, and developer experience from day one, along with lessons learned, trade-offs, and pitfalls to avoid when moving from visibility to enforcement.
4:40 PM – 5:20 PM

30

DEVOPS ALL LEVELS
Shipping Code Safely in a GenAI powered-SDLC
GenAI is allowing the generation of new tools and code faster than ever. Very few organizations can ship it safely at scale. The real bottleneck is no longer writing code; it’s trusting it, securing it, and integrating it into a fully governed software supply chain. This session will share how Admiral moved beyond experimentation to operationalize GenAI usage across the SDLC using JFrog as the control plane for trust, traceability, and flow. We'll show how GenAI-generated tools and code can be made trustworthy from the earliest stages of delivery, before it ever enters a pipeline, across the full developer workflow: - From prompt to Skill, MCP context, prototype, and dependency choice through to commit, with visibility before code enters the pipeline - Supported by curated package registries, reusable Skills, agents, and prompts that encourage sharing, reduce cognitive load, and improve developer flow across teams - Continuously guided by JFrog Xray and Curation policies, then connected into CI/CD with less rework, clearer provenance, and smoother promotion when code is ready to release We will walk through a practical flow demonstrating how - Shifting left on DevEx when using GenAI enables both security and speed at scale - AI-generated code and its dependencies enter the SDLC, and where JFrog intersects that flow - JFrog XRay, Curation, and Artifactory enforce security, provenance, and policy - Platform engineering enables all this consistently across teams Critically, the session will focus on the human and business reality - Developers gain speed, but need guardrails to feel safe. - Organizations want innovation but can’t absorb unmanaged risk introduced by AI tooling and dependencies. - Platform teams must scale both without becoming the new bottleneck. We'll also discuss lessons learned from implementations at scale - what worked, what didn’t, and how to design a platform that allows GenAI to accelerate delivery without compromising trust.
4:40 PM – 5:20 PM

31

DEVSECOPS ALL LEVELS
Self-Healing Supply Chains: Lessons from Major OSS Attacks + Automated Remediation
CVEs in open source dependencies pose a massive risk. Take Log4Shell as an example: a single bug in a widely used library put thousands of applications at risk overnight. This year, there are 242 CVEs being reported each day, up 80% from 2025. This session covers the growing security risk of CVEs and how JFrog and Chainguard are working together to keep your applications secure. JFrog's new Self-Healing Zero-Touch Remediation automatically detects vulnerable Python and Java dependencies and swaps them for Chainguard-built versions with backported fixes for critical and high-severity CVEs. Your application becomes secure without creating a breaking change. Together, JFrog and Chainguard are turning vulnerability remediation from a manual dev task into an automated, policy-compliant workflow, so your team can move fast without getting bogged down in CVE remediation toil. Why you should join: - Understand how recent major open source supply chain attacks happened - See how JFrog Zero-Touch Remediation + Chainguard allows you to automatically remediate critical and high CVEs found in hard-to-upgrade versions of Python and Java dependencies - Gain insights to better protect your organization from future malware and vulnerability risk
4:40 PM – 5:00 PM
5:00 PM
5:00 PM 1 session

32

DEVSECOPS INTERMEDIATE
Agentic Change Management: The Control Layer for Code Written by Agents
CodeRabbit reviews code changes downstream of every major coding agent, which gives us an unusual view of agentic development. Across more than 30M pull requests in the last 12 months, volume grew 4x while review rounds per change fell by 1/5th. This means more code is shipping with less scrutiny per change. Teams are not consolidating on one agent either; larger organizations increasingly run several. That creates a structural problem: a review feature inside one agent checks only that agent's output, and authors do not reliably catch their own mistakes. So review has to sit outside all of them. That outside layer is Agentic Change Management: the control layer that helps teams govern, understand, and ship software created by people and agents. In practice it is code review rebuilt for agentic volume. Every change gets checked for correctness, security, consistency, policy, tests, and completeness, whoever or whatever wrote it, and scheduled scans re-check code that already merged. The session's security segment shows the deepest version of that review: agents map a codebase's entry points and trust boundaries, follow attacker-controlled input to the operations it reaches, and report findings only after verifying them, each with a drafted fix an engineer merges or rejects. Review covers the inner loop; the outer loop is JFrog's ground, and the two answer different questions about the same software. Builds land in Artifactory, Curation gates which open-source packages enter your repositories, and JFrog AppTrust evaluates the evidence every tool contributes, CodeRabbit's review decisions and scan results included, against policy before promotion. The talk closes by following one agent-written change through the whole pipeline: verified at review, built, stored, and promoted with its evidence. Covering both loops is what makes agentic development fast and safe.
5:00 PM – 5:20 PM
7:00 PM
7:00 PM 1 session

33

BREAK Gala Dinner & Customer Awards Ceremony in 2026 Celebrate the best in the business. Join us for an immersive experience featuring our annual awards ceremony, followed by a gala dinner and open bar with industry pioneers.
7:00 PM – 9:00 PM
9:00 PM
9:00 PM 1 session

34

BREAK Open Bar
9:00 PM – 10:00 PM
MatrixFrog
Room
NeoFrog
Room
TronFrog
Room
8:00 AM
8:00 AM 1 session

35

BREAK Breakfast Ease into the day… grab breakfast, reconnect with peers, and get ready for what’s next.
8:00 AM – 9:00 AM
9:00 AM
9:00 AM 1 session

36

BREAK Opening
9:00 AM – 9:15 AM
9:15 AM
9:15 AM 1 session

37

KEYNOTE
Shattering The Compliance Illusion: Built In. Continuous. Automatic.
Most organizations believe they are compliant because they follow the known path: they check, they audit, they sign off. What the agentic era is exposing is that this model was always fragile - and it is now broken. It started with manual workarounds, screenshots, spreadsheets, email chains as audit trails. Painful, but manageable. Code moved at human pace. The gaps could be filled. Then the assumptions collapsed. Autonomous agents began committing code, opening PRs, and deploying to production in minutes, with no humans in the loop. When the auditors arrive, there is no one to ask. There is no memory. There is no context. There is no evidence. You are using 2025 practices to face a 2027 threat model. Process integrity is the answer: compliance built into the pipeline from day one, not bolted onto releases after the fact. Find out how with process integrity, policy enforces itself and evidence collects itself. Continuous, automatic, and proven at the speed your teams ship.
FrogHall
9:15 AM – 10:00 AM
10:00 AM
10:00 AM 1 session

38

KEYNOTE
Sovereignty Is a Release Gate, Not a Data Center
Data residency is table stakes. The question you should be asking is: Who decides what your AI agents ship? Using the Five Pillars of Sovereign AI framework from Agency Labs and theCUBE Research, Amit Eyal Govrin will run a live assessment of Stripe's published "Minion" agents against the Operational pillar. He will demonstrate why the release gate, not the data center, is where control is truly proven and how a software system of record enables governance in practice
FrogHall
10:00 AM – 10:30 AM
10:30 AM
10:30 AM 1 session

39

BREAK Coffee Break
10:30 AM – 10:45 AM
10:45 AM
10:45 AM 1 session

40

KEYNOTE
Keynote
Leap into the future of trusted software and AI with JFrog’s founders as they unpack how AI is reshaping the software supply chain. Watch as autonomous agents move from assistants to builders by writing code, resolving dependencies, and producing binaries at machine speed. Join us to see how the rules of trust are being rewritten!
FrogHall
10:45 AM – 11:30 AM
11:30 AM
11:30 AM 1 session

41

KEYNOTE
Supply Chain Attacks & AI: A Match Made in Hell
451%. That is the increase in malicious packages over the past year in npm alone. Hijacking open source packages has become the attacker's highest-ROI play, supercharged by AI-powered payloads, precision phishing, and entirely new injection vectors like malicious AI skills. But there's good news. The same cyber models attackers use are being turned against them. Find out how JFrog's Security Research team is winning against both widespread and targeted attacks, by enhancing JFrog Curation and deploying AI-powered detection at the scale and speed these threats demand. You will leave knowing what you need to prepare for: the new attack techniques, the near-future supply chain threats, and how JFrog's Research team feeds that intelligence directly into JFrog Curation, so threats are blocked before they manifest.
FrogHall
11:30 AM – 12:15 PM
12:15 PM
12:15 PM 1 session

42

KEYNOTE
Panel: The Great Model Surge: Patching at the Speed of the Threat
The rapid rise of frontier cyber models is triggering an unprecedented shift in software supply chain security. Organizations are bracing for an impending onslaught of vulnerabilities paired with drastically compressed exploit windows and the automated exploitation of lower-severity findings. To survive this, we must fundamentally rewrite the security playbook by scaling and accelerating automated patching and completely reimagining the traditional vulnerability disclosure process.
FrogHall
12:15 PM – 1:00 PM
1:00 PM
1:00 PM 1 session

43

BREAK Lunch Refuel, recharge, and reconnect before diving back in.
1:00 PM – 2:00 PM
2:00 PM
2:00 PM 3 sessions

44

DEVSECOPS ALL LEVELS
How Erste Bank Turned DevSecOps Ambition into an Enterprise Program
It all started five years ago when Erste&Steiermärkische Bank's security team realized they had a serious problem. They had a lot of internally developed applications, including the core banking system, but literally had no application security team nor DevSecOps of any meaningful kind. In the past five years, the bank has established an award-winning internal cyber security education program, won huge investment from the EU for co-financing development of cyber security capabilities, tested every open source and commercial security tool you can think of, and managed to change its whole security culture. Today, developers and infrastructure colleagues actively participate in security matters and actually use all security tools implemented. Their internal security workshops are the most attended, and even other entities within our banking group consult with the bank's security team regarding their cybersecurity programs. But it was not all wine and roses. There were many blockers and issues the security team needed to address to get to where they are now - from securing management backing, finding our way through a bureaucratic EU labyrinth, to winning the hearts and minds of our developers and changing their perspective of security. This session will cover the bank's security team's journey: How they did it, what security tools were tested and why, how they are using them today, and where they are heading.
2:00 PM – 2:40 PM

45

AUTOMATION ALL LEVELS
Scaling Engineering Without Losing Control: The JFrog Projects Blueprint
Every growing engineering org hits the same wall. More teams shipping software means more repositories, more permission requests, more onboarding cycles - and eventually one platform admin fielding every change. The platform that was supposed to accelerate delivery becomes the bottleneck. This session walks through the organizational model that breaks that pattern: structuring your JFrog Platform around Projects, the administrative, resource, and security workspace that lets teams work independently on shared infrastructure. We'll cover: *What a JFrog Project actually is — the administrative, resource, and security boundary that maps to how your business already tracks ownership and cost. *Projects best practices — choosing the right boundary (team, application, microservice, or budget unit), designing the three-tier role model (Platform Admin, Project Admin, Project Roles), scoping RBAC and environments to contain blast radius, delegating authority to remove the platform-admin bottleneck, and extending governance to AI assets via the AI Catalog and MCP Registry. *How to migrate to JFrog Projects using the Project migration tool - a practical walkthrough of moving from a flat platform structure to a Projects-based model: planning your target topology, mapping existing repositories and permissions, running the migration tool, validating the result, and rolling out self-service onboarding once the foundation is in place.
2:00 PM – 2:40 PM

46

DEVOPS INTERMEDIATE
Scaling Trusted Software Releases with JFrog and AppTrust
This session will cover how - Alstom deployed JFrog Artifactory to support large volumes (HA). - The repository is structured in Artifactory - Software is aggregated in release bundles, challenges we faced, and the pivot to AppTrust Evaluation. - Artifactory is linked to the Alstom Configuration Management process. - Alstom will distribute software to factories that are responsible for installing software. Alstom leverages JFrog Artifactory as the central platform for software artifact storage, traceability, promotion, and release, integrated first with GitLab and progressively with configuration-management tooling such as IBM ELM/GCM.
2:00 PM – 2:40 PM
2:45 PM
2:45 PM 3 sessions

47

SUPPLY CHAIN SECURITY INTERMEDIATE
Navigating the CRA Mandate: Automating EU Compliance with JFrog
The EU Cyber Resilience Act (CRA) transforms supply chain visibility from a best practice into a strict legal requirement. With severe fines and potential market exclusion on the line, the stakes are unprecedented. Yet, manually retrofitting mandatory SBOMs, vulnerability tracking, and end-to-end traceability into high-velocity pipelines threatens to bring developer productivity to a grinding halt. The solution requires a shift from reactive audits to continuous, automated compliance. In this session, we’ll demystify the CRA and demonstrate how JFrog AppTrust solves this exact challenge. By capturing verifiable evidence across your SDLC and enforcing gates. You’ll learn how to indisputably prove that every release is CRA-ready before it ships, protecting your business without slowing down your engineers.
2:45 PM – 3:25 PM

48

AUTOMATION INTERMEDIATE
Stop Chasing Vulnerabilities: Building Proactive Product Security at Danfoss
This session highlights Danfoss’ journey to strengthen software supply chain security, transitioning from a reactive, fragmented approach with limited visibility and high effort toward a more proactive and structured model, supported by JFrog. Where We Started The initial maturity level in software security was low and largely reactive. We were always responding to alerts without full visibility into potential impact or compromise. Significant time was spent on remediation efforts, often without certainty about whether development teams had been affected. Communication challenges further compounded the problem, either overwhelming teams with too much information or failing to target the right stakeholders, leading to confusion and inefficiencies. At the same time, we were trying to balance security with developer productivity, ensuring that controls did not slow down delivery pipelines. Where We Are Today To address these challenges, Danfoss established the Digital Product Security Program (DPSP): a structured initiative designed to embed security directly into our development processes and products. With the support of JFrog, we shifted earlier in the lifecycle and introduced preventive controls rather than late-stage remediation. This includes, but is not limited to: - Preventing malicious or untrusted packages from entering the environment - Blocking critical vulnerabilities (CVEs) early in the development lifecycle - Implementing controlled and auditable exception handling processes The Value of JFrog Support An important enabler in this transformation has been the strong and responsive support from JFrog, which played a key role in: - Providing best practices and guidance aligned with our goals - Helping us fine-tune policies and controls to balance security with developer productivity - Acting as a trusted partner in our ongoing journey toward proactive security
2:45 PM – 3:25 PM

49

SUPPLY CHAIN SECURITY ALL LEVELS
Minutes to Exploit, Weeks to Patch: Inside the ECB's AI Cyber Mandate
On 7 July 2026, the ECB set a 31 October deadline for 2,000+ banks across 21 EU member states to submit concrete AI-cyber action plans. The message is blunt. Frontier AI now compresses the window from vulnerability discovery to working exploit from weeks to minutes. Manual triage, week-long patch waves, and CVSS-only prioritization no longer clear the bar. Banks are first. Every other regulated industry is next. In this fireside chat, JFrog Global Field CISO Nir Peleg sits down with Dafna Zahger-Bernanka for a candid look at what has actually changed in the threat landscape, what supervisors now expect institutions to prove (not just claim), and how European enterprises are re-engineering the software supply chain layer for machine-speed defense. Expect a working view of the remediation gap, the evidence that satisfies a supervisor, and what a credible action plan looks like from the CISO's chair, no matter which regulator writes to you next.
2:45 PM – 3:25 PM
3:25 PM
3:25 PM 2 sessions

50

SESSION INTERMEDIATE
Trust at the Speed of AI with Coralogix
Software delivery got faster. Reviews didn't. As that gap widens, your risk exposure grows. Compromised packages, slow root cause analysis, or unauthorized access become the real constraint to reliable software delivery at scale. The data you need to reduce that risk already exists - Artifactory, Xray, Curation, and Access logs already capture these events. But most pipeline activity lands there and is never looked at again. This session shows what it looks like to ask your JFrog questions in plain language. We'll stream these events into the Coralogix telemetry data lake and let Olly, an autonomous investigation agent, answer: which packages the organization actually consumes and by whom, who is reaching past their permissions, what shipped right before an incident. Then we'll schedule those same questions to run every hour, without us, so reviews can also move at machine speed.
3:25 PM – 3:45 PM

51

SESSION INTERMEDIATE
Agentic Speed, Enterprise Quality: Building a trustworthy agent centric development cycle
AI agents can now produce code faster than any human team, but speed alone does not create software that is secure, reliable or maintainable. As developers move from writing code to guiding agents and verifying their output, software engineering needs a new operating model. This presentation introduces the Agent Centric Development Cycle, or AC/DC: Sonar’s methodology for guiding, verifying and improving AI-generated code throughout its lifecycle. We will explore why human review alone is insufficient, how zero-trust, multilayered verification combines deterministic analysis with context-aware agentic reasoning, and how verification can be embedded into development, continuous integration and code maintenance. Attendees will leave with a practical model for building an AI-enabled software factory that can move at agentic speed without sacrificing enterprise quality, security or control.
3:25 PM – 3:45 PM
No matching sessions were found

Thank You!

Thank You for Registering!

Looking forward to swamp with you

Thank You!

Thank you for inquiring about sponsoring swampUP 2024. We’ll be in touch shortly!