Event: swampUP 2026
Dates: September 1-3, 2026
Location: The Glasshouse, New York City
Host: JFrog Ltd. (Nasdaq: FROG)
JFrog brings its annual user conference to Manhattan for three days built around one question: how do you keep a software supply chain trustworthy when most of the code moving through it is being written by machines. swampUP has always been a DevOps and DevSecOps event. This year the agenda leans hard into AI, agentic tooling, and the registries that feed both.
Format
Day one is JFrog Academy Training Day, with hands-on labs. Days two and three carry the keynotes, breakout tracks, technical deep dives, and the expo hall. Registration covers keynotes, breakouts, workshops, expo access, networking events, meals, and an invitation to the community gala. Hands-on training labs carry an extra charge and come with CPE credits. Discounted hotel blocks are available through the event site.
Speakers
The lineup pulls from the companies currently defining AI-assisted development and the ones trying to secure it. Jason Clinton, Deputy CISO at Anthropic, delivers a keynote on rethinking security with AI. David Pan, Field CTO at Cursor, covers what it takes for enterprise engineering teams to adopt coding agents at scale, drawing on two decades leading teams at Mixpanel, Twitter, and Amazon. Speakers from Microsoft, NVIDIA, and Google’s Wiz round out the roster.
A panel on the future of remediation puts Moderne CEO Jonathan Schneider, Echo Security CTO Eylam Milner, Broadcom Tanzu CTO James Watters, and Chainguard Field CTO Behn Williams on stage with JFrog Chief Strategy Officer Gal Marder. The premise is uncomfortable and worth sitting through: frontier models are finding and exploiting faster than traditional security cycles can patch.
What the sessions are actually about
JFrog’s own research frames the problem. Something like 97% of organizations say they have AI governance in place, while 53% are still pulling models straight from public registries where malicious payloads have already turned up. That gap is the conference thesis.
One session digs into the March 2026 Trivy compromise, where attackers redirected 76 of 77 release tags on a widely trusted CI/CD security action to credential-stealing malware while affected pipelines kept looking healthy. The session maps five common pipeline exposures against eight compliance frameworks including NIST SP 800-53, PCI DSS 4.0, and SOC 2, and reaches a finding worth the ticket price on its own: none of the eight explicitly require pinning CI/CD dependencies to immutable commit SHAs, the one control that would have stopped it.
Other tracks cover replacing tool sprawl with platform-level governance, embedding agentic AI into the delivery pipeline without breaking compliance, and treating models and binaries as artifacts with the same provenance requirements as code.
The gala
Evening programming moves to the Intrepid Museum. A happy hour runs on the carrier’s flight deck, and the gala dinner features a keynote from Carey Lohrenz, the first female F-14 Tomcat pilot in U.S. Navy history, on decision-making under pressure. It is the kind of thing that reads as filler on an agenda and tends not to be.
Who should go
Platform engineers, DevSecOps leads, and security architects at organizations already running Artifactory or evaluating it. Also relevant to anyone whose company has quietly started letting coding agents commit to main and has not yet worked out what that does to their attestation story.