From c0dca72fb6c1fa3cd58bc1c8cca228401db78185 Mon Sep 17 00:00:00 2001 From: s-stumbo Date: Fri, 11 Sep 2026 09:54:27 -0400 Subject: [PATCH 1/4] docs(libraries): add JFrog Curation snippet to Java global config Chainguard Libraries for Java now work with JFrog Curation. Add a reusable blurb snippet describing the integration and include it in the JFrog Artifactory section of the Java global configuration guide. Co-Authored-By: Claude Opus 4.8 (1M context) --- content/chainguard/libraries/java/global-configuration.md | 4 +++- layouts/shortcodes/blurb/jfrog-curation.html | 3 +++ 2 files changed, 6 insertions(+), 1 deletion(-) create mode 100644 layouts/shortcodes/blurb/jfrog-curation.html diff --git a/content/chainguard/libraries/java/global-configuration.md b/content/chainguard/libraries/java/global-configuration.md index 711834fceb..871002f7aa 100644 --- a/content/chainguard/libraries/java/global-configuration.md +++ b/content/chainguard/libraries/java/global-configuration.md @@ -4,7 +4,7 @@ linktitle: "Global configuration" description: "Configuring Chainguard Libraries for Java in your organization" type: "article" date: 2025-03-25T08:04:00+00:00 -lastmod: 2026-08-28T16:31:04+00:00 +lastmod: 2026-09-11T13:54:27+00:00 draft: false tags: ["Chainguard Libraries", "Java"] images: [] @@ -279,6 +279,8 @@ for proxying and hosting, and virtual repositories to combine them. Refer to the Artifactory](https://docs.jfrog.com/artifactory/docs/maven-repositories) for more information. +{{< blurb/jfrog-curation >}} + If you follow the recommended approach to rely on Chainguard Repository's upstream fallback, disable or remove any existing Artifactory remote repository that points at Maven Central, and remove it from the virtual repository your diff --git a/layouts/shortcodes/blurb/jfrog-curation.html b/layouts/shortcodes/blurb/jfrog-curation.html new file mode 100644 index 0000000000..1989a8af07 --- /dev/null +++ b/layouts/shortcodes/blurb/jfrog-curation.html @@ -0,0 +1,3 @@ +

Chainguard Libraries work with JFrog Curation. JFrog Catalog recognizes Chainguard-built and remediated packages before a build requests them, so you can apply Curation policies and consume Chainguard Libraries without waiting for a first-pull scan. The integration doesn't change how Chainguard serves libraries: configure Artifactory using the standard instructions, then use the resulting Artifactory repository as your Curation source.

+ +

JFrog Curation support is currently available only for Chainguard Libraries for Java.

From cf1839917c06ef4895678cc58a669257de0d99ce Mon Sep 17 00:00:00 2001 From: s-stumbo Date: Fri, 11 Sep 2026 11:52:33 -0400 Subject: [PATCH 2/4] update wording Signed-off-by: s-stumbo --- layouts/shortcodes/blurb/jfrog-curation.html | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/layouts/shortcodes/blurb/jfrog-curation.html b/layouts/shortcodes/blurb/jfrog-curation.html index 1989a8af07..df9c723e61 100644 --- a/layouts/shortcodes/blurb/jfrog-curation.html +++ b/layouts/shortcodes/blurb/jfrog-curation.html @@ -1,3 +1,3 @@ -

Chainguard Libraries work with JFrog Curation. JFrog Catalog recognizes Chainguard-built and remediated packages before a build requests them, so you can apply Curation policies and consume Chainguard Libraries without waiting for a first-pull scan. The integration doesn't change how Chainguard serves libraries: configure Artifactory using the standard instructions, then use the resulting Artifactory repository as your Curation source.

+

Together, Chainguard Libraries and JFrog Curation support a self-healing library workflow. When JFrog identifies a vulnerable dependency, [Zero-Touch Remediation](https://jfrog.com/zero-touch-remediation/) can help route the application to a Chainguard-built or remediated version that satisfies your organization's policies, without requiring developers to change their usual Artifactory-based workflow.

-

JFrog Curation support is currently available only for Chainguard Libraries for Java.

+

JFrog Catalog recognizes Chainguard-built and remediated packages before a build requests them, so you can apply Curation policies and consume Chainguard Libraries without waiting for a first-pull scan. The integration doesn't change how Chainguard serves libraries: configure Artifactory using the standard instructions, then use the resulting Artifactory repository as your Curation source.

From 479a9af7a6481c7375b96440a34e4457069e3c3c Mon Sep 17 00:00:00 2001 From: s-stumbo Date: Fri, 11 Sep 2026 11:58:17 -0400 Subject: [PATCH 3/4] updates Signed-off-by: s-stumbo --- content/chainguard/libraries/java/global-configuration.md | 8 +++++--- layouts/shortcodes/blurb/jfrog-curation.html | 2 +- 2 files changed, 6 insertions(+), 4 deletions(-) diff --git a/content/chainguard/libraries/java/global-configuration.md b/content/chainguard/libraries/java/global-configuration.md index 871002f7aa..5f1532f209 100644 --- a/content/chainguard/libraries/java/global-configuration.md +++ b/content/chainguard/libraries/java/global-configuration.md @@ -4,7 +4,7 @@ linktitle: "Global configuration" description: "Configuring Chainguard Libraries for Java in your organization" type: "article" date: 2025-03-25T08:04:00+00:00 -lastmod: 2026-09-11T13:54:27+00:00 +lastmod: 2026-09-11T15:58:17+00:00 draft: false tags: ["Chainguard Libraries", "Java"] images: [] @@ -279,8 +279,6 @@ for proxying and hosting, and virtual repositories to combine them. Refer to the Artifactory](https://docs.jfrog.com/artifactory/docs/maven-repositories) for more information. -{{< blurb/jfrog-curation >}} - If you follow the recommended approach to rely on Chainguard Repository's upstream fallback, disable or remove any existing Artifactory remote repository that points at Maven Central, and remove it from the virtual repository your @@ -289,6 +287,10 @@ those protections. Since Artifactory resolves through the virtual repository in order, a misconfiguration can result in Artifactory serving an unprotected package. +### JFrog Curation and Chainguard Libraries + +{{< blurb/jfrog-curation >}} + ### Initial configuration Use the following steps to add Chainguard Libraries for Java as a remote repository: diff --git a/layouts/shortcodes/blurb/jfrog-curation.html b/layouts/shortcodes/blurb/jfrog-curation.html index df9c723e61..ad8bbc8b7f 100644 --- a/layouts/shortcodes/blurb/jfrog-curation.html +++ b/layouts/shortcodes/blurb/jfrog-curation.html @@ -1,3 +1,3 @@ -

Together, Chainguard Libraries and JFrog Curation support a self-healing library workflow. When JFrog identifies a vulnerable dependency, [Zero-Touch Remediation](https://jfrog.com/zero-touch-remediation/) can help route the application to a Chainguard-built or remediated version that satisfies your organization's policies, without requiring developers to change their usual Artifactory-based workflow.

+

Together, Chainguard Libraries and JFrog Curation support a self-healing library workflow. When JFrog identifies a vulnerable dependency, Zero-Touch Remediation can help route the application to a Chainguard-built or remediated version that satisfies your organization's policies, without requiring developers to change their usual Artifactory-based workflow.

JFrog Catalog recognizes Chainguard-built and remediated packages before a build requests them, so you can apply Curation policies and consume Chainguard Libraries without waiting for a first-pull scan. The integration doesn't change how Chainguard serves libraries: configure Artifactory using the standard instructions, then use the resulting Artifactory repository as your Curation source.

From dabf91adc3c9408f71ffe3a6bfcc1da088c50775 Mon Sep 17 00:00:00 2001 From: s-stumbo Date: Fri, 11 Sep 2026 12:18:28 -0400 Subject: [PATCH 4/4] updates Signed-off-by: s-stumbo --- layouts/shortcodes/blurb/jfrog-curation.html | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/layouts/shortcodes/blurb/jfrog-curation.html b/layouts/shortcodes/blurb/jfrog-curation.html index ad8bbc8b7f..6fb8cc44ae 100644 --- a/layouts/shortcodes/blurb/jfrog-curation.html +++ b/layouts/shortcodes/blurb/jfrog-curation.html @@ -1,3 +1,3 @@ -

Together, Chainguard Libraries and JFrog Curation support a self-healing library workflow. When JFrog identifies a vulnerable dependency, Zero-Touch Remediation can help route the application to a Chainguard-built or remediated version that satisfies your organization's policies, without requiring developers to change their usual Artifactory-based workflow.

+

Together, Chainguard Libraries and JFrog Curation support a self-healing library workflow. When JFrog identifies a vulnerable dependency, Zero-Touch Remediation can help route the application to a Chainguard-remediated version that satisfies your organization's policies, without requiring developers to change their usual Artifactory-based workflow.

JFrog Catalog recognizes Chainguard-built and remediated packages before a build requests them, so you can apply Curation policies and consume Chainguard Libraries without waiting for a first-pull scan. The integration doesn't change how Chainguard serves libraries: configure Artifactory using the standard instructions, then use the resulting Artifactory repository as your Curation source.