JFrog Xray
  • 07 Dec 2024
  • 1 Minute to read
  • Contributors
  • Dark
    Light

JFrog Xray

  • Dark
    Light

Article summary

JFrog Xray is a universal software composition analysis (SCA) solution that natively integrates with Artifactory, giving developers and DevSecOps teams an easy way to proactively identify vulnerabilities on open source and license compliance violations, before they manifest in production releases.

Integration Method: API

Tables: Vulnerability Finding

Event Types: Artifact summary

JFrog Xray Configuration

This feature is supported on the Cloud (SaaS) platform with an Enterprise X or Enterprise+ license, and on the Self-Hosted platform with a Pro X, Enterprise X , or Enterprise+ license.

API URL: https://<hostname>.jfrog.io/xray/api/v1/summary/artifact.

Jfrog hostname need to be replaced in the placeholder <hostname>.

  1. To get started, get the Access Token by logging into the JFrog platform

  1. Navigate to User management -> Access Tokens -> Generate Token (top right).  Copy the token for use during DataBee configuration.

Note:

Creating a non-expiring token will not require the data source to be updated in the future.

DataBee Configuration

  1. Log into the DataBee console, navigate to Data and click on Add New Data SourceA screenshot of a computer  Description automatically generated

  2. Search for JFrog Xray and click it. 

  3. Select API Ingest. A screenshot of a phone  Description automatically generated

  4. Fill in basic information about the data source. 

  5. In the configuration dialog box, fill in the following:

    1. API_URL: Replace the <hostname> placeholder with the JFrog platform hostname

    2. Token: Paste the token generated previously in this field


  6. Click Submit


Was this article helpful?

Changing your password will log you out immediately. Use the new password to log back in.
First name must have atleast 2 characters. Numbers and special characters are not allowed.
Last name must have atleast 1 characters. Numbers and special characters are not allowed.
Enter a valid email
Enter a valid password
Your profile has been successfully updated.
ESC

Eddy AI, facilitating knowledge discovery through conversational intelligence