AppTrust Out-of-the-Box Rules

This page shows a listing of the rules that come with JFrog AppTrust out-of-the-box. In addition to these rules, you can create your own rules.

Tip: You can edit and delete custom rules that you create, but you cannot edit or delete the AppTrust Out-of-the-Box Rules.

Lifecycle Policy Out-of-the-Box Rules

Table 1: Security Rules

Rule NameDescription
Medium CVE with CVSS score between 4.0 and 6.9 (skip if not applicable)Triggers an issue when an application resource (such as a Docker image) contains a package or component affected by a CVE listed in the NVD with a CVSS score in the Medium range (4.0–6.9). Skip “Not Applicable” option: The violation is skipped when the JFrog Applicability Scanner marks the finding as Not Applicable. Otherwise, the issue is triggered.
High CVE with CVSS score between 7.0 and 8.9 (skip if not applicable)Triggers an issue when an application resource (such as a Docker image) contains a package or component affected by a CVE listed in the NVD with a CVSS score in the High range (7.0–8.9). Skip “Not Applicable” option: The violation is skipped when the JFrog Applicability Scanner marks the finding as Not Applicable. Otherwise, the issue is triggered.
Critical CVE with CVSS score between 9.0 and 10.0 (skip if not applicable)Triggers an issue when an application resource (such as a Docker image) contains a package or component affected by a CVE listed in the NVD with a CVSS score in the Critical range (9.0–10.0). Skip “Not Applicable” option: The violation is skipped when the JFrog Applicability Scanner marks the finding as Not Applicable. Otherwise, the issue is triggered.
Medium CVE with CVSS score between 4.0 and 6.9 (ignore applicability)Triggers an issue when an application resource (such as a Docker image) contains a package or component affected by a CVE listed in the NVD with a CVSS score in the Medium range (4.0–6.9). Ignore applicability: Results from the JFrog Applicability Scanner are ignored for this rule.
High CVE with CVSS score between 7.0 and 8.9 (ignore applicability)Triggers an issue when an application resource (such as a Docker image) contains a package or component affected by a CVE listed in the NVD with a CVE score in the High range (7.0–8.9). Ignore applicability: Results from the JFrog Applicability Scanner are ignored for this rule.
Critical CVE with CVSS score between 9.0 and 10.0 (ignore applicability)Triggers an issue when an application resource (such as a Docker image) contains a package or component affected by a CVE listed in the NVD with a CVSS score in the Critical range (9.0–10.0). Ignore applicability: Results from the JFrog Applicability Scanner are ignored for this rule.
All Severities Exposures - Secrets Services ApplicationsTriggers a policy violation when an application version contains secrets, services, or application security findings of any severity.
High and Critical Exposures - Secrets Services ApplicationsTriggers a policy violation when an application version contains secrets, services, or application security findings with High or Critical severity.

Table 2: Evidence

Rule NameDescription
Evidence slug:gradle-build-tool, from:Gradle, version:1, exist on evaluated resourceTriggers a policy violation if the evidence slug:gradle-build-tool, from:Gradle, version:1, predicate type: https://gradle.com/attestations/build-tool/v1 is not attached to the evaluated resource.
Evidence slug:cyclonedx-sbom, from:JFrog, version:1.6, exist on evaluated resourceTriggers a policy violation if the evidence slug:cyclonedx-sbom from:JFrog, version:1.6, predicate type: https://jfrog.com/evidence/cyclonedx/sbom/v1.6, is not attached to the evaluated resource.
Evidence slug:gradle-java-toolchain, from:Gradle, version:1, exist on evaluated resourceTriggers a policy violation if the evidence slug:gradle-java-toolchain, from:Gradle, version:1, predicate type: https://gradle.com/attestations/build-tool/v1 is not attached to the evaluated resource.
Evidence slug:gradle-resolved-dependencies-repository, from:Gradle, version:1, exist on evaluated resourceTriggers a policy violation if the evidence slug:gradle-resolved-dependencies-repository, from:Gradle, version:1, predicate type: https://gradle.com/attestations/resolved-dependencies-repository/v1 is not attached to the evaluated resource.
Evidence slug:gradle-resolved-dependencies, from:Gradle, version:1, exist on evaluated resourceTriggers a policy violation if the evidence slug:gradle-resolved-dependencies, from:Gradle, version:1, predicate type: https://gradle.com/attestations/resolved-dependencies/v1 is not attached to the evaluated resource.
Evidence slug:coguard-scan-results, from:CoGuard, version:1, exist on evaluated resourceTriggers a policy violation if the evidence slug:coguard-scan-results, from:CoGuard, version:1, predicate type: https://coguard.io/evidence/scan/results/v1 is not attached to the evaluated resource.
Evidence slug:dagger-trace-url, from:Dagger, version:1, exist on evaluated resourceTriggers a policy violation if the evidence slug:dagger-trace-url, from:Dagger, version:1, predicate type: https://dagger.io/evidence/trace-url/v1 is not attached to the evaluated resource.
Evidence slug:akuity-promotion, from:Akuity, version:1, exist on evaluated resourceTriggers a policy violation if the evidence slug:akuity-promotion, from:Akuity, version:1, predicate type: https://akuity.io/evidence/promotion/v1 is not attached to the evaluated resource.
Evidence slug:troj-test-result, from:Troj.ai, version:1, exist on evaluated resourceTriggers a policy violation if the evidence slug:troj-test-result, from:Troj.ai, version:1, predicate type: https://troj.ai/attestation/test-result/v1 is not attached to the evaluated resource.
Evidence slug:nightvision-vulnscan, from:NightVision, version:1, exist on evaluated resourceTriggers a policy violation if the evidence slug:nightvision-vulnscan, from:NightVision, version:1, predicate type: https://nightvision.net/evidence/vulnscan/v1 is not attached to the evaluated resource.
Evidence slug:servicenow-change-approval, from:ServiceNow, version:1, exist on evaluated resourceTriggers a policy violation if the evidence https://servicenow.com/approval/v1 slug:servicenow-change-approval, from:ServiceNow, version:1, predicate type: https://servicenow.com/approval/v1 is not attached to the evaluated resource.
Evidence slug:sonarsource-sonarqube, from:Sonar, version:1, exist on evaluated resourceTriggers a policy violation if the evidence slug:sonarsource-sonarqube, from:Sonar, version:1, predicate type: https://sonarsource.com/evidence/sonarqube/v1 is not attached to the evaluated resource.
Evidence slug:cosign, from:OCI, version:1, exist on evaluated resourceTriggers a policy violation if the evidence slug:cosign, from:OCI, version:1, predicate type: https://cosign.sigstore.dev/attestation/v1 is not attached to the evaluated resource.
Evidence slug:slsa-provenance, from:Github, version:1, exist on evaluated resourceTriggers a policy violation if the evidence slug:slsa-provenance, from:GitHub, version:1, predicate type: https://slsa.dev/provenance/v1 is not attached to the evaluated resource.





Did this page help you?