AppTrust Out-of-the-Box Rules
This page shows a listing of the rules that come with JFrog AppTrust out-of-the-box. In addition to these rules, you can create your own rules.
Tip: You can edit and delete custom rules that you create, but you cannot edit or delete the AppTrust Out-of-the-Box Rules.
Lifecycle Policy Out-of-the-Box Rules
Table 1: Security Rules
| Rule Name | Description |
|---|---|
| Medium CVE with CVSS score between 4.0 and 6.9 (skip if not applicable) | Triggers an issue when an application resource (such as a Docker image) contains a package or component affected by a CVE listed in the NVD with a CVSS score in the Medium range (4.0–6.9). Skip “Not Applicable” option: The violation is skipped when the JFrog Applicability Scanner marks the finding as Not Applicable. Otherwise, the issue is triggered. |
| High CVE with CVSS score between 7.0 and 8.9 (skip if not applicable) | Triggers an issue when an application resource (such as a Docker image) contains a package or component affected by a CVE listed in the NVD with a CVSS score in the High range (7.0–8.9). Skip “Not Applicable” option: The violation is skipped when the JFrog Applicability Scanner marks the finding as Not Applicable. Otherwise, the issue is triggered. |
| Critical CVE with CVSS score between 9.0 and 10.0 (skip if not applicable) | Triggers an issue when an application resource (such as a Docker image) contains a package or component affected by a CVE listed in the NVD with a CVSS score in the Critical range (9.0–10.0). Skip “Not Applicable” option: The violation is skipped when the JFrog Applicability Scanner marks the finding as Not Applicable. Otherwise, the issue is triggered. |
| Medium CVE with CVSS score between 4.0 and 6.9 (ignore applicability) | Triggers an issue when an application resource (such as a Docker image) contains a package or component affected by a CVE listed in the NVD with a CVSS score in the Medium range (4.0–6.9). Ignore applicability: Results from the JFrog Applicability Scanner are ignored for this rule. |
| High CVE with CVSS score between 7.0 and 8.9 (ignore applicability) | Triggers an issue when an application resource (such as a Docker image) contains a package or component affected by a CVE listed in the NVD with a CVE score in the High range (7.0–8.9). Ignore applicability: Results from the JFrog Applicability Scanner are ignored for this rule. |
| Critical CVE with CVSS score between 9.0 and 10.0 (ignore applicability) | Triggers an issue when an application resource (such as a Docker image) contains a package or component affected by a CVE listed in the NVD with a CVSS score in the Critical range (9.0–10.0). Ignore applicability: Results from the JFrog Applicability Scanner are ignored for this rule. |
| All Severities Exposures - Secrets Services Applications | Triggers a policy violation when an application version contains secrets, services, or application security findings of any severity. |
| High and Critical Exposures - Secrets Services Applications | Triggers a policy violation when an application version contains secrets, services, or application security findings with High or Critical severity. |
Table 2: Evidence
| Rule Name | Description |
|---|---|
| Evidence slug:gradle-build-tool, from:Gradle, version:1, exist on evaluated resource | Triggers a policy violation if the evidence slug:gradle-build-tool, from:Gradle, version:1, predicate type: https://gradle.com/attestations/build-tool/v1 is not attached to the evaluated resource. |
| Evidence slug:cyclonedx-sbom, from:JFrog, version:1.6, exist on evaluated resource | Triggers a policy violation if the evidence slug:cyclonedx-sbom from:JFrog, version:1.6, predicate type: https://jfrog.com/evidence/cyclonedx/sbom/v1.6, is not attached to the evaluated resource. |
| Evidence slug:gradle-java-toolchain, from:Gradle, version:1, exist on evaluated resource | Triggers a policy violation if the evidence slug:gradle-java-toolchain, from:Gradle, version:1, predicate type: https://gradle.com/attestations/build-tool/v1 is not attached to the evaluated resource. |
| Evidence slug:gradle-resolved-dependencies-repository, from:Gradle, version:1, exist on evaluated resource | Triggers a policy violation if the evidence slug:gradle-resolved-dependencies-repository, from:Gradle, version:1, predicate type: https://gradle.com/attestations/resolved-dependencies-repository/v1 is not attached to the evaluated resource. |
| Evidence slug:gradle-resolved-dependencies, from:Gradle, version:1, exist on evaluated resource | Triggers a policy violation if the evidence slug:gradle-resolved-dependencies, from:Gradle, version:1, predicate type: https://gradle.com/attestations/resolved-dependencies/v1 is not attached to the evaluated resource. |
| Evidence slug:coguard-scan-results, from:CoGuard, version:1, exist on evaluated resource | Triggers a policy violation if the evidence slug:coguard-scan-results, from:CoGuard, version:1, predicate type: https://coguard.io/evidence/scan/results/v1 is not attached to the evaluated resource. |
| Evidence slug:dagger-trace-url, from:Dagger, version:1, exist on evaluated resource | Triggers a policy violation if the evidence slug:dagger-trace-url, from:Dagger, version:1, predicate type: https://dagger.io/evidence/trace-url/v1 is not attached to the evaluated resource. |
| Evidence slug:akuity-promotion, from:Akuity, version:1, exist on evaluated resource | Triggers a policy violation if the evidence slug:akuity-promotion, from:Akuity, version:1, predicate type: https://akuity.io/evidence/promotion/v1 is not attached to the evaluated resource. |
| Evidence slug:troj-test-result, from:Troj.ai, version:1, exist on evaluated resource | Triggers a policy violation if the evidence slug:troj-test-result, from:Troj.ai, version:1, predicate type: https://troj.ai/attestation/test-result/v1 is not attached to the evaluated resource. |
| Evidence slug:nightvision-vulnscan, from:NightVision, version:1, exist on evaluated resource | Triggers a policy violation if the evidence slug:nightvision-vulnscan, from:NightVision, version:1, predicate type: https://nightvision.net/evidence/vulnscan/v1 is not attached to the evaluated resource. |
| Evidence slug:servicenow-change-approval, from:ServiceNow, version:1, exist on evaluated resource | Triggers a policy violation if the evidence https://servicenow.com/approval/v1 slug:servicenow-change-approval, from:ServiceNow, version:1, predicate type: https://servicenow.com/approval/v1 is not attached to the evaluated resource. |
| Evidence slug:sonarsource-sonarqube, from:Sonar, version:1, exist on evaluated resource | Triggers a policy violation if the evidence slug:sonarsource-sonarqube, from:Sonar, version:1, predicate type: https://sonarsource.com/evidence/sonarqube/v1 is not attached to the evaluated resource. |
| Evidence slug:cosign, from:OCI, version:1, exist on evaluated resource | Triggers a policy violation if the evidence slug:cosign, from:OCI, version:1, predicate type: https://cosign.sigstore.dev/attestation/v1 is not attached to the evaluated resource. |
| Evidence slug:slsa-provenance, from:Github, version:1, exist on evaluated resource | Triggers a policy violation if the evidence slug:slsa-provenance, from:GitHub, version:1, predicate type: https://slsa.dev/provenance/v1 is not attached to the evaluated resource. |
Updated 3 days ago
Did this page help you?
