Cross-Product Projects Support

See where JFrog Projects support appears across Artifactory, Xray, Distribution, AppTrust, JFrog ML, and platform administration.

Cross-Product Projects Support

JFrog Projects are core management entities in the JFrog Platform that centralize all resources and users tied to a specific department, team, or product. They adapt to your organizational structure by letting you assign, manage, and control project resources, such as repositories, builds, and Release Bundles. By providing a single view for managing development activities at scale, Projects ensure clear operational governance, resource ownership, and cost accountability.

As your organization grows, this combination of delegated administration and resource isolation makes Projects the recommended way to work with the JFrog Platform. The following tables list the releases that support Projects and the improvements delivered so far, organized by product. The Announced Version column shows SaaS and Self-managed versions when both exist.

JFrog Artifactory

The following table lists JFrog Artifactory capabilities for binary and repository management that respect project boundaries for OpenID Connect (OIDC) identity mappings, repository views, and webhooks.

Feature DescriptionPainValueAnnounced VersionDocumentation Link
OIDC Mapping Visibility for Admins: Restricts Project Admins from viewing global OIDC identity mappings.Excessive global privilege exposure when admins view enterprise-wide authentication data.Enhance security compliance by limiting Project Admins to viewing only identity mappings applicable to their assigned projects.SaaS: Artifactory 7.161.5
Self-managed: Artifactory 7.161.15
Configure an OIDC integration
Project Virtual Repository Filtering for Developers: All Projects and Set Me Up views show only relevant virtual repositories.Cluttered repository lists showing virtual repositories from projects unrelated to the developer's work.Boost developer productivity by filtering out irrelevant enterprise repositories and simplifying workspace navigation.SaaS: Artifactory 7.156.2
Self-managed: Artifactory 7.161.15
Virtual repositories
Project-Scoped Build Webhooks for Admins: Support for webhooks for project-related builds.High noise from global webhook triggers alerting teams to builds outside their ownership.Improve automation efficiency by routing build event webhooks exclusively to the specific project teams that own them.SaaS: Artifactory 7.122.2
Self-managed: Artifactory 7.125.4
Webhook event types
Project-Scoped Release Bundle Webhooks for Admins: Support for webhooks for project-related Release Bundle v2 versions.Global Release Bundle webhooks notify teams about promotions and deletions outside their ownership.Improve automation efficiency by scoping Release Bundle upload, promotion, and delete notifications to the owning project.SaaS: Artifactory 7.125.3
Self-managed: Artifactory 7.125.4
Webhook event types
Project Admin Resource Permissions for Admins: Grant Project Admins Manage Resources permissions while preventing them from creating or managing remote repositories.Project Admins needed either full remote-repository control or insufficient resource management rights.Tighten delegated administration by separating resource management from remote-repository creation and management.SaaS: Artifactory 7.134.0
Self-managed: Artifactory 7.133.3
Manage project roles
Resource Management Granularity in Projects for Admins: Assign create, update, or delete permissions for remote, local, and virtual repositories separately.Coarse project-admin privileges forced all-or-nothing repository management across repository types.Scale project administration with finer control over which repository types Project Admins can create, update, or delete.SaaS: Artifactory 7.146.0
Self-managed:
Manage project roles
Archive Packages Search for Project Admins: Project Admins can use Archive Search scoped to packages in projects they manage.Project Admins couldn't search archived packages without broader platform privileges.Enable self-service archive recovery within project boundaries.SaaS: Artifactory 7.123.0
Self-managed: Artifactory 7.125.4
Smart Archiving
Project Support for OpenID Connect Integrations for Admins: Project Admins can create identity mappings associated with specific projects.OIDC mappings were global-only, so project teams couldn't own authentication mappings for their pipelines.Delegate OIDC configuration by allowing project-level identity mappings alongside global mappings.SaaS: Artifactory 7.94.1
Self-managed:
Configure an OIDC integration

JFrog Security

The following table lists JFrog Xray and JFrog Runtime capabilities that scope security data and metrics to projects, including role-based access control (RBAC).

Feature DescriptionPainValueAnnounced VersionDocumentation Link
Project-Scoped RBAC for Security: Enforces project-scoped RBAC for runtime-detected images.Unauthorized access to runtime container security data across different teams.Strengthen multi-tenant data privacy by restricting runtime container vulnerability views strictly to assigned project owners.SaaS: Runtime Security 1.8
Self-managed:
Access control
Runtime Project-Level Filtering for Security: Vulnerability Prioritization Dashboard and Live Assessment Highlights support project-scoped metrics via projectKey.Project-scoped users couldn't filter runtime vulnerability and live assessment metrics to their repositories.Focus runtime risk by scoping dashboard and highlights data to each project's repositories.SaaS: Runtime Security 1.19
Self-managed:
Inspecting live software components
Xray Overview Project Scoping for Security: Added Projects support to the Xray Overview, scoping adoption and policy metrics.Difficulty filtering security posture, adoption trends, and CVE violations to specific team ownership.Accelerate risk remediation by providing project teams with dedicated security posture, violation, and compliance metrics.SaaS: Xray 3.148.0
Self-managed: Xray 3.150.17
Xray Overview

JFrog Distribution

The following table lists JFrog Distribution capabilities for Edge delivery and Release Bundles that keep Release Bundle v2 workflows aligned with project ownership. Distribution publishes a single release-notes stream used for Self-managed deployments and paired platform versions. The same announced version is listed for both when no separate SaaS announcement exists.

Feature DescriptionPainValueAnnounced VersionDocumentation Link
Source Project Visibility for Developers: Distributed Release Bundles v2 now display their source project.Naming collisions when managing release bundles from different teams on the same Edge service.Ensure deployment precision by disambiguating identically named release bundles from different teams on shared Edge services.SaaS: Distribution 2.28.1
Self-managed: Distribution 2.28.1
View release bundles on Edge services
Project-Level Role Permissions for Admins: Define distribution permissions for project-level roles.Lack of granular control over which team members can distribute Release Bundle v2 versions.Empower decentralized team operations by delegating Release Bundle distribution authority directly to Project Admins.SaaS: Distribution 2.28.1
Self-managed: Distribution 2.28.1
Manage project roles
Release Bundle v2 Project Distribution for Developers: Distribute Release Bundles v2 that were created in the context of a specific project.Inability to push project-scoped Release Bundles to target Edge services without global elevation.Streamline secure software delivery by maintaining strict project context and policy compliance from build through edge distribution.SaaS: Distribution 2.21.3
Self-managed: Distribution 2.21.3
Distribute Release Bundles v2

JFrog AppTrust and Governance

The following table lists JFrog AppTrust and governance capabilities that apply project context to insights and lifecycle policies. These services publish SaaS release notes. Self-managed counterparts aren't listed separately in the Release Information publication.

Feature DescriptionPainValueAnnounced VersionDocumentation Link
Project Insights Dashboard for Admins: Introduces a dedicated insights dashboard at the project level.Lack of high-level visibility into deployment failures across a team's entire portfolio.Optimize engineering velocity by tracking DevOps Research and Assessment (DORA) metrics, deployment health, and CVE blast radius at the project portfolio level.SaaS: AppTrust Service 1.75.0
Self-managed:
Project insights
Multi-Scope Lifecycle Policies for Admins: Define multiple applications or projects in a single lifecycle policy scope.Duplicated policy administration effort when multiple projects require identical governance rules.Scale enterprise governance by eliminating administrative duplication and applying uniform release policies across project groups.SaaS: Unified Policy 1.44.0
Self-managed:
Create lifecycle policy

JFrog ML

The following table lists JFrog ML capabilities for the AI supply chain that apply project context to AI tooling and Model Context Protocol (MCP) runtime usage.

Feature DescriptionPainValueAnnounced VersionDocumentation Link
Project-Scoped MCP Gateway for Developers: MCP Gateway scripts are pre-populated with project context.Tedious manual AI tool setup and duplicate-project errors disrupting model workflows.Accelerate AI model onboarding by embedding project context directly into automated setup scripts and runtime usage analytics.SaaS: JFrog ML H1 2026
Self-managed:
AI tools and integrations

JFrog Platform Federation

The following table lists JFrog Grid platform administration capabilities that keep project entities consistent across environments.

Feature DescriptionPainValueAnnounced VersionDocumentation Link
Project Entity Sync for Admins: Introduces synchronization for major platform entities across environments.Difficult and error-prone manual duplication of project structures across environments.Maintain cross-environment consistency by automatically synchronizing projects, members, and RBAC roles across multi-region SaaS endpoints.SaaS: JFrog Grid
Self-managed:
JFrog Grid

Related Topics


Did this page help you?