JFrog Security Deprecations
The following deprecations have already been implemented in JFrog Xray.
| Deprecation | Version/Date | Deprecation process and next steps | What has to be done? |
|---|---|---|---|
| Block Download feature for remote repositories in JFrog Xray | We are rolling this out in phases, from April 1, 2026, through November 2026. to ensure every customer has the support they need to migrate. | JFrog Curation makes automated, policy-driven decisions based on metadata before the download ever starts. This results in split-second decisions and clear, immediate feedback that keeps your developers moving.
| We want to make this transition as seamless as possible for your team.
|
| Deprecated integrations | Xray 3.0 | Aqua, WhiteSource, and Black Duck out-of-the-box integrations have been deprecated in the Xray UI integrations page (Self-hosted) | Custom integrations are still available, supporting integrating to any external source of your choice. The VulnDB integration, now transparently integrated into Xray. |
| Xray homepage in the Platform UI (Self-hosted) | Xray 3.0 | The Xray homepage, as part of the JFrog Platform UI unification, this page has been removed. | |
| Xray 2.0 Reports functionality | Xray 3.0 | The Xray 3.0 Reports, which are new a functionality, require new permissions. | |
| REST API deprecations | Xray 3.0 |
|
Updated 4 months ago
Did this page help you?
