Export Scan Results
The JFrog Security platform allows you to export your scan results to simplify identification, assessment, and prioritization of vulnerabilities in your code and dependencies.
- Navigate to Xray → Scans List.
- Under the Git Repositories tab, select a scanned repository.
- Select either the Commits or Pull Requests tab.
- Select a scan you wish to export.
The overview window opens. - On the top, right-hand side of the page, click on the three-dot menu and select Export Scan Data.
The Export Scan Data window opens.
The Export Scan Data window has three tabs: Security, Legal, and SBOM.
Security export
On the Security tab, select the content you want to export:
- Policy Violations — export violations triggered by Xray Watches and Policies. To include violations that were ignored or suppressed, select Include Ignores under Policy Violations.
- License Report
- CVEs
- Operational Risk
- Secrets
- SAST
Select a file format:
- CSV
- JSON
Click Export.
Legal export
On the Legal tab, export license and compliance data for the scanned repository.
SBOM export
On the SBOM tab:
- Under SBOM Standard, select CycloneDX or SPDX.
- Optionally select additional content:
- Multiple license resolution
- Vulnerabilities (VEX)
- CBOM
- Choose a format: XML or JSON.
- Click Export.
For SBOM format details and field descriptions, see Export Scan Results.
Updated 21 days ago
Did this page help you?
