How-Tos

Use the JFrog window to review Software Composition Analysis (SCA) findings and to identify a fixed version for each issue.

Review Scan Results

The JFrog window shows a dependency tree, component details, and issue details. Findings are SCA issues and licenses. For the scanners this extension supports, see Supported Technologies.

To review findings:

  1. Open View > Other Windows > JFrog.
  2. Expand a component in the tree. Direct and transitive dependencies appear in the tree.
  3. Select a component. Components Details shows Name, Version, Type, Licenses, and Top Severity.
  4. Review Components Issues Details. Each issue includes Severity, Summary, Issue Type, Fixed Versions, and Component.
  5. Click the filter icon in the JFrog window toolbar, then select the severities to show.

You can filter by All, Critical, High, Medium, Low, Unknown, and Normal. Use Expand All or Collapse All in the toolbar to change the tree.

Act on Scan Results

The Visual Studio extension doesn't apply upgrades, ignore findings, or send issues to an AI assistant. Use the Fixed Versions value as guidance, then change the dependency in your project.

To act on a vulnerability:

  1. Select the affected component in the JFrog window.
  2. In Components Issues Details, note Fixed Versions.
  3. Update the package version in your project file or package manager to a version listed under Fixed Versions.
  4. Restore or install dependencies.
  5. Click Refresh in the JFrog window and confirm that the issue no longer appears.

Troubleshoot the Extension

Scan and connection messages are written to the Visual Studio Output window.

To view JFrog logs:

  1. Go to View > Output.
  2. In the Show output from dropdown list, select JFrog.

Report issues on the JFrog Visual Studio Extension GitHub issues page.


Did this page help you?