Source Scanning Engines and Frogbot Versions
Compare static SCA with dynamic scanning and Frogbot versions.
JFrog source scanning uses either a dynamic package-manager engine or the static Software Composition Analysis (SCA) engine. The engine determines how JFrog discovers dependencies, which project files it reads, and which ecosystems it supports.
Frogbot V3 and jf audit --static-sca use the static SCA engine. Maven and Gradle are exceptions: Frogbot V3 uses dynamic building for these ecosystems. The Frogbot V2 engine will eventually be deprecated and replaced by the Frogbot V3 engine. Default jf audit, Frogbot V2, and the JFrog IDE plugins use the dynamic package-manager path.
This page explains the engine behind JFrog CLI jf audit, Frogbot V2, and Frogbot V3. For the exact files and dependency graph available for each ecosystem, open the ecosystem page from Supported Technologies.
Dynamic and Static SCA Engines
The following table compares how the dynamic package-manager engine and the static SCA engine discover dependencies.
| Dimension | Dynamic Package-Manager Engine | Static SCA Engine |
|---|---|---|
| Dependency discovery | Runs the package manager to resolve the project dependency tree | Reads supported manifests, lockfiles, and project metadata directly |
| Build environment | Requires the relevant package manager and, in some cases, an installed or built project. Maven and Gradle support dynamic building. | Does not run the package manager or require a build environment |
| Primary tools | Default jf audit, IDEs, and Frogbot V2 | Frogbot V3 and jf audit --static-sca |
| Ecosystem coverage | Depends on the package managers available in the scan environment | Depends on the files the static SCA parser supports |
| Dependency graph | Uses the graph returned by the package manager | Can provide a full or flat graph, depending on the ecosystem and available files |
The engines can support different files for the same ecosystem. For example, the static SCA engine supports ecosystems such as Gradle, pnpm, Conda, Conan, and Cargo that are not covered by the dynamic path in the supported configurations shown in Supported Technologies.
Frogbot V2 and Frogbot V3
The following table compares Frogbot V2 and Frogbot V3. V3 adds snippet detection, centralized configuration in the JFrog Platform, and Auto-PR integration.
| Dimension | Frogbot V2 | Frogbot V3 |
|---|---|---|
| SCA engine | Dynamic package-manager engine | Static SCA engine, with dynamic building for Maven and Gradle |
| Dependency discovery | Uses package-manager output | Parses supported project files without executing package managers, except Maven and Gradle, which use dynamic building |
| Project detection | Uses the repository scan configuration | Automatically detects nested and multi-package project structures |
| Centralized configuration | Uses per-repository frogbot-config.yml files and environment variables | Config profiles in the JFrog Platform at the server, folder, repository, and workspace levels |
| Snippet detection | Not available | Detects code snippets copied from open-source projects, even when they are not installed as a dependency |
| Auto-PR | Opens autofix pull requests from repository configuration | Auto-PR is managed in the JFrog Platform and opens fix pull requests during commit scans |
| Smart Remediation | Not available | Supported for npm, Maven, and PyPI |
Warning
The first Frogbot V3 scan switches that Git repository to V3 mode. You can't switch the repository back to V2. You can trial V3 on a repository that you don't need to scan with V2 again.
For more information, see Frogbot V3. For the legacy workflow, see Frogbot V2.
jf audit and Static SCA
Default jf audit uses the dynamic package-manager engine. You can add --static-sca to use the same static SCA engine as Frogbot V3. For all command options, see Scan Your Source Code.
Static SCA support still depends on the ecosystem and project files.
Scanning Method Options
- Default
jf auditis an on-demand local scan when the dynamic engine supports your package manager. jf audit --static-scais an on-demand scan that uses static SCA without running the package manager, including ecosystems that require that engine.- Frogbot V2 remains available for repositories that must stay on the V2 workflow.
- Frogbot V3 is Git-based scanning with static SCA, centralized configuration, and visibility in the JFrog Platform.
- Platform scanning covers built packages and other artifacts stored in indexed Artifactory repositories. It reads the artifact rather than the source project files.
Each ecosystem page lists the supported source files, dependency graph, binary formats, and capability differences for that technology. For more information, see Scan Types.
Related Topics
Updated 1 day ago
