Source Scanning Engines and Frogbot Versions

Compare static SCA with dynamic scanning and Frogbot versions.

JFrog source scanning uses either a dynamic package-manager engine or the static Software Composition Analysis (SCA) engine. The engine determines how JFrog discovers dependencies, which project files it reads, and which ecosystems it supports.

Frogbot V3 and jf audit --static-sca use the static SCA engine. Maven and Gradle are exceptions: Frogbot V3 uses dynamic building for these ecosystems. The Frogbot V2 engine will eventually be deprecated and replaced by the Frogbot V3 engine. Default jf audit, Frogbot V2, and the JFrog IDE plugins use the dynamic package-manager path.

This page explains the engine behind JFrog CLI jf audit, Frogbot V2, and Frogbot V3. For the exact files and dependency graph available for each ecosystem, open the ecosystem page from Supported Technologies.

Dynamic and Static SCA Engines

The following table compares how the dynamic package-manager engine and the static SCA engine discover dependencies.

DimensionDynamic Package-Manager EngineStatic SCA Engine
Dependency discoveryRuns the package manager to resolve the project dependency treeReads supported manifests, lockfiles, and project metadata directly
Build environmentRequires the relevant package manager and, in some cases, an installed or built project. Maven and Gradle support dynamic building.Does not run the package manager or require a build environment
Primary toolsDefault jf audit, IDEs, and Frogbot V2Frogbot V3 and jf audit --static-sca
Ecosystem coverageDepends on the package managers available in the scan environmentDepends on the files the static SCA parser supports
Dependency graphUses the graph returned by the package managerCan provide a full or flat graph, depending on the ecosystem and available files

The engines can support different files for the same ecosystem. For example, the static SCA engine supports ecosystems such as Gradle, pnpm, Conda, Conan, and Cargo that are not covered by the dynamic path in the supported configurations shown in Supported Technologies.

Frogbot V2 and Frogbot V3

The following table compares Frogbot V2 and Frogbot V3. V3 adds snippet detection, centralized configuration in the JFrog Platform, and Auto-PR integration.

DimensionFrogbot V2Frogbot V3
SCA engineDynamic package-manager engineStatic SCA engine, with dynamic building for Maven and Gradle
Dependency discoveryUses package-manager outputParses supported project files without executing package managers, except Maven and Gradle, which use dynamic building
Project detectionUses the repository scan configurationAutomatically detects nested and multi-package project structures
Centralized configurationUses per-repository frogbot-config.yml files and environment variablesConfig profiles in the JFrog Platform at the server, folder, repository, and workspace levels
Snippet detectionNot availableDetects code snippets copied from open-source projects, even when they are not installed as a dependency
Auto-PROpens autofix pull requests from repository configurationAuto-PR is managed in the JFrog Platform and opens fix pull requests during commit scans
Smart RemediationNot availableSupported for npm, Maven, and PyPI
⚠️

Warning

The first Frogbot V3 scan switches that Git repository to V3 mode. You can't switch the repository back to V2. You can trial V3 on a repository that you don't need to scan with V2 again.

For more information, see Frogbot V3. For the legacy workflow, see Frogbot V2.

jf audit and Static SCA

Default jf audit uses the dynamic package-manager engine. You can add --static-sca to use the same static SCA engine as Frogbot V3. For all command options, see Scan Your Source Code.

Static SCA support still depends on the ecosystem and project files.

Scanning Method Options

  • Default jf audit is an on-demand local scan when the dynamic engine supports your package manager.
  • jf audit --static-sca is an on-demand scan that uses static SCA without running the package manager, including ecosystems that require that engine.
  • Frogbot V2 remains available for repositories that must stay on the V2 workflow.
  • Frogbot V3 is Git-based scanning with static SCA, centralized configuration, and visibility in the JFrog Platform.
  • Platform scanning covers built packages and other artifacts stored in indexed Artifactory repositories. It reads the artifact rather than the source project files.

Each ecosystem page lists the supported source files, dependency graph, binary formats, and capability differences for that technology. For more information, see Scan Types.

Related Topics


Did this page help you?