Supported Technologies

SAST, CVEs Contextual Analysis, and Secrets Detection

Programming LanguageSource Code SAST (1st party)Source Code CVEs Contextual AnalysisBinary CVEs Contextual AnalysisSecrets Detection
GoInside Docker
JavaMaven & Gradle : Uber/Fat JARs + Thin Jars in Builds
KotlinInside Docker
JavaScriptInside Docker
TypeScriptInside Docker
C# .NETInside Docker
PythonInside Docker
C/C++Inside Docker
RustInside Docker
DockerConditional (depends on contained language)
Helm and Helm OCI✅ (images the chart deploys)✅ (images the chart deploys)
Terraform (IaC)

For binary contextual analysis inside Docker, see Package Applications in Docker for Contextual Analysis.

For Helm and Helm OCI charts, Xray scans the container images the chart deploys and shows contextual analysis and Secrets results on the chart. For more information, see Helm and Helm OCI.

Misconfigurations

  • Infrastructure as code (IaC)
    1. Terraform modules - Supported in JFrog IDE Plugins and JFrog CLI
    2. Terraform plan files - Supported in JFrog CLI
    3. Terraform state files - Supported in JFrog Artifactory (Terraform BE Repository)
  • Applications and Services misconfigurations:
    1. Supported in JFrog Artifactory for Container images
    2. Supported for Helm and Helm OCI charts through the container images the chart deploys. Xray doesn't check the chart's own files for misconfigurations.

Did this page help you?