Supported Technologies
SAST, CVEs Contextual Analysis, and Secrets Detection
| Programming Language | Source Code SAST (1st party) | Source Code CVEs Contextual Analysis | Binary CVEs Contextual Analysis | Secrets Detection |
|---|---|---|---|---|
| Go | ✅ | ✅ | Inside Docker | ✅ |
| Java | ✅ | ✅ | Maven & Gradle : Uber/Fat JARs + Thin Jars in Builds | ✅ |
| Kotlin | ✅ | Inside Docker | ✅ | |
| JavaScript | ✅ | ✅ | Inside Docker | ✅ |
| TypeScript | ✅ | ✅ | Inside Docker | ✅ |
| C# .NET | ✅ | ✅ | Inside Docker | ✅ |
| Python | ✅ | ✅ | Inside Docker | ✅ |
| C/C++ | ✅ | Inside Docker | ✅ | |
| Rust | ✅ | Inside Docker | ✅ | |
| Docker | Conditional (depends on contained language) | |||
| Helm and Helm OCI | ✅ (images the chart deploys) | ✅ (images the chart deploys) | ||
| Terraform (IaC) | ✅ | ✅ |
For binary contextual analysis inside Docker, see Package Applications in Docker for Contextual Analysis.
For Helm and Helm OCI charts, Xray scans the container images the chart deploys and shows contextual analysis and Secrets results on the chart. For more information, see Helm and Helm OCI.
Misconfigurations
- Infrastructure as code (IaC)
- Terraform modules - Supported in JFrog IDE Plugins and JFrog CLI
- Terraform plan files - Supported in JFrog CLI
- Terraform state files - Supported in JFrog Artifactory (Terraform BE Repository)
- Applications and Services misconfigurations:
- Supported in JFrog Artifactory for Container images
- Supported for Helm and Helm OCI charts through the container images the chart deploys. Xray doesn't check the chart's own files for misconfigurations.
Updated 16 days ago
Did this page help you?
