Supported Technologies

Compare JFrog Xray source and platform scan coverage by technology.

Xray coverage depends on your package ecosystem and on where the scan runs. Each of the following technologies has its own page for the supported files and limitations.

How to Read This Page

Every table covers two scan methods. The method that applies depends on how you work.

  • Source scanning reads the manifests and lockfiles in your project. It runs from jf audit in Scan Your Source Code, Frogbot, the JFrog IDE plugins, and your pipelines.
  • Platform scanning reads the built artifacts you store in Artifactory, once Xray indexes the repository, build, or Release Bundle that holds them, as described in Configure Indexing.

For more information about when each scan runs, see Scan Types.

📘

Note

These tables show whether a scan method covers an ecosystem. They don't show which files Xray reads or which findings you get. Vulnerabilities, licenses, malicious packages, operational risk, and Smart Remediation vary by ecosystem. Those details are on the ecosystem page.

Artifactory Repository Types

Coverage also depends on the repository holding the artifact.

  • Local repositories: Xray scans them once you index them.
  • Remote repositories: Xray scans only cached artifacts, not the whole upstream registry.
  • Virtual repositories: Xray indexes the local and remote repositories inside them, not the virtual repository.

For more information, see Index Xray Resources and Configure Indexing. Xray rescans indexed artifacts as new threats appear through Impact Analysis, as described in Continuous Monitoring.

Software Packages

The following table shows source scanning and platform scanning coverage for each package ecosystem.

LanguageEcosystemSource ScanningBinary ScanningDetails
Java and KotlinMavenYESYESJava / Kotlin
Java and KotlinGradleYESYESJava / Kotlin
Java and KotlinIvyNOYESJava / Kotlin
ScalaSBTNOYESScala
JavaScriptnpmYESYESJavaScript / TypeScript
JavaScriptYarnYESNOJavaScript / TypeScript
JavaScriptpnpmYESYESJavaScript / TypeScript
JavaScriptBowerNOYESJavaScript / TypeScript
PythonPyPIYESYESPython
PythonCondaYESYESPython
GoGo ModulesYESYESGo
C# and .NETNuGetYESYESC# / .NET
C and C++ConanYESYESC/C++
RubyRubyGemsYESYESRuby
PHPComposerNOYESPHP
RustCargoYES Static SCAYESRust
SwiftSwiftPMYESYESSwift / Objective-C
Objective-CCocoaPodsYESYESSwift / Objective-C
RCRANNOYESR
DartPubNOYESDart / Pub

Static software composition analysis (SCA) means source scanning uses the static SCA engine, which Frogbot V3 and jf audit --static-sca run. Default jf audit, Frogbot V2, and the JFrog IDE plugins still use the earlier dynamic package-manager SCA path. Maven and Gradle support dynamic building. For a comparison, see Source Scanning Engines and Frogbot Versions.

JFrog will eventually deprecate the Frogbot V2 engine and replace it with the Frogbot V3 engine.

📘

Note

JFrog will eventually deprecate the Frogbot V2 engine and replace it with the Frogbot V3 engine. Frogbot V3 uses static SCA or dynamic building, depending on the ecosystem.

Operational risk is available for Maven and npm only.

OS Packages

Xray finds OS packages in indexed artifacts and inside container images.

Package TypeEcosystemSource ScanningBinary Scanning
AlpineAlpine Linux and ChainguardNot applicableYES
DebianDebian packages and Debian ArchiveNot applicableYES
DebianNodeSourceNot applicableYES
DebianPostgreSQL APT RepositoryNot applicableYES
Ubuntu debUbuntu packages, Old Releases, and PortsNot applicableYES
RPMRPM-based Linux distributionsNot applicableYES

Containers

Xray scans images stored in Artifactory. Xray unpacks the layers and scans the OS packages, dependencies, and ML models inside. It also flags CVEs that come from the base image, as described in Base Image Detection.

FormatSource ScanningBinary Scanning
DockerNot applicableYES
OCINot applicableYES

For more information, see Docker / OCI.

Helm Charts

Xray scans a chart by scanning the container images it deploys. Xray never scans the chart's own files, such as templates and values.

Chart TypeSource ScanningBinary Scanning
HelmNot applicableYES
Helm OCINot applicableYES

You must store those images in Artifactory. Xray skips any image it can't find there, so the chart shows findings only for the images it scanned.

For more information, see Helm and Helm OCI.

ML Models

Xray scans ML models you store in Artifactory, whether they sit in an ML repository, a Generic repository, or inside a container image. What Xray reports depends on where the model came from.

ModelIdentificationLicensesMalicious Model Detection
Hugging FaceYESYESYES
All other modelsYESNONO

Models don't carry CVEs, so Xray reports no vulnerabilities for them.

Xray identifies models saved as bin, ckpt, dill, flax, ggml, gguf, h5, hdf5, joblib, keras, mpk, msgpack, nemo, npy, npz, onnx, pb, pdparams, pkl, pt, pth, safetensors, tflite, and zip.

For more information, see ML Models and Malicious Package Detection.

Infrastructure as Code

The following table shows platform scanning coverage for infrastructure as code.

TypeBinary ScanningDetails
Terraform stateYESState files in Terraform Backend repositories, for provider licenses.

Terraform misconfiguration scanning requires JFrog Advanced Security. For more information, see Advanced Security Supported Technologies.

SBOM Formats

Xray reads and generates these software bill of materials (SBOM) formats. You can import an SBOM for scanning, or export an SBOM from scan results.

FormatVersionsFile Types
CycloneDX1.3 to 1.7JSON and XML
SPDX2JSON

Archives in Generic Repositories

In Generic repositories, Xray unpacks these archives and scans what's inside.

TypeSupported Formats
Archive types7z, zip, tar, vmdk, ova, cpio, iso, rar, aar, qcow2
Compression typesgz, xz, bz2, zstd, lzma

Operating System Images

Xray scans an OS image only when its archive format, boot sector, and filesystem are all supported.

ComponentSupported Formats
Archivesimg, iso, vmdk, ova, cpio, qcow2
Boot sectorsGPT and MBR. LVM isn't supported.
FilesystemsEXT4, NTFS, SquashFS, and XFS. EXT3 is supported from Xray 3.149.0.

Related Topics


Did this page help you?