Supported Technologies
Compare JFrog Xray source and platform scan coverage by technology.
Xray coverage depends on your package ecosystem and on where the scan runs. Each of the following technologies has its own page for the supported files and limitations.
How to Read This Page
Every table covers two scan methods. The method that applies depends on how you work.
- Source scanning reads the manifests and lockfiles in your project. It runs from
jf auditin Scan Your Source Code, Frogbot, the JFrog IDE plugins, and your pipelines. - Platform scanning reads the built artifacts you store in Artifactory, once Xray indexes the repository, build, or Release Bundle that holds them, as described in Configure Indexing.
For more information about when each scan runs, see Scan Types.
Note
These tables show whether a scan method covers an ecosystem. They don't show which files Xray reads or which findings you get. Vulnerabilities, licenses, malicious packages, operational risk, and Smart Remediation vary by ecosystem. Those details are on the ecosystem page.
Artifactory Repository Types
Coverage also depends on the repository holding the artifact.
- Local repositories: Xray scans them once you index them.
- Remote repositories: Xray scans only cached artifacts, not the whole upstream registry.
- Virtual repositories: Xray indexes the local and remote repositories inside them, not the virtual repository.
For more information, see Index Xray Resources and Configure Indexing. Xray rescans indexed artifacts as new threats appear through Impact Analysis, as described in Continuous Monitoring.
Software Packages
The following table shows source scanning and platform scanning coverage for each package ecosystem.
| Language | Ecosystem | Source Scanning | Binary Scanning | Details |
|---|---|---|---|---|
| Java and Kotlin | Maven | Java / Kotlin | ||
| Java and Kotlin | Gradle | Java / Kotlin | ||
| Java and Kotlin | Ivy | Java / Kotlin | ||
| Scala | SBT | Scala | ||
| JavaScript | npm | JavaScript / TypeScript | ||
| JavaScript | Yarn | JavaScript / TypeScript | ||
| JavaScript | pnpm | JavaScript / TypeScript | ||
| JavaScript | Bower | JavaScript / TypeScript | ||
| Python | PyPI | Python | ||
| Python | Conda | Python | ||
| Go | Go Modules | Go | ||
| C# and .NET | NuGet | C# / .NET | ||
| C and C++ | Conan | C/C++ | ||
| Ruby | RubyGems | Ruby | ||
| PHP | Composer | PHP | ||
| Rust | Cargo | Rust | ||
| Swift | SwiftPM | Swift / Objective-C | ||
| Objective-C | CocoaPods | Swift / Objective-C | ||
| R | CRAN | R | ||
| Dart | Pub | Dart / Pub |
Static software composition analysis (SCA) means source scanning uses the static SCA engine, which Frogbot V3 and jf audit --static-sca run. Default jf audit, Frogbot V2, and the JFrog IDE plugins still use the earlier dynamic package-manager SCA path. Maven and Gradle support dynamic building. For a comparison, see Source Scanning Engines and Frogbot Versions.
JFrog will eventually deprecate the Frogbot V2 engine and replace it with the Frogbot V3 engine.
Note
JFrog will eventually deprecate the Frogbot V2 engine and replace it with the Frogbot V3 engine. Frogbot V3 uses static SCA or dynamic building, depending on the ecosystem.
Operational risk is available for Maven and npm only.
OS Packages
Xray finds OS packages in indexed artifacts and inside container images.
| Package Type | Ecosystem | Source Scanning | Binary Scanning |
|---|---|---|---|
| Alpine | Alpine Linux and Chainguard | Not applicable | |
| Debian | Debian packages and Debian Archive | Not applicable | |
| Debian | NodeSource | Not applicable | |
| Debian | PostgreSQL APT Repository | Not applicable | |
| Ubuntu deb | Ubuntu packages, Old Releases, and Ports | Not applicable | |
| RPM | RPM-based Linux distributions | Not applicable |
Containers
Xray scans images stored in Artifactory. Xray unpacks the layers and scans the OS packages, dependencies, and ML models inside. It also flags CVEs that come from the base image, as described in Base Image Detection.
| Format | Source Scanning | Binary Scanning |
|---|---|---|
| Docker | Not applicable | |
| OCI | Not applicable |
For more information, see Docker / OCI.
Helm Charts
Xray scans a chart by scanning the container images it deploys. Xray never scans the chart's own files, such as templates and values.
| Chart Type | Source Scanning | Binary Scanning |
|---|---|---|
| Helm | Not applicable | |
| Helm OCI | Not applicable |
You must store those images in Artifactory. Xray skips any image it can't find there, so the chart shows findings only for the images it scanned.
For more information, see Helm and Helm OCI.
ML Models
Xray scans ML models you store in Artifactory, whether they sit in an ML repository, a Generic repository, or inside a container image. What Xray reports depends on where the model came from.
| Model | Identification | Licenses | Malicious Model Detection |
|---|---|---|---|
| Hugging Face | |||
| All other models |
Models don't carry CVEs, so Xray reports no vulnerabilities for them.
Xray identifies models saved as bin, ckpt, dill, flax, ggml, gguf, h5, hdf5, joblib, keras, mpk, msgpack, nemo, npy, npz, onnx, pb, pdparams, pkl, pt, pth, safetensors, tflite, and zip.
For more information, see ML Models and Malicious Package Detection.
Infrastructure as Code
The following table shows platform scanning coverage for infrastructure as code.
| Type | Binary Scanning | Details |
|---|---|---|
| Terraform state | State files in Terraform Backend repositories, for provider licenses. |
Terraform misconfiguration scanning requires JFrog Advanced Security. For more information, see Advanced Security Supported Technologies.
SBOM Formats
Xray reads and generates these software bill of materials (SBOM) formats. You can import an SBOM for scanning, or export an SBOM from scan results.
| Format | Versions | File Types |
|---|---|---|
| CycloneDX | 1.3 to 1.7 | JSON and XML |
| SPDX | 2 | JSON |
Archives in Generic Repositories
In Generic repositories, Xray unpacks these archives and scans what's inside.
| Type | Supported Formats |
|---|---|
| Archive types | 7z, zip, tar, vmdk, ova, cpio, iso, rar, aar, qcow2 |
| Compression types | gz, xz, bz2, zstd, lzma |
Operating System Images
Xray scans an OS image only when its archive format, boot sector, and filesystem are all supported.
| Component | Supported Formats |
|---|---|
| Archives | img, iso, vmdk, ova, cpio, qcow2 |
| Boot sectors | GPT and MBR. LVM isn't supported. |
| Filesystems | EXT4, NTFS, SquashFS, and XFS. EXT3 is supported from Xray 3.149.0. |
Related Topics
Updated 1 day ago
