Understanding and Analyzing Xray Scan Results

Learn how to read Xray scan results and act on vulnerabilities and licenses.

Overview

JFrog Xray scans your artifacts, builds, and Release Bundles for vulnerabilities, license compliance issues, and Operational Risk. After Xray completes a scan, it provides a detailed report with identified issues, their severity, affected components, and possible remediation steps.

This guide will help you navigate, interpret, and act upon scan results effectively.

Find Xray Scan Results

Xray scan results are available for Git repositories, repositories, builds, Release Bundles, and packages.

To find Xray scan results:

  1. Navigate to Application > Xray > Scan List.
  2. Select the resource type.
  3. Click the resource.
  4. Select the version you want to analyze.

Understanding Xray Scan Results

1. Scan Summary

The Xray Scan Dashboard provides a high-level summary of issues found in the scanned entity. It includes:

  • General scan data: The last scan date and downloads.
  • Vulnerabilities by severity: Critical, High, Medium, and Low.
  • Policy violations by severity: Critical, High, Medium, and Low.
  • Policy violation types: Security, license, or operational risk.
  • Software bill of materials (SBOM) details: The most common package types and the most common licenses.
  • Validated runtime risks: Detected CVEs, Critical and Applicable CVEs, malicious packages, and integrity violations.

2. Policy Violations Tab

This tab displays all detected violations that affect your scanned resource. For more information, see Policy and Governance.

Examples of recommended actions:

  • You can upgrade the component to the suggested fix version when a fix is available for a security violation.
  • You can request an ignore rule with an expiration date from the security team when a violation is failing your build and you need a grace period. For more information, see Ignoring Violations in JFrog Xray: Understanding Ignore Rules.
  • You can request an ignore rule from the security team for a false positive.

3. SBOM Tab

This tab provides a list of components and licenses associated with the scanned resource. It identifies the components, their versions, their licenses, and operational risk data.

Examples of recommended actions:

  • Identify a risky component in your resource.
  • Obtain legal approval or find an alternative package for a restricted license.
  • Confirm that the package includes a valid license declaration when a license is missing.
  • Identify which component is end-of-life and review other operational risk information.

4. Security Issues Tab for Vulnerabilities and Malicious Packages

The Vulnerabilities section displays detected vulnerabilities that affect the scanned resource, including additional information on each vulnerability.

Vulnerabilities listed in the Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) Catalog display a red icon in the Metadata column. Open a vulnerability to view the CISA KEV badge. Open the Public Sources tab to view the Date Added and Due Date when this information is available.

Examples of recommended actions:

  • Upgrade the component to the suggested fix version when a fix is available.
  • Use the enriched data provided by the JFrog Research Team to understand the exploitability of the vulnerability. For more information, see JFrog Security Research.
  • Check which component version is vulnerable and what the vulnerable path is.

5. Remediation Tab

This tab appears in the vulnerability details pane. It groups remediations as Direct, Base Image, Transitive, and JFrog Research Suggestion, and offers the Best Version, Least Vulnerable, and Quickest Fix strategies.

To open a fix pull request from the Remediation tab:

  1. Select a strategy.
  2. Expand Direct or Base Image.
  3. Click Create Pull Request.

For more information, see Create Fix Pull Requests with Auto-PR.

Filter and Sort Scan Results

Xray provides filters to help narrow down scan results for better prioritization.

1. Filter by Severity

  • Critical and High: Prioritize immediate remediation.
  • Medium and Low: Monitor these findings without blocking deployment.

2. Filter by Component Name

Search for vulnerabilities that affect a specific package, for example log4j.

3. Filter by Policy Violations

  • Show only vulnerabilities that violate predefined security policies.

Take Action on Scan Results

You can fix vulnerabilities, handle license issues, and export scan reports.

Fix Vulnerabilities

You can reduce risk from vulnerabilities found in a scan.

To fix vulnerabilities:

  • Upgrade the vulnerable dependency when a fix is available.
  • Apply a security patch when an upgrade isn't feasible.
  • Request an exception for a false positive or a justified risk.

Handle License Issues

You can address license findings in the scan result.

To handle license issues:

  • Replace a restricted license with a compliant alternative.
  • Obtain legal approval when a specific case requires it.

Export and Share Reports

You can export a scan report and share it with the teams that assess risk.

To export a scan report:

  • Click Export Report.
  • Select CSV, JSON, or PDF.

You can share the report with security, DevOps, and compliance teams. For more information, see Export Scan Results.

Related Topics


Did this page help you?