Xray and JFrog External DB Sync
To provide accurate and up-to-date vulnerability intelligence, JFrog Xray continuously synchronizes with its JFrog global security database. This database contains:
- Known CVEs (Common Vulnerabilities and Exposures)
- Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) Catalog data
- Security research insights from JFrog
- Open-source software vulnerabilities
- License compliance data
Keeping Xray’s database synchronized ensures that scans detect the latest threats, allowing security teams to proactively address vulnerabilities in software artifacts.
Warning
From Xray 3.80, new self-hosted installations use DBSync v3 by default. Existing self-hosted installations that still run DBSync v1 continue to use v1 until you migrate. SaaS installations already use DBSync v3. DBSync v1 is deprecated. To keep receiving current threat intelligence, migrate self-hosted instances from DBSync v1 to v3. For the migration steps, see Migration Guide for Self-Hosted Customers: Upgrading from DBSync V1 to V3.
Database Synchronization Modes
Xray offers two modes of database synchronization, depending on your organization's connectivity and security requirements:
| Mode | Description | Best Use Case |
|---|---|---|
| Online Mode | Xray automatically syncs with JFrog’s security database at hourly intervals. | Organizations with internet access, requiring real-time updates. |
| Offline Mode | Xray syncs manually using downloaded data packages. | Air-gapped environments or restricted network access. |
Online Mode: Automatic Synchronization - Best Practice
By default, Xray operates in Online Mode, where it automatically fetches security updates from the JFrog global database.
How It Works
- Xray checks for updates hourly.
- The database is incrementally updated, ensuring minimal performance impact.
- No user intervention is required—Xray stays continuously up to date.
Refer to JFrog Security External Resources for the list of URLs that must be whitelisted
Offline Mode: Manual Synchronization
For air-gapped networks or organizations with restricted internet access, Xray supports Offline Mode.
How It Works
- Download the latest database update package from JFrog’s external source with JFrog CLI. For the command and options, see Xray Offline Database Sync. You can also copy the command from Administration → Xray Settings → Database Sync after you select Offline mode.
- Transfer the update package to the offline Xray instance.
- Apply the update using the Admin Panel.
Steps to Manually Sync in Offline Mode
Step 1: Download the Security Database Update via JFrog CLI
- Run
jf xr offline-updateto download the latest vulnerability database update package. - Ensure that your JFrog environment is authorized to access the update package.
Step 2: Transfer the Update to the Offline System
- Move the package to the Xray Server.
Step 3: Apply the Update to Xray
- Use the JFrog Platform UI to trigger the security database update.
- Verify that the synchronization was successful.
It is not recommended. It's recommended only for Enterprises with restricted internet access that require controlled updates.
The offline sync operation should be preformed frequently.
Verifying Database Synchronization
To check the current synchronization status:
- Navigate to Administration → Xray Settings → DB Sync.
- Verify the last update timestamp and check the last sync status.
Updated 24 days ago
