sha256:44fc4c93acae623dbcd6c2191221fb6f4830cce3058b4826462e68f6fc2be871
Last pushed
9 days by cdupuis
Type
Sandbox Kit
Manifest digest
sha256:44fc4c93acae623dbcd6c2191221fb6f4830cce3058b4826462e68f6fc2be871
Installs the JFrog CLI (jf), pre-wired to your JFrog Platform, so agents can run Xray security & license scans (jf audit / jf scan / jf docker scan) against dependencies, binaries, and container images. Xray is a core component of the JFrog Platform and shares package metadata with Artifactory, so a scan reports not just a CVE but its full impact path through your dependency graph.
| Name | Required | Default | Description |
|---|---|---|---|
jfrog_host | Optional | your-company.jfrog.io | Your JFrog Platform host, e.g. mycompany.jfrog.io (SaaS) or artifactory.internal.example.com (self-hosted). Hostname only - no scheme, no path, no port. Defaults to a placeholder; set it or scans have no host to reach. |
version | Optional | 2.121.0 | JFrog CLI release carried by the overlay |
[email protected]| Type | Required | Description | |
|---|---|---|---|
com.docker.sandbox/network-policy@1 | Required | — | |
com.docker.sandbox/credential@1 | Required | JFrog Platform access token (needs Xray read + scan scopes). Stored on the host; the sandbox only ever sees a placeholder, and the proxy injects the real value on outbound requests to your JFrog host. | |
com.docker.sandbox/agent-context@1 | Required | — | |
sbx run <agent> --kit docker/sbx-kit-jfrog-xray:2.121.0Run the following command to install sbx on your machine.
brew install docker/tap/sbxwinget install Docker.sbx