sha256:44fc4c93acae623dbcd6c2191221fb6f4830cce3058b4826462e68f6fc2be871
Last pushed
9 days by cdupuis
Type
Sandbox Kit
Manifest digest
sha256:44fc4c93acae623dbcd6c2191221fb6f4830cce3058b4826462e68f6fc2be871
schemaVersion: "3"
displayName: JFrog Xray
description: Installs the JFrog CLI (jf), pre-wired to your JFrog Platform, so agents can run Xray security & license scans (jf audit / jf scan / jf docker scan) against dependencies, binaries, and container images. Xray is a core component of the JFrog Platform and shares package metadata with Artifactory, so a scan reports not just a CVE but its full impact path through your dependency graph.
sourceUrl: https://github.com/jfrog/jfrog-cli
version: 2.121.0
licenses:
- Apache-2.0
kind: mixin
provides:
- [email protected]
capabilities:
- type: com.docker.sandbox/network-policy@1
config:
runtime:
allow:
- ${{ kit.args.jfrog_host }}
- type: com.docker.sandbox/credential@1
config:
apiKey:
inject:
- domain: ${{ kit.args.jfrog_host }}
scheme: bearer
name: JF_ACCESS_TOKEN
proxyManaged: true
phase: runtime
service: jfrog
description: JFrog Platform access token (needs Xray read + scan scopes). Stored on the host; the sandbox only ever sees a placeholder, and the proxy injects the real value on outbound requests to your JFrog host.
- type: com.docker.sandbox/agent-context@1
config:
contentFile: /usr/share/sandbox/kit/jfrog-xray/jfrog-xray-context.md
args:
jfrog_host:
default: your-company.jfrog.io
description: Your JFrog Platform host, e.g. mycompany.jfrog.io (SaaS) or artifactory.internal.example.com (self-hosted). Hostname only - no scheme, no path, no port. Defaults to a placeholder; set it or scans have no host to reach.
pattern: ^[a-z0-9]([a-z0-9.-]{0,251}[a-z0-9])?$
env: JFROG_HOST
version:
default: 2.121.0
description: JFrog CLI release carried by the overlay
pattern: ^[0-9]+\.[0-9]+\.[0-9]+$
buildArg: JF_VERSION