Sign inSign up

ajeetraina777/jfrog-xray-kit:0.1.2

Manifest digest

sha256:e7cade0b3762a17eb2aedc01ba2ae5be34238815a0d14e97a316240db536fe89

Last pushed

about 1 month by ajeetraina777

Type

Sandbox Kit

Manifest digest

sha256:e7cade0b3762a17eb2aedc01ba2ae5be34238815a0d14e97a316240db536fe89

MIXIN
REQUIRES SECRETS

Installs the JFrog CLI (jf), pre-wired to your JFrog Platform, so agents can run Xray security & license scans (jf audit / jf scan / jf docker scan) against dependencies, binaries, and container images. Xray is a core component of the JFrog Platform and shares package metadata with Artifactory, so a scan reports not just a CVE but its full impact path through your dependency graph.


Arguments
NameRequiredDefaultDescription
jfrog_hostRequired

Your JFrog Platform host, e.g. mycompany.jfrog.io (SaaS) or artifactory.internal.example.com (self-hosted). Hostname only — no scheme, no path, no port.


Credentials
NameServiceRequiredDescription
JF_ACCESS_TOKENjfrogRequiredJFrog Platform access token (needs Xray read + scan scopes). Stored on the host; the sandbox only ever sees a placeholder, and the proxy injects the real value on outbound requests to your JFrog host.

Network Egress

releases.jfrog.io

releases-cdn.jfrog.io

${{ kit.args.jfrog_host }}

Apply this mixin to a sandbox

sbx run <agent> --kit ajeetraina777/jfrog-xray-kit:0.1.2 --set jfrog_host=<jfrog_host>

Make sure you have docker sbx installed

Run the following command to install sbx on your machine.

macOS
brew install docker/tap/sbx
Windows
winget install Docker.sbx
Learn more about docker sbx