JFrog Xray integration
Triage JFrog Xray artifact vulnerabilities based on exploitability in your environment.
Integration details
Primary category
Software Composition Analysis
Sync direction
JFrog Xray ↔ Konvu
Findings are ingested from JFrog Xray into Konvu. What Konvu writes back to JFrog Xray depends on the integration.
Status
Coming soon
What is JFrog Xray?
JFrog Xray scans artifacts and dependencies stored in Artifactory for security vulnerabilities, license compliance issues, and operational risks across the software supply chain.
Why connect JFrog Xray to Konvu
- Determine which Xray-flagged vulnerabilities in artifacts are exploitable when deployed versus sitting in storage.
- Prioritize remediation for components that Xray surfaces across multiple artifacts based on actual risk.
- Sync triage decisions back to Xray to prevent blocking builds for accepted risks.
How it works
Scan
JFrog Xray produces findings from scans or assessments.
Ingest & enrich
Konvu ingests those findings and enriches them with code, configuration, and deployment context.
Assess exploitability
Konvu determines exploitability and recommended action with evidence attached.
Record decisions
Konvu records each verdict with its evidence. What it can write back to JFrog Xray depends on the integration.
Quick setup
When JFrog Xray is available, you’ll configure it from the integrations list in Konvu.
- 1Go to /configuration/integrations in Konvu and choose JFrog Xray.
- 2Authorize access and confirm the data sources you want to sync.
- 3Save the configuration to start syncing.
Sync direction
JFrog Xray ↔ Konvu
Findings are ingested from JFrog Xray into Konvu. What Konvu writes back to JFrog Xray depends on the integration.
Join the waitlist
We’ll let you know when the JFrog Xray integration is ready. Leave your email to get updates.
More integrations
View allArnica
Add exploitability verdicts with evidence to Arnica SCA and SAST findings, and send approved SCA dismissals back to Arnica.
- SCA
- SAST
- ASPM
Black Duck
Get an exploitability verdict with evidence for Black Duck Polaris SCA findings and Coverity SAST findings.
- SCA
- SAST
Checkmarx
Send Checkmarx One SCA and SAST results to Konvu for an exploitability verdict with evidence, through the Konvu API or a report upload.
- SAST
- SCA
Dependabot
Get an exploitability verdict for each Dependabot alert, and dismiss the false positives in GitHub with the evidence linked.
- SCA
Endor Labs
Add an exploitability verdict with evidence to Endor Labs SCA findings, on top of Endor's own reachability.
- SCA
GitHub
Prioritize GitHub CodeQL and Dependabot alerts by adding exploit context to each finding.
- SAST
- SCA
- Ticketing & Messaging