Xray 3.71.6

Xray Release Information

Products
JFrog Xray
ft:sourceType
Paligo

Released: April 16, 2023

Note

RabbitMQ Version Upgrade

Xray version 3.71.x includes RabbitMQ version 3.11.13. Before upgrading to this version of Xray, some feature flags need to be enabled in RabbitMQ. For more information, see Upgrading from Upgrading from Xray Version 3.x to 3.xUpgrading from Xray Version 3.x to 3.x

Enhancements

AAR Packages Support

Xray now supports scanning AAR packages.

Support Zstandard (zstd) Compression

Added support for packages using zstd compression.

Resolved Issues

Jira

Description

XRAY-12478

Fixed an issue whereby, Ignored Violation URL sent as an email notification was broken.

XRAY-12354

Fixed an issue whereby, in some cases, when using the artifact summary API with multiple components, results were duplicated.

XRAY-15075

Fixed an issue whereby,  users with read permissions were not authorized to retrieve the details of the violation via the Get Violations REST API. Users can view details of violations only on resources they have read permissions for.

XRAY-13119

Fixed an issue whereby,  sha256 was missing from the SBOM report.

XRAY-15189

Fixed an issue whereby, when a Policy in a Project Watch was blocking unscanned artifacts on Any-Repository it resulted in blocking repositories in other Projects as well.

XRAY-15970

Fixed an issue whereby, defining a non-default Vhost of the rabbitMQ caused Xray to hang and stop processing requests. A new system.yaml parameter now allows the user to define a non-default Vhost of the rabbitMQ and make Xray aware of it. For more information, see Xray System YAML.Xray System YAML

XRAY-13757

Fixed an issue whereby, the Notify Deployer option for Policies for Builds was not working properly.

XRAY-10987

Fixed an issue whereby modifying a custom issue was not successful.

XRAY-12660

Fixed an issue whereby, in some cases, custom issues that were created by the Issues REST API were not editable.