SAST, CVEs Contextual Analysis, and Secrets Detection
Info
* Supported inside a Docker image and via CLI using jf audit (includes npm contextual analysis).
| Programming Language | Source code SAST (1st party code) | Source code CVEs Contextual Analysis | Binary CVEs Contextual Analysis | Secrets Detection |
|---|---|---|---|---|
| Go | ✅ | ✅ | ✅* | ✅ |
| Java | ✅ | ✅ | ✅* ✅ Maven and Gradle repositories | ✅ |
| Kotlin | ✅* | ✅ | ||
| JavaScript | ✅ | ✅ | ✅* | ✅ |
| TypeScript | ✅ | ✅ | ✅* | ✅ |
| C# .NET | ✅ | ✅ | ✅* | ✅ |
| Python | ✅ | ✅ | ✅* | ✅ |
| C/C++ | ✅ | ✅* | ✅ | |
| Rust | ✅ | ✅* | ✅ | |
| Docker | ✅ | ✅ | ||
| Terraform (See Infrastructure as code below) | ✅ | ✅ |
Misconfigurations
- Infrastructure as code (IaC)
- Terraform modules - Supported in JFrog IDE Plugins and JFrog CLI
- Terraform plan files - Supported in JFrog CLI
- Terraform state files - Supported in JFrog Artifactory (Terraform BE Repository)
- Applications and Services misconfigurations:
- Supported in JFrog Artifactory for Container images