SAST, CVEs Contextual Analysis, and Secrets Detection
Info
*Supported inside a Docker image.
Programming Language | Source code SAST (1st party code) | Source code CVEs Contextual Analysis | Binary CVEs Contextual Analysis | Secrets Detection |
---|---|---|---|---|
Go | ✅ | ✅ | ✅* | ✅ |
Java | ✅ | ✅ | ✅* ✅ Maven and Gradle repositories | ✅ |
Kotlin | ✅* | ✅ | ||
JavaScript | ✅ | ✅ | ✅* | ✅ |
TypeScript | ✅ | ✅ | ✅* | ✅ |
C# .NET | ✅ | ✅ | ✅* | ✅ |
Python | ✅ | ✅ | ✅* | ✅ |
C/C++ | ✅ | ✅* | ✅ | |
Rust | ✅* | ✅ | ||
Docker | ✅ | ✅ | ||
Terraform (See Infrastructure as code below) | ✅ | ✅ |
Misconfigurations
- Infrastructure as code (IaC)
- Terraform modules - Supported in JFrog IDE Plugins and JFrog CLI
- Terraform plan files - Supported in JFrog CLI
- Terraform state files - Supported in JFrog Artifactory (Terraform BE Repository)
- Applications and Services misconfigurations:
- Supported in JFrog Artifactory for Container images