Supported Technologies

JFrog Security User Guide

ft:sourceType
Ftml

Software Packages

Programming LanguagePackageSCA Source code scanningSCA Binary scanning
GoGo
PHPPHP
JavaMaven

jar, war, ear, nupkg, sar, har, hpi, cpa, jpi, all archive types

JavaGradle

jar, war, ear, nupkg, sar, har, hpi, cpa, jpi, all archive types

JavaIvy
jar, war, ear, nupkg, sar, har, hpi, cpa, jpi, all archive types
ScalaSBT
jar, war, ear, nupkg, sar, har, hpi, cpa, jpi, all archive types
JavaScriptnpm
JavaScriptBower
JavaScriptpnpm
JavaScriptYARN
.NETNuGet
nupkg, all archive types
PythonPyPI
whl, egg, all archive types
PythonConda
RubyRubyGems
Objective-CCocoaPods
podspec
C/C++Conan
conanmanifest.txt
RustCargo
crate
RCRAN
All archive types
SwiftSwiftPM

OS Packages

PackageSCA Source code scanningSCA Binary scanning
DebianN/A
RPMN/A
AlpineN/A

Containers

PackageSCA Source code scanningSCA Binary scanning
Docker
OCI
Chainguard Images

ML Models

PackageSCA Source code scanningSCA Binary scanning
Hugging Face MLN/A
Machine Learning ModelN/A


bin, ckpt, dill, flax, ggml, gguf, h5, hdf5, joblib, keras, mpk, msgpack, nemo, npy, npz, onnx, pb, pdparams, pkl, pt, pth, safetensors, tflite, zip

Xray Identifies ML Model binaries in Generic repositories and inside Docker containers

SBOM only, no malicious package scanning

The following formats are supported - Flax, GGML, GGUF, Joblib, Keras H5, NeMo, NumPy Archive, NumPy Array, ONNX, PaddlePaddle, Pickle / Dill, PyTorch Archive, PyTorch state_dict, Safetensors, SavedModel, TFLite


Others

PackageSCA Source code scanningSCA Binary scanning
CycloneDX SBOM
cdx.json, cdx.xml
Terraform
Terraform Module, Terraform Plan

Terraform State

Archive Support in Generic Artifactory Repository

TypeSCA Source code scanningSCA Binary scanning
Supported Archive TypesN/A7z, zip, tar, vmdk, ova, cpio, iso, rar, aar
Supported Compression TypesN/Agz, xz, bz2, zstd, lzma

Notes:

  • Operational risk is supported for Maven and NPM