> Integration > Gradle XRay

JFrog +

gradle repository
JFrog offers an end-to-end solution covering the full lifecycle of your Gradle packages to manage development, vulnerability analysis, artifact flow control and distribution. Through the Gradle Artifactory Plugin Artifactory also provides tight integration with the Gradle build tool so you can resolve artifacts from and deploy builds to Artifactory.

WHAT XRAY AND GRADLE INTEGRATION MEANS TO YOU

Deep Recursive Scan Through All Layers of a Gradle Package

Impact Analysis

JFROG
ARTIFACTORY

gradle repository

Continuous Analysis

Fully Integrated with Your CI/CD Pipeline

Protection From Developer Fingertips to Production

Deep Recursive Scan Through All Layers of a Gradle Package

Xray recursively peels away the different layers of your Gradle packages and their dependencies ensuring that every software artifact that is included in your software has been scanned for issues and vulnerabilities.

Impact Analysis

When a vulnerability is detected, Xray shows you all the Gradle packages that contain the infected artifact so you can instantly understand the impact that any vulnerable layer has on all packages in your system.

Continuous Analysis

Even when packages uploaded to your Gradle repositories in Artifactory are given a clean bill of health, Xray continues to scan them to make sure they are not infected with any new vulnerabilities that are registered with Xray’s global vulnerability database.

Fully Integrated with Your CI/CD Pipeline

Through Xray’s integration with common CI servers, you can stop infected builds from ever getting to your repositories. During the build process, Xray will notify your CI server if an infected artifact is being included in your Gradle packages so the build can be halted before completion.

Protection From Developer Fingertips to Production

Using the JFrog IDEA Plugin, Xray scans Gradle projects right in the developer's IDE providing information on Gradle components and their dependencies. This allows the developer to make an informed decision on whether to use a component or not before it gets entrenched in the organization's product. Then, during CI/CD, Xray can stop builds that include infected components, and in production, Xray continuously scans production systems for any new issues and vulnerabilities that have been discovered. Effectively, Xray covers the full lifecycle of components in the software supply chain.

Release Fast Or Die