Sign inSign up

sbx/jfrog-xray:latest

Multi-platform
Manifest digest

sha256:e0044d3b9a3af07b24c43d926f9906e76c46ce72c5c894b904978a760ab4cb4d

Last pushed

40 minutes by sbx

Type

Sandbox Kit

Manifest digest

sha256:e0044d3b9a3af07b24c43d926f9906e76c46ce72c5c894b904978a760ab4cb4d

MIXIN

Installs the JFrog CLI (jf), pre-wired to your JFrog Platform, so agents can run Xray security & license scans (jf audit / jf scan / jf docker scan) against dependencies, binaries, and container images. Xray is a core component of the JFrog Platform and shares package metadata with Artifactory, so a scan reports not just a CVE but its full impact path through your dependency graph.


Arguments
NameRequiredDefaultDescription
jfrog_hostOptionalyour-company.jfrog.io

Your JFrog Platform host, e.g. mycompany.jfrog.io (SaaS) or artifactory.internal.example.com (self-hosted). Hostname only - no scheme, no path, no port. Defaults to a placeholder; set it or scans have no host to reach.

versionOptional2.121.0

JFrog CLI release carried by the overlay



CapabilitiesExpand a row to see its full configuration.
TypeRequiredDescription
com.docker.sandbox/network-policy@1Required—
com.docker.sandbox/credential@1RequiredJFrog Platform access token (needs Xray read + scan scopes). Stored on the host; the sandbox only ever sees a placeholder, and the proxy injects the real value on outbound requests to your JFrog host.
com.docker.sandbox/agent-context@1Required—

Apply this mixin to a sandbox

sbx run <agent> --kit sbx/jfrog-xray:latest

Make sure you have docker sbx installed

Run the following command to install sbx on your machine.

macOS
brew install docker/tap/sbx
Windows
winget install Docker.sbx
Learn more about docker sbx⁠