Supply Chain Security
Get hands-on with contextualized, agent-ready scanning natively where your code and artifacts live and learn to block risk before it reaches production.
Get hands-on with contextualized, agent-ready scanning natively where your code and artifacts live and learn to block risk before it reaches production.
Prerequisite: Before diving in, you must complete the Essentials for Artifactory learning path. Because Xray relies entirely on Artifactory to house and manage the components it scans, a solid grasp of Artifactory basics is required.
Start here. If Xray is running but no policies are enforced, you're collecting vulnerability data with nothing acting on it. This section takes you from a bare Xray setup to a fully enforced pipeline: indexing configured, policies defined, watches attached, and developers who understand what they're looking at.
Recommended for: All roles new to JFrog Xray.
A policy without a watch does nothing — silently. A watch on the wrong repo leaves gaps. A fail-build gate with no grace period breaks every build on day one. This path closes those gaps in the right order, so your security posture is real — not just configured.
Designed for DevSecOps and Security Champions, this course automates compliance using JFrog Xray. You will create policies, generate SBOMs, integrate scanning, and use dedicated resources and tools to develop a comprehensive execution plan.
Test your knowledge of JFrog Xray concepts, policies, and scanning behavior. Take this after completing the Xray Foundation courses to confirm you're ready to move on.
Equip yourself with the skills to leverage Xray effectively in your software development lifecycle.
Xray scans what's already in your repositories. Curation decides what's allowed to arrive in the first place. Every time a developer runs npm install or pip install, packages enter your environment unchecked — Xray catches the problem after the fact. This section moves that enforcement to the perimeter, before the package ever touches your SDLC.
Note: Complete Xray Section before starting here.
Learn how to set up and roll out the JFrog Curation service in your platform to boost adoption and maximize efficiency.
Take your Curation service to the next levels of scale, adoption and efficiency.
This course we will introduce JFrog Curation and its value to the software developer, learn how to seamlessly integrate it into our development workflow and boosting productivity with quick resolutions to security vulnerabilities
Designed for DevSecOps and Security Champions, this course uses JFrog Curation to block malicious packages at the source. You will configure risk policies, manage waivers, and leverage dedicated resources and tools to develop a comprehensive execution plan.
If your team is chasing every Xray finding, most of that effort is wasted. The CVE is real. The severity score is real. But the code path that triggers it may never execute in your application. While developers remediate those false priorities, the vulnerabilities that actually matter stay open. This section reduces the noise with contextual analysis, secrets detection, SAST, and IaC scanning so your team acts on signal, not volume.
Note: Complete Xray sections before starting here.
Learn to use JFrog Advanced Security to achieve comprehensive vulnerability and compliance control across your entire software supply chain. This path covers key capabilities like contextual analysis, secret detection, and SAST, empowering security managers and DevSecOps engineers to mitigate risks
Designed for DevSecOps and Security Professionals, this intermediate course uses JFrog Advanced Security to eliminate alert fatigue. You will use Contextual Analysis to filter irrelevant risks, deploy scanners for secrets and IaC misconfigurations, and use dedicated resources and tools to build a comprehensive execution plan.
Complete the labs, enable your developers, and leverage our high-level execution plans for every security product.
Unlock your team's JFrog security expertise with a continuous stream of practical hands-on labs.
Empower your coding with JFrog security tools. This path teaches you to secure code instantly using the IDE Plugin and JFrog CLI. Master Frogbot for Git, learn SAST analysis, and apply Curation policies to prevent risky dependencies from entering your builds
A practical, step-by-step execution plan to guide you through implementing JFrog Curation in your environment.