Practice Lab: JFrog Xray - Continuous Security Scanning [LAB-507]
Establish a robust security process for your software supply chain using JFrog Xray
This lab teaches you to establish a robust security process for your software supply chain using JFrog Xray. Get hands-on with configuring and managing Xray to continuously scan your artifacts for vulnerabilities and license compliance, protecting you from potential risks.
Course Level: Intermediate
Upon completing this lab, you'll be able to:
- Setting Up Repositories: Configure remote, virtual, and local repositories with Xray integration for comprehensive artifact scanning.
- Indexing Artifactory Resources: Index repositories in Xray via the UI, enabling continuous monitoring of your artifacts.
- Creating Xray Policies and Watches: Create and configure Xray security and license policies, and set up watches to monitor and enforce these policies across your repositories.
- Using Xray with APIs (Optional): Learn to create policies and watches using REST APIs for automated security management.
- Scanning Artifacts: Understand how to build and push Docker images to your repository, triggering security scans in Xray.
- Reviewing Scan Results: Navigate the Xray UI to view scan results, understand vulnerabilities and license violations, and take appropriate actions.
Requirements - To get the most out of this lab, you should have:
- A basic understanding of REST APIs and command-line operations.
- Familiarity with JFrog Artifactory's user interface (UI).
- Knowledge of artifact repositories and Docker.