-
JFrog Scan Results: Vulnerability deep-dives & exception management 0 hr 15 min
-
Share Your Feedback
JFrog Xray Scan Results: Vulnerability deep-dives and exception management
Course 5 of 7 in Getting Started with Xray Security
Understand what the security data actually means. This is your practical guide to interpreting deep vulnerability mechanics, assessing real-world exploitability, and managing pipeline exceptions responsibly.
About this course
Course Level: Intermediate
Requirements: Working knowledge of JFrog Xray, including confidence reading the Vulnerability Details panel and applying Ignore Rules. Familiarity with your organization's security policies, CI/CD pipelines, and the reporting obligations you owe to legal, security, and executive stakeholders.
Prerequisites: None. Completion of JFrog Xray Scan Results: Vulnerability deep-dives and exception management — or equivalent hands-on Xray experience — is strongly recommended, as this course builds directly on that triage foundation.
Course Description:
Passing a single scan is easy. Proving that your security posture is actually improving sprint over sprint — and containing a zero-day CVE across every repository, build, and container in your inventory before the news cycle turns over — is what separates a working DevSecOps practice from a checkbox one. And when auditors, legal, and executives all want the same data in a different shape, the wrong export format can stall a release just as fast as an unresolved CVE.
This course walks through the Xray workflows that close the loop: comparing versions to prove fixes landed, exporting the right report for the right audience, and running Impact Search the moment a zero-day breaks — so a discovery in the news becomes a scoped, communicated response within the hour.
Topics Covered:
- Version Comparisons: Use the Versions Diff view and the Versions Trend chart to prove remediation sprints actually reduced risk, catch regressions where a "-11 net change" hides a new critical CVE, and give leadership a defensible trajectory rather than a snapshot.
- Exporting and Reporting: Match the right export to the right audience — License Attribution Reports for legal and compliance, Scan Results (with or without Ignores) for security and DevOps, and SBOMs in SPDX or CycloneDX for auditors, regulators, and enterprise procurement toolchains.
- Zero-Day Response: Run Impact Search across Repositories, Builds, Release Bundles, Packages, and Git Repositories in a single query, turn the raw affected-resources list into a prioritised action list via Policy Violations, and communicate exposure to stakeholders with production impact, fix status, and action taken.
- Closing the Loop: Tie every workflow into the repeatable Scan → Filter → Fix → Compare → Share cycle so continuous security scales alongside your pipeline rather than lagging behind it.