Code Monkey home page Code Monkey logo

jfrog-apps-config's Introduction

JFrog Applications Config

The JFrog Applications Config schema is used to define the configuration schema used by some for the JFrog applications, such as JFrog CLI, JFrog Frogbot and the JFrog IDE integrations. This configuration schema is used to define the rules and settings for the JFrog source code scanning tools.

By consolidating the relevant settings, rules and policies into a single file, developers and security teams can easily manage and update scanning configurations, ensuring consistent and effective code analysis.

Project status

Scanned by Frogbot Test Static Analysis

Schema:

# [Required] JFrog Applications Config version
version: "1.0"

modules:
  # [Required] Module name
  - name: FrogLeapApp
    # [Optional, default: "."] Application's root directory
    source_root: "src"
    # [Optional] Directories to exclude from scanning across all scanners
    exclude_patterns:
      - "docs/"
    # [Optional] Scanners to exclude from JFrog Advanced Security (Options: "secrets", "sast", "iac")
    exclude_scanners:
      - secrets
    # [Optional] Customize scanner configurations
    scanners:
      # [Optional] Configuration for Static Application Security Testing (SAST)
      sast:
        # [Optional] Specify the programming language for SAST
        language: java
        # [Optional] Working directories specific to SAST (Relative to source_root)
        working_dirs:
          - "dir1"
          - "dir2"
        # [Optional] Additional exclude patterns for this scanner
        exclude_patterns:
          - "dir1/test/**"
        # [Optional] List of specific scan rules to exclude from the scan
        excluded_rules:
          - xss-injection

      # [Optional] Configuration for secrets scan
      secrets:
        # [Optional] Working directories specific to the secret scanner (Relative to source_root)
        working_dirs:
          - "dir1"
          - "dir2"
        # [Optional] Additional exclude patterns for this scanner
        exclude_patterns:
          - "dir1/test/**"

      # [Optional] Configuration for Infrastructure as Code scan (IaC)
      iac:
        # [Optional] Working directories specific to IaC (Relative to source_root)
        working_dirs:
          - "dir1"
          - "dir2"
        # [Optional] Additional exclude patterns for this Scanner
        exclude_patterns:
          - "dir1/test/**"

jfrog-apps-config's People

Contributors

yahavi avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar

Forkers

yahavi

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.