JFrog

Compatible with IntelliJ IDEA (Ultimate, Community), Android Studio and 5 more
Screenshot 1
Screenshot 2

The plugin allows developers to find and fix security vulnerabilities in their projects and to see valuable information about the status of their code by continuously scanning it locally with the JFrog Platform.

Software Composition Analysis (SCA)

Scan your project dependencies for security issues. The plugin offers an automatic upgrade of the vulnerable dependencies to versions which include fixes.

CVE Research and Enrichment

For selected security issues, get leverage-enhanced CVE data that is provided by our JFrog Security Research team. Prioritize the CVEs based on:

  • JFrog Severity: The severity given by the JFrog Security Research team after the manual analysis of the CVE by the team. CVEs with the highest JFrog security severity are the most likely to be used by real-world attackers. This means that you should put effort into fixing them as soon as possible.
  • Research Summary: The summary that is based on JFrog's security analysis of the security issue provides detailed technical information on the specific conditions for the CVE to be applicable.
  • Remediation: Detailed fix and mitigation options for the CVEs.

Check out what our research team is up to and stay updated on newly discovered issues by clicking on this link: https://research.jfrog.com

Advanced Scans

Vulnerability Contextual Analysis: This feature uses the code context to eliminate false positive reports on vulnerable dependencies that are not applicable to the code. Vulnerability Contextual Analysis is currently supported for Python, JavaScript, and Java code.

Secrets Detection: Prevent the expose of keys or credentials that are stored in your source code.

Infrastructure as Code (IaC) Scans: Secure your IaC files. Critical to keeping your cloud deployment safe and secure.


Advanced Scans require Xray version 3.66.5 or above and Enterprise X / Enterprise+ subscription with Advanced DevSecOps.

For more information about the plugin see the README.

What’s New

For the latest release notes, please visit our Release Notes page.
Jan 29, 2025
Version 2.7.2

Getting Started

Once the plugin is successfully installed, connect the plugin to your JFrog Platform as follows:
1. Under Settings (Preferences) | Other Settings, click JFrog Global Configuration.
2. Set your JFrog platform URL and login credentials.
3. Test your connection to Xray and Artifactory using the Test connection button.

Rating & Reviews

4.9
10 Ratings (126,062 Downloads)
5
4
3
2
1

Bhupesh PAndey

23.07.2021

It drains the jetbrains memory out when the scan is running. Please provide a means by which I can use it scan the vunerabilities. It worked great though. I was impressed with the way it was listing out the issues with my dependencies.

0

Additional Information

Vendor:
JFrog(Trader)
Plugin ID:
org.jfrog.idea