jfrog / jfrog/jfrog-cli-security

Xray link is not customizable

Open
#442 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

bug
Dominant language
Go
Stars
13
Forks
50
Avg merge
3d 48m
Merged PRs (30d)
26

Description

Describe the bug
When using AWS private link, the Xray link after the scan step will not be encrypted with the private link but will be displayed as the public link.

To Reproduce
Make sure to use AWS private link for JFrog Platform and add the Artifactory Plugin to Jenkins .
Perform a CI/CD job which includes Xray scan.

Expected behavior
Xray URL should be displayed with the AWS private link such as Artifactory.

Versions

  • Jenkins Artifactory plugin version: 3.17.3
  • Jenkins: 2.346.2
  • Jenkins operating system: NA
  • Artifactory Version: 7.47.12

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Begin by reproducing the Xray link behavior with an AWS private link and the listed plugin and platform versions. Trace where the post-scan Xray URL is produced, then verify that the displayed URL uses the private link rather than the public endpoint. No file or test location is named, so repository exploration will be required.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws, go
Domain
cloud, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.