Jfrog Artifactory
Jfrog Artifactory
Edition: Enterprise only and Self-Hosted and Hosted Scanner
The Artifactory integration scans artifacts stored in JFrog Artifactory repositories for credentials and other sensitive data.
Configuration
The Artifactory integration can be configured in TruffleHog under Integrations, or via a local configuration file (below).
Web configuration
Configure this integration from the Integrations page in TruffleHog. You'll need credentials appropriate to your Artifactory instance — see the local configuration section below for the supported authentication methods.
Local configuration
Local configuration supports two authentication methods:
- Access token — uses an Artifactory access token, recommended for a read-only service account.
- Basic auth — uses a username and password (or API key, or access token as the password).
Creating a read-only service account. Both auth methods work best with a dedicated read-only account:
- In Artifactory, navigate to Identity and Access and create a new user.
- Leave all roles unchecked. Ensure the user is added to the readers group (selected by default).
- After creating the user, open the Access Tokens tab and generate a token.
Access token
Basic auth
The password field accepts an access token, API key, or account password.
Scope with includePaths and ignorePaths
Path filters control which artifacts within a repository are scanned. The two fields combine as follows:
- includePaths only — only artifacts matching the include list are scanned.
- ignorePaths only — all artifacts are scanned except those matching the ignore list.
- Both specified — artifacts must match includePaths and must not match ignorePaths.
Paths should not include a repository qualifier. If example is the repository name and the directory to include is example/path/to/dir, the includePaths value should be path/to/dir/*.
Paths apply to all repositories in the configuration. To scope a path to a specific repository, configure a separate Artifactory source for that repository.
Configuration options
Field | Type | Required | Description |
|---|---|---|---|
endpoint | string | Yes | The URL for your Artifactory instance. |
repositories | list | No | Explicit list of Artifactory repositories to scan. Omit to enumerate instead. |
includePaths | list | No | Artifact paths to include in scans. Supports glob patterns (*). |
ignorePaths | list | No | Artifact paths to skip during scans. Supports glob patterns (*). |
Capabilities
Feature | Supported |
|---|---|
Scan artifacts | ✅ |
Scan archive files | ✅ |
Scan base64-encoded data | ✅ |
Scan binaries | ✅ |
Include / exclude filters | ✅ |
Auto-resume | ✅ |