Xray Integration

General Information

JFrog Xray works with JFrog Artifactory to perform universal analysis of binary software components at any stage of the application lifecycle. 

The Mend Xray integration is a vulnerability feed that can be easily integrated with your Xray account.

In order to integrate Mend with JFrog Xray, simply add your WhitesSource organization API key to your Xray configuration.

Your organization API key is available on the Integrate tab of your Mend account, under Integration.

Setting Up the Mend Integration

  1. Login to JFrog Xray with administrator permissions. From the main menu, select Admin > Configuration > Integrations.

  2. The integration pop-up window appears. Select the Mend icon from the integration list, and enter the Mend API key in the API Token field.


    The test URL is https://saas.Mendsoftware.com/xray/api/checkauth or in Azure EU https://app-eu.Mendsoftware.com/xray/api/checkauth

The URL for an on-premises deployment is the on-premises installation URL.

Testing & Saving the Integration

  1. Click the Test button to validate that the integration is configured properly. A confirmation message should appear indicating that the API key is valid.

     

  2. Click Save.

Viewing Security Vulnerabilities

Once integrated, Xray starts pulling data from Mend based on your watches (rules).

Mend provides all relevant information about security vulnerabilities (severity, impacted versions and actionable remediation suggestions), and known severe software bugs for each of the displayed open source components. To view vulnerabilities: 

  1. Go to the Security tab of a specific package as displayed in the following screenshot:

     

  2. Select a specific component in order to view details on the security vulnerability.

Copyright © 2024 Mend.io (White Source Ltd.) | All rights reserved.