{"repo":"jfrog/frogbot","free":true,"listed":false,"github":"https://github.com/jfrog/frogbot","clone":"git clone https://github.com/jfrog/frogbot.git","description":"🐸 Scans your Git repository with JFrog Xray & JFrog advanced security for security vulnerabilities. 🤖","language":"Go","stars":369,"topics":["jfrog","jfrog-xray","artifactory","bot","action","npm","maven","gradle","python","go"],"license":"Apache-2.0","category":"security-tools","readme_excerpt":"JFrog Frogbot Branch Status :------: :------: main v2 main (maintenance only) ⚠️ Frogbot V2 — Maintenance Only: V2 ( v2 main branch) is in sunset mode. It is not accepting new features or general contributions — only critical bug and security fixes until its official end-of-life. All active development happens on main (V3). See CONTRIBUTING.md for details. 🤖 About JFrog Frogbot Overview JFrog Frogbot is a Git bot that scans your Git repositories for security vulnerabilities. 1. It scans pull requests immediately after they are opened but before they are merged. This process notifies you if the pull request is about to introduce new vulnerabilities to your code. This unique capability ensures the code is scanned and can be fixed even before vulnerabilities are introduced into the codebase. 2. It scans the Git repository periodically and creates pull requests with fixes for detected vulnerabilities. Why use JFrog Frogbot? - Software Composition Analysis (SCA) : Scan your project dependencies for security issues. For selected security issues, get leverage-enhanced CVE data from our JFrog Security Research team. Frogbot uses JFrog's vast vulnerabilities database, to which we continuously add new component vulnerability data. - Validate Dependency Licenses : Ensure that the licenses for the project's dependencies are in compliance with a predefined list of approved licenses. - Static Application Security Testing (SAST) : Provides fast and accurate security-focused engines that de","default_branch":null,"files":null,"tree":[],"storefront":"/r/jfrog","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/jfrog/frogbot/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}