JFrog
JFrog stores the artifacts you actually deploy and the vulnerability findings attached to them. Antimetal reads both to verify what shipped and whether it carried a known issue.
What Antimetal does with JFrog
- Inspect Artifactory repositories and artifacts
- Read build info to trace exactly what was shipped
- Read Xray vulnerability findings for a component
- Verify which artifact version is running in production
Connecting JFrog
Go to Integrations in the Antimetal dashboard and find JFrog.
Click Connect and follow the prompt. Depending on the tool this is either an OAuth handoff or a read-only credential you generate in JFrog and paste into Antimetal.
Once JFrog shows as connected, Antimetal begins pulling from it during investigations. No further configuration is required.
Permissions and access
Antimetal connects over MCP with read-only access and performs no write operations. The exact scopes depend on the credential you issue in the vendor tool — grant read access only.
All tenant data is processed in isolated environments. See security and compliance for details.
Need help?
Contact us via Slack or at support@antimetal.com.