Artifactory
Visualize JFrog Artifactory repository groups, code repositories, builds, keys, permissions, user groups, and users, and monitor changes through queries and alerts.
- Installation
- Data Model
- Types
- Release Notes
Installation
For this integration, JupiterOne requires the namespace of your Artifactory account. It also requires are a Client Access Token, Client Pipeline Access Token, and the Client Administrator Name that granted the access tokens.
Configuration in Artifactory
Configure API access tokens in Artifactory using the instructions in the Access Tokens guide.
Required permissions
The integration reads platform-wide security and administration APIs, so the Client Access Token must be created with the applied-permissions/admin scope, or by a user holding Admin privileges. A token limited to a user's own permissions cannot read most of the endpoints below and its steps will fail with 403 Forbidden.
The token is used for these endpoints:
| Endpoint | Used for |
|---|---|
GET artifactory/api/system/ping | Connection check when the instance is saved |
GET artifactory/api/security/users and GET artifactory/api/security/users/{name} | Users |
GET artifactory/api/security/groups and GET artifactory/api/security/groups/{name} | Groups |
GET artifactory/api/security/token | Access tokens |
GET artifactory/api/repositories | Repositories |
POST artifactory/api/search/aql | Artifacts |
GET artifactory/api/v2/security/permissions and GET artifactory/api/v2/security/permissions/{name} | Permissions |
GET artifactory/api/build, GET artifactory/api/build/{name} and POST artifactory/api/search/buildArtifacts | Builds |
GET xray/api/v1/artifacts and POST xray/api/v1/summary/artifact | Vulnerabilities (requires JFrog Xray) |
The optional Client Pipeline Access Token is used only for GET pipelines/api/v1/pipelinesources, and only when Ingest Pipeline Information is enabled.
Network access
JupiterOne reaches your JFrog host over the public internet from its own egress addresses. If a reverse proxy, WAF, CDN, IP allowlist or edge rate limiter sits in front of the host, it can reject JupiterOne's requests with 403 Forbidden before they ever reach Artifactory — which looks like a permissions problem but is not one.
A rejection from the edge is recognisable in two ways: the failures are intermittent or vary between jobs rather than always affecting the same endpoints, and the error page is HTML from the proxy rather than Artifactory's own JSON error. When the integration sees an HTML error page where an API error belongs, the job error says so and points at a proxy as the likely cause. In that case, allowlist JupiterOne's egress addresses or exempt the JFrog API paths from the blocking rule; changing the token will not help.
Data Volume Configuration
Control how much data is ingested from Artifactory to manage storage and processing.
Ingestion Windows (Time Ranges)
| Field | Description | Default | Options |
|---|---|---|---|
| Artifacts Ingestion Window | Ingest artifacts created within the last X days | 30 | 30, 60, 90, 365 |
How it affects data volume: A longer ingestion window retrieves more artifacts from Artifactory, increasing the number of artifact entities stored in JupiterOne.
Data Filtering Options
| Field | Type | Description | Default |
|---|---|---|---|
| Included Vulnerability Severities | Multi-select | Select vulnerability severities to ingest | Medium, High, Critical |
| Include Repository Artifacts | Array | Comma-separated list of repositories from which artifacts will be ingested. Excludes all others. | None (all repositories) |
How it affects data volume:
- Severity filtering reduces vulnerability entities by excluding low-severity findings. By default, only Medium, High, and Critical vulnerabilities are ingested.
- Repository filtering limits artifact ingestion to specified repositories, significantly reducing data when only specific repositories are needed.
Configuration in JupiterOne
To install the JFrog Artifactory integration in JupiterOne, navigate to the Integrations tab in JupiterOne and select Artifactory. Click New Instance to begin configuring your integration, providing the following:
-
Account Name used to identify the JFrog Artifactory account in JupiterOne. Ingested entities will have this value stored in
tag.AccountNamewhen theAccountNameoption is enabled. -
Description to assist in identifying the integration instance, if desired.
-
Polling Interval that you feel is sufficient for your monitoring needs. You may leave this as
DISABLEDand manually execute the integration. -
Client Namespace of your Artifactory account.
-
Client Access Token configured in your Artifactory account.
-
Client Pipeline Access Token configured in your Artifactory account.
-
Client Administrator Name, or username of the administrator who granted the Artifactory access tokens.
Click Create once all values are provided to finalize the integration.
Next steps
Now that your integration instance has been configured, it will begin running on the polling interval you provided, populating data within JupiterOne. Continue on to our Instance management guide to learn more about working with and editing integration instances.
Entities
The following entities are created:
| Resources | Entity _type | Entity _class |
|---|---|---|
| AccessToken | artifactory_access_token | Key, AccessKey, NHI |
| Account | artifactory_account | Account |
| ArtifactCodeModule | artifactory_artifact_codemodule | CodeModule |
| Build | artifactory_build | Configuration |
| Finding | artifactory_vulnerability_finding | Finding, Vulnerability |
| Group | artifactory_group | UserGroup |
| Permission | artifactory_permission | AccessPolicy |
| PipelineSource | artifactory_pipeline_source | CodeRepo |
| Repository | artifactory_repository | Repository |
| RepositoryGroup | artifactory_repository_group | Group |
| User | artifactory_user | User |
Relationships
The following relationships are created:
Source Entity _type | Relationship _class | Target Entity _type |
|---|---|---|
artifactory_access_token | ASSIGNED | artifactory_user |
artifactory_account | HAS | artifactory_group |
artifactory_account | HAS | artifactory_access_token |
artifactory_account | HAS | artifactory_user |
artifactory_account | HAS | artifactory_repository |
artifactory_account | HAS | artifactory_repository_group |
artifactory_account | HAS | artifactory_pipeline_source |
artifactory_artifact_codemodule | HAS | artifactory_vulnerability_finding |
artifactory_build | CREATED | artifactory_artifact_codemodule |
artifactory_group | HAS | artifactory_user |
artifactory_permission | ASSIGNED | artifactory_user |
artifactory_permission | ASSIGNED | artifactory_group |
artifactory_permission | ALLOWS | artifactory_repository |
artifactory_permission | ALLOWS | artifactory_build |
artifactory_permission | ALLOWS | artifactory_repository_group |
artifactory_repository | HAS | artifactory_artifact_codemodule |
Artifactory User
artifactory_user inherits from User
| Property | Type | Description | Specifications |
|---|---|---|---|
disableUIAccess | boolean | ||
internalPasswordDisable | boolean | ||
mfaStatus | boolean | ||
policyManager | boolean | ||
profileUpdatable | boolean | ||
realm | string | ||
reportsManager | boolean | ||
watchManager | boolean |
Artifactory Vulnerability Finding
artifactory_vulnerability_finding inherits from Finding, Vulnerability
Release Notes
- 2026-02-13 — Added TLS verification configuration options for Artifactory, supporting custom CA certificates and self-signed certificate environments.
- 2025-06-03 — Artifactory vulnerability findings now support both the Vulnerability and Weakness entity classes for improved data model compatibility.
- 2025-04-29 — Added configuration option to include artifacts from specific repositories in Artifactory ingestion.