Skip to main content

Artifactory

Visualize JFrog Artifactory repository groups, code repositories, builds, keys, permissions, user groups, and users, and monitor changes through queries and alerts.

Installation​

For this integration, JupiterOne requires the namespace of your Artifactory account. It also requires are a Client Access Token, Client Pipeline Access Token, and the Client Administrator Name that granted the access tokens.

Configuration in Artifactory​

Configure API access tokens in Artifactory using the instructions in the Access Tokens guide.

Required permissions​

The integration reads platform-wide security and administration APIs, so the Client Access Token must be created with the applied-permissions/admin scope, or by a user holding Admin privileges. A token limited to a user's own permissions cannot read most of the endpoints below and its steps will fail with 403 Forbidden.

The token is used for these endpoints:

EndpointUsed for
GET artifactory/api/system/pingConnection check when the instance is saved
GET artifactory/api/security/users and GET artifactory/api/security/users/{name}Users
GET artifactory/api/security/groups and GET artifactory/api/security/groups/{name}Groups
GET artifactory/api/security/tokenAccess tokens
GET artifactory/api/repositoriesRepositories
POST artifactory/api/search/aqlArtifacts
GET artifactory/api/v2/security/permissions and GET artifactory/api/v2/security/permissions/{name}Permissions
GET artifactory/api/build, GET artifactory/api/build/{name} and POST artifactory/api/search/buildArtifactsBuilds
GET xray/api/v1/artifacts and POST xray/api/v1/summary/artifactVulnerabilities (requires JFrog Xray)

The optional Client Pipeline Access Token is used only for GET pipelines/api/v1/pipelinesources, and only when Ingest Pipeline Information is enabled.

Network access​

JupiterOne reaches your JFrog host over the public internet from its own egress addresses. If a reverse proxy, WAF, CDN, IP allowlist or edge rate limiter sits in front of the host, it can reject JupiterOne's requests with 403 Forbidden before they ever reach Artifactory — which looks like a permissions problem but is not one.

A rejection from the edge is recognisable in two ways: the failures are intermittent or vary between jobs rather than always affecting the same endpoints, and the error page is HTML from the proxy rather than Artifactory's own JSON error. When the integration sees an HTML error page where an API error belongs, the job error says so and points at a proxy as the likely cause. In that case, allowlist JupiterOne's egress addresses or exempt the JFrog API paths from the blocking rule; changing the token will not help.

Data Volume Configuration​

Control how much data is ingested from Artifactory to manage storage and processing.

Ingestion Windows (Time Ranges)​

FieldDescriptionDefaultOptions
Artifacts Ingestion WindowIngest artifacts created within the last X days3030, 60, 90, 365

How it affects data volume: A longer ingestion window retrieves more artifacts from Artifactory, increasing the number of artifact entities stored in JupiterOne.

Data Filtering Options​

FieldTypeDescriptionDefault
Included Vulnerability SeveritiesMulti-selectSelect vulnerability severities to ingestMedium, High, Critical
Include Repository ArtifactsArrayComma-separated list of repositories from which artifacts will be ingested. Excludes all others.None (all repositories)

How it affects data volume:

  • Severity filtering reduces vulnerability entities by excluding low-severity findings. By default, only Medium, High, and Critical vulnerabilities are ingested.
  • Repository filtering limits artifact ingestion to specified repositories, significantly reducing data when only specific repositories are needed.

Configuration in JupiterOne​

To install the JFrog Artifactory integration in JupiterOne, navigate to the Integrations tab in JupiterOne and select Artifactory. Click New Instance to begin configuring your integration, providing the following:

  • Account Name used to identify the JFrog Artifactory account in JupiterOne. Ingested entities will have this value stored in tag.AccountName when the AccountName option is enabled.

  • Description to assist in identifying the integration instance, if desired.

  • Polling Interval that you feel is sufficient for your monitoring needs. You may leave this as DISABLED and manually execute the integration.

  • Client Namespace of your Artifactory account.

  • Client Access Token configured in your Artifactory account.

  • Client Pipeline Access Token configured in your Artifactory account.

  • Client Administrator Name, or username of the administrator who granted the Artifactory access tokens.

Click Create once all values are provided to finalize the integration.

Next steps​

Now that your integration instance has been configured, it will begin running on the polling interval you provided, populating data within JupiterOne. Continue on to our Instance management guide to learn more about working with and editing integration instances.