You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A discussion dedicated to the JFrog (Token) module. Share your thoughts, questions, and feedback here.
Module Scorecard
Presentation & Onboarding
Credential Hygiene
Restricted-Environment Readiness
Engineering Quality
Overall
17 / 17
8 / 20
11 / 20
10 / 10
69 / 100
Drilldown
Presentation & Onboarding — 17 / 17
Criterion
Max
Score
Notes
Configuration-mode examples
12
12
README documents full mode (default), token-only mode (install_jfrog_cli = false, configure_jfrog_cli = false), pre-installed binary mode (install_jfrog_cli = false only), package-manager-only mode, code-server extension mode, and custom token description. Each has a complete Terraform example with sensible defaults.
Visual preview
5
5
README embeds ; file verified to exist at 56.0 KB.
Credential Hygiene — 8 / 20
Criterion
Max
Score
Notes
Secrets marked sensitive
16
8
The access_token output is marked sensitive = true, and README examples use var.artifactory_access_token (no inline secrets). However, the input variable artifactory_access_token in main.tf is not marked sensitive = true, failing the "sensitive inputs" half of the criterion.
Non-hardcoded auth path
4
0
No documented path avoids providing a raw admin access token. The module creates a scoped token via the Artifactory provider, but the user must still supply an admin-level token as a variable. No ServiceAccount, IAM/OAuth, API key helper, or AI Gateway path is documented.
Restricted-Environment Readiness — 11 / 20
Criterion
Max
Score
Notes
Mirrorable artifact source
5
0
The JF CLI install URL https://install-cli.jfrog.io is hardcoded in run.sh (curl -fL https://install-cli.jfrog.io | sudo sh). No module input variable overrides this download URL.
Bring-your-own binary
10
10
install_jfrog_cli = false disables download entirely. README explicitly documents: "To configure a pre-installed jf binary, set only install_jfrog_cli = false and leave configure_jfrog_cli enabled. The module fails with a clear error if jf is required but unavailable." The script also checks command -v jf before installing.
Egress transparency
3
0
No dedicated README section enumerates external endpoints (install-cli.jfrog.io, the JFrog instance URL, open-vsx.org for the code-server extension). No air-gapped or restricted-network guidance is provided.
Runs without sudo
2
1
run.sh invokes sudo sh and sudo chmod 755 /usr/local/bin/jf during CLI install. However, install_jfrog_cli = false provides a documented no-sudo fallback (pre-installed binary), and the module remains fully functional in token-only or pre-installed modes.
Engineering Quality — 10 / 10
Criterion
Max
Score
Notes
Input quality
6
6
All 14 variables have clear descriptions. Sensible defaults on all optional inputs. validation blocks on jfrog_url (URL regex) and username_field (enum regex). package_managers has a detailed multi-line description with examples.
Test coverage
4
4
jfrog-token.tftest.hcl covers business-logic mode selection (default, token-only, package-manager-only). main.test.ts provides end-to-end tests for all six package managers (npm, pypi, docker, go, conda, maven), error handling for missing CLI, and uses a local fake JFrog server to avoid remote calls.
Overall — 69 / 100
Raw 46 / 67 → round(46 / 67 × 100) = 69
Scored against SCORECARD.md on 2026-09-28 with solstice-1.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
A discussion dedicated to the JFrog (Token) module. Share your thoughts, questions, and feedback here.
Module Scorecard
Drilldown
Presentation & Onboarding — 17 / 17
install_jfrog_cli = false,configure_jfrog_cli = false), pre-installed binary mode (install_jfrog_cli = falseonly), package-manager-only mode, code-server extension mode, and custom token description. Each has a complete Terraform example with sensible defaults.; file verified to exist at 56.0 KB.Credential Hygiene — 8 / 20
access_tokenoutput is markedsensitive = true, and README examples usevar.artifactory_access_token(no inline secrets). However, the input variableartifactory_access_tokeninmain.tfis not markedsensitive = true, failing the "sensitive inputs" half of the criterion.Restricted-Environment Readiness — 11 / 20
https://install-cli.jfrog.iois hardcoded inrun.sh(curl -fL https://install-cli.jfrog.io | sudo sh). No module input variable overrides this download URL.install_jfrog_cli = falsedisables download entirely. README explicitly documents: "To configure a pre-installedjfbinary, set onlyinstall_jfrog_cli = falseand leaveconfigure_jfrog_clienabled. The module fails with a clear error ifjfis required but unavailable." The script also checkscommand -v jfbefore installing.run.shinvokessudo shandsudo chmod 755 /usr/local/bin/jfduring CLI install. However,install_jfrog_cli = falseprovides a documented no-sudo fallback (pre-installed binary), and the module remains fully functional in token-only or pre-installed modes.Engineering Quality — 10 / 10
validationblocks onjfrog_url(URL regex) andusername_field(enum regex).package_managershas a detailed multi-line description with examples.jfrog-token.tftest.hclcovers business-logic mode selection (default, token-only, package-manager-only).main.test.tsprovides end-to-end tests for all six package managers (npm, pypi, docker, go, conda, maven), error handling for missing CLI, and uses a local fake JFrog server to avoid remote calls.Overall — 69 / 100
Raw 46 / 67 → round(46 / 67 × 100) = 69
Scored against SCORECARD.md on 2026-09-28 with
solstice-1.All reactions