You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A discussion dedicated to the JFrog Xray module. Share your thoughts, questions, and feedback here.
Module Scorecard
Presentation & Onboarding
Credential Hygiene
Restricted-Environment Readiness
Engineering Quality
Overall
12 / 17
16 / 20
N/A
10 / 10
81 / 100
Drilldown
Presentation & Onboarding — 12 / 17
Criterion
Max
Score
Notes
Configuration-mode examples
12
12
Two major modes documented: local repository (default) and remote/proxy repository with use_cache_repo = true. Both have full README examples with sensible defaults. The repo and repo_path overrides are described in variable docs but lack dedicated README examples; however, they are minor overrides, not major modes.
Visual preview
5
0
No image, GIF, or video embedded in the README. The frontmatter icon field references an SVG file, which is a module icon, not a visual preview of the module in action.
Credential Hygiene — 16 / 20
Criterion
Max
Score
Notes
Secrets marked sensitive
16
16
xray_token is marked sensitive = true in main.tf. README examples use var.artifactory_access_token (a variable reference), not inline literal secrets. No hardcoded tokens in any example.
Non-hardcoded auth path
4
0
The only auth path documented is a JFrog access token passed as a variable. No alternative mechanism (OAuth, service account, API key helper, external auth) is mentioned in the README.
Restricted-Environment Readiness — N/A
All four criteria are N/A by construction. This module performs no downloads or installations; it exclusively calls the JFrog Xray REST API via the jfrog/xray Terraform provider data source. No scripts are executed.
Criterion
Max
Score
Notes
Mirrorable artifact source
5
N/A
Module downloads or installs nothing of its own. It only queries an external API endpoint supplied by the caller.
Bring-your-own binary
10
N/A
No binary is downloaded or installed.
Egress transparency
3
N/A
No install-time downloads. The sole external interaction is the caller-supplied xray_url API endpoint.
Runs without sudo
2
N/A
Module contains no scripts; it is purely Terraform configuration with a data source.
Engineering Quality — 10 / 10
Criterion
Max
Score
Notes
Input quality
6
6
All six variables have clear descriptions. xray_url has a regex validation, image has a structural validation (split check), xray_token is marked sensitive. Optional variables (repo, repo_path, use_cache_repo) have sensible defaults ("", "", false).
Test coverage
4
4
main.test.ts provides a clear testing story with three mock Xray servers (local repo, remote/cache repo, empty results). Tests cover: required-variable validation (3 tests), local-repo vulnerability counts, zero-count edge case, cache-repo SHA filtering logic, and custom repo/repo_path overrides. Business logic (image parsing, cache-repo filtering, tag-vs-SHA disambiguation) is well covered.
Overall — 81 / 100
Raw 38 / 47 → round(38 / 47 × 100) = 81
Scored against SCORECARD.md on 2026-09-28 with solstice-1.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
A discussion dedicated to the JFrog Xray module. Share your thoughts, questions, and feedback here.
Module Scorecard
Drilldown
Presentation & Onboarding — 12 / 17
use_cache_repo = true. Both have full README examples with sensible defaults. Therepoandrepo_pathoverrides are described in variable docs but lack dedicated README examples; however, they are minor overrides, not major modes.iconfield references an SVG file, which is a module icon, not a visual preview of the module in action.Credential Hygiene — 16 / 20
xray_tokenis markedsensitive = trueinmain.tf. README examples usevar.artifactory_access_token(a variable reference), not inline literal secrets. No hardcoded tokens in any example.Restricted-Environment Readiness — N/A
All four criteria are N/A by construction. This module performs no downloads or installations; it exclusively calls the JFrog Xray REST API via the
jfrog/xrayTerraform provider data source. No scripts are executed.xray_urlAPI endpoint.Engineering Quality — 10 / 10
xray_urlhas a regex validation,imagehas a structural validation (split check),xray_tokenis marked sensitive. Optional variables (repo,repo_path,use_cache_repo) have sensible defaults ("","",false).main.test.tsprovides a clear testing story with three mock Xray servers (local repo, remote/cache repo, empty results). Tests cover: required-variable validation (3 tests), local-repo vulnerability counts, zero-count edge case, cache-repo SHA filtering logic, and customrepo/repo_pathoverrides. Business logic (image parsing, cache-repo filtering, tag-vs-SHA disambiguation) is well covered.Overall — 81 / 100
Raw 38 / 47 → round(38 / 47 × 100) = 81
Scored against SCORECARD.md on 2026-09-28 with
solstice-1.All reactions