In Flashduty On-call
You can get the integration push URL in either of the following ways.
Use a dedicated integration
- In the Flashduty console, select Channel and open a channel
- Select Configuration → Integrations → Private integration, then click Add an integration
- Select JFrog Xray and click Save
- Open the new integration card and copy the Push URL
Use a shared integration
- In the Flashduty console, select Integration Center → Alert Events
- Select JFrog Xray and enter an integration name
- Configure the default route and select a channel. You can add more rules under Routes after creation
- Click Save and copy the generated Push URL
Configure JFrog Xray
1
Create a webhook
- Sign in to the JFrog Platform as an administrator, go to Administration → Xray Settings → Webhooks and click New Webhook
- In Webhook Name, enter a name such as
flashduty; policy rules refer to the webhook by this name - In URL, paste the full Flashduty push URL (starting with
https://and includingintegration_key) - Leave Use Proxy, Basic Auth and Custom Headers empty and click Create
2
Trigger the webhook from a policy rule
- Go to Platform → Xray → Watches & Policies → Policies and open an existing policy, or click New Policy (type Security, License or Operational Risk)
- Edit or create a rule. Under Then → Do the following actions, select Trigger webhook, choose the webhook from the previous step and click Save Rule
- Click Save Policy. Select the webhook on every rule you want to send to Flashduty
3
Assign the policy to a watch
- Go to Platform → Xray → Watches & Policies → Watches and open an existing watch, or click New Watch
- Add the repositories, builds or release bundles to scan, add the policy from the previous step and save
4
Verify
The Xray webhook page has no test button. Upload a component with a known vulnerability (for example
log4j-core 2.14.1) to a watched repository. After Xray scans it, Flashduty shows an alert titled like JFrog Xray: 7 violations in watch <watch name> (<policy name>).Recovery and auto-close
The Xray violation webhook is sent only when a scan finds violations. The request body has no field that marks a violation as fixed or ignored, so the alert in Flashduty does not recover on its own. Each delivery is a separate Flashduty alert. Close it by hand, or turn on auto-close in the channel that receives this integration, set to how quickly your team handles vulnerabilities, for example 7 days.
Alert Key
Xray creates an
alert_id for each scan of a watch. When one scan matches several policy rules (for example a security policy and a license policy on the same watch), Xray sends one webhook per rule, all with the same alert_id. So Flashduty builds the Alert Key from alert_id, the watch name watch_name, the policy name policy_name and the rule name policy_rule (joined with an invisible separator, then MD5):
- A repeated delivery of the same webhook merges into the same alert
- Different rules of one scan, and the next scan (even if it finds the same issues), are different alerts
- Request bodies from older Xray versions have no
alert_id; Flashduty then generates a random Alert Key and each delivery is its own alert - If the body has no
watch_name, Flashduty returns 400 and names the missing field
Status and severity
The alert status equals its severity; it does not recover. The severity comes from the highest severity in the body,
top_severity; if it is missing or not one of the values below, the most severe issue decides.
Alert content
One webhook holds every issue (
issues) that the scan found under that rule.
- Title:
JFrog Xray: <issue count> violations in watch <watch name> (<policy name>); with a single issue,JFrog Xray: <CVE ID or license name> in <impacted component> (watch <watch name>) - Description: the watch name, issue count, policy and rule, then the 10 most severe issues (severity, CVE, Xray ID, issue type, impacted component and summary); the remaining issues are only counted
Troubleshooting
- Flashduty receives nothing: check that the policy rule’s Then section has Trigger webhook selected with this webhook, that the policy is assigned to a watch, and that the watch is active. Xray sends a webhook only for newly found violations; saving a rule does not resend violations that already exist. Apply on Existing Content in the row actions of the watch does not resend them either. Upload a new vulnerable component to a watched repository to verify
- Flashduty returns a parameter error: the body is not JSON, or it has no
watch_name. Send the Xray violation webhook directly, not through a relay that rewrites the body - One scan created several alerts: Xray sends one webhook for each matched policy rule on the watch, and each becomes its own alert
- The alert never closes: Xray sends no recovery notification. Turn on auto-close in the channel, or close the alert by hand