Project reference ↗

A software artifact can contain dependencies whose security or licensing issues are not obvious from the application’s own source. JFrog Xray analyzes artifacts and their components, connects findings to the JFrog platform and evaluates configured policies. It helps teams review the software they store and distribute through Artifactory. This entry concerns that service, not another product called Xray. Its database, messaging dependencies and stored keys must be considered together when moving an older installation to current packaging.

Current guidance

This entry is JFrog Xray’s artifact-analysis service, not another product named Xray. Current JFrog chart material uses PostgreSQL, RabbitMQ and Xray services and connects them to Artifactory. The upgrade documentation explains that Xray 3 no longer uses MongoDB except during migration from version 2, so the old page’s dependency list should not be copied into a new installation.

Confirm the required license and compatible Artifactory version, then preserve master/join keys, policies, watches, credentials and authoritative data stores. Migrate from classic RabbitMQ mirroring to quorum queues while still running RabbitMQ 3.x, before upgrading to RabbitMQ 4.x. JFrog warns that skipping this order causes data loss and requires repository re-indexing; treat the queue migration as a separate upgrade step.

Rehearse the documented sequence with isolated backups and validate ingestion, indexing, policy evaluation and downstream build behavior. Size database storage for the actual migration and inspect migration logs before enabling normal traffic. Review PVC retention carefully: the chart’s uninstall example includes explicit volume deletion. Do not run a cleanup command as a substitute for an upgrade, and retain a tested data restore path rather than relying solely on Helm revision history.

Historical upstream link check · 2026-10-09

The recorded upstream address redirects to https://docs.jfrog.com/setup/docs/get-started and returned HTTP 200 on 2026-10-09. Link availability does not certify the historical installation instructions or current security support.

Source for this check ↗

Website availability is separate from project, chart and image support. Use the current guidance and primary sources on this page to assess the distribution.

The original record

Historical Kubedex content

Preserved for context. Commands, versions, prices and results below reflect the original research.

Multilayer analysis of your containers and software artifacts for vulnerabilities, license compliance, and quality assurance.

 

Chart Details

This chart will do the following:

  • Optionally deploy PostgreSQL, MongoDB
  • Deploy RabbitMQ (optionally as an HA cluster)
  • Deploy JFrog Xray micro-services

Requirements

 

  • A running Kubernetes cluster
  • Dynamic storage provisioning enabled
  • Default StorageClass set to allow services using the default storage class for persistent storage
  • A running Artifactory
  • Kubectl installed and set up to use the cluster
  • Helm installed and set up to use the cluster (helm init)

 

Features:

 

  • The only binary analysis product that adds value to Artifactory by enriching artifacts with metadata and protecting your software from potential threats.
  • Provides fully automated protection for development, build, and production phases through IDE and CI/CD integration and an
    extensive REST API.
  • We provide around the clock help from the best support team in the industry.
  • Detect dependencies across all artifacts to enable full impact analysis and secured data-centers.
  • Increase your development workflow speed. Xray helps you speed up development by detecting vulnerabilities and outdated
    artifacts in the early stages of the software build and release cycle.

 

To get you up and running as quickly and easily as possible with all the Enterprise+ product suite, you’ll need to first install JFrog Artifactory and Mission Control. You can then continue to install, configure and add each additional service to Mission Control.

 

 

Sources & further reading

  1. JFrog chart dependencies and deletion warning
  2. Current Xray upgrade and data migration guidance
  3. Current Xray installation entry point
  4. Recovered historical source (Common Crawl index)

Spotted something that needs another look?

Help improve this page →