JFrog · Arazzo Workflow

JFrog Xray Vulnerability Report

Version 1.0.0

Generate a vulnerability report and poll until it completes.

1 workflow 1 source API 1 provider
View Spec View on GitHub ArtifactoryCI/CDContainer RegistryDevOpsMLOpsPackage ManagementSecuritySoftware Supply ChainArazzoWorkflows

Provider

jfrog

Workflows

vulnerability-report
Kick off a vulnerability report and wait for it to finish.
Generates a vulnerability report scoped to a repository, captures the report id, then polls the report status until it is completed.
2 steps inputs: repoKey, reportName outputs: reportId, status
1
generateReport
Generate a vulnerability report scoped to the supplied repository, filtering for findings that have remediation.
2
pollStatus
Poll the report status. While it is pending or running, loop back and check again; once it is completed, finish.

Source API Descriptions

Arazzo Workflow Specification

Raw ↑
arazzo: 1.0.1
info:
  title: JFrog Xray Vulnerability Report
  summary: Generate a vulnerability report and poll until it completes.
  description: >-
    An asynchronous reporting flow. The workflow generates a vulnerability
    report for a repository, then polls the report status in a loop, branching
    back to itself while the status is pending or running and ending once it
    reaches completed. Every step spells out its request inline so the flow can
    be read and executed without opening the underlying OpenAPI description.
  version: 1.0.0
  x-realizes-capability-ids:
  - BC-620.40
  x-capability-derivation:
    method: 'deterministic join: sourceDescriptions -> per-tag OpenAPI -> tag/capability edge. No classification at this step.'
    min_confidence: 0.7
    sources:
    - capability_id: BC-620.40
      capability_name: Vulnerability Management
      spec: jfrog-reports-api-openapi.yml
      confidence: 0.7
    model: Turbo EA Capabilities by Vincent Verdet — Turbo EA, https://github.com/vincentmakes/turbo-ea-capabilities, CC BY 4.0
sourceDescriptions:
- name: reportsApi
  url: ../openapi/jfrog-reports-api-openapi.yml
  type: openapi
workflows:
- workflowId: vulnerability-report
  summary: Kick off a vulnerability report and wait for it to finish.
  description: >-
    Generates a vulnerability report scoped to a repository, captures the report
    id, then polls the report status until it is completed.
  inputs:
    type: object
    required:
    - reportName
    - repoKey
    properties:
      reportName:
        type: string
        description: The name to assign to the generated report.
      repoKey:
        type: string
        description: The repository to scope the report to.
  steps:
  - stepId: generateReport
    description: >-
      Generate a vulnerability report scoped to the supplied repository,
      filtering for findings that have remediation.
    operationId: generateVulnerabilityReport
    requestBody:
      contentType: application/json
      payload:
        name: $inputs.reportName
        resources:
          repositories:
          - name: $inputs.repoKey
        filters:
          has_remediation: true
    successCriteria:
    - condition: $statusCode == 200
    outputs:
      reportId: $response.body#/report_id
  - stepId: pollStatus
    description: >-
      Poll the report status. While it is pending or running, loop back and
      check again; once it is completed, finish.
    operationId: getReportStatus
    parameters:
    - name: reportId
      in: path
      value: $steps.generateReport.outputs.reportId
    successCriteria:
    - condition: $statusCode == 200
    outputs:
      status: $response.body#/status
      reportId: $response.body#/id
    onSuccess:
    - name: stillRunning
      type: goto
      stepId: pollStatus
      criteria:
      - context: $response.body
        condition: $.status == 'pending' || $.status == 'running'
        type: jsonpath
    - name: finished
      type: end
      criteria:
      - context: $response.body
        condition: $.status == 'completed'
        type: jsonpath
  outputs:
    reportId: $steps.generateReport.outputs.reportId
    status: $steps.pollStatus.outputs.status

Work with this as data

Every workflow here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for arazzo workflows

4 MCP tools reach this
  • find_arazzoBrowse and filter every workflow in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This workflow
curl "https://apis.io/api/v1/arazzo/jfrog-xray-vulnerability-report-workflow"
All arazzo workflows
curl "https://apis.io/api/v1/arazzo?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.