Skip to content

Commit 1270933

Browse files
authored
Merge pull request #1008 from flashcatcloud/fix/jfrog-xray-docs-ui-test
docs(jfrog-xray): match webhook form button and verification steps to the Xray UI
2 parents 3a1d860 + 457979d commit 1270933

2 files changed

Lines changed: 6 additions & 6 deletions

File tree

‎en/on-call/integration/alert-integration/alert-sources/jfrog-xray.mdx‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -40,7 +40,7 @@ You can get the integration push URL in either of the following ways.
4040
1. Sign in to the JFrog Platform as an administrator, go to **Administration → Xray Settings → Webhooks** and click **New Webhook**
4141
2. In **Webhook Name**, enter a name such as `flashduty`; policy rules refer to the webhook by this name
4242
3. In **URL**, paste the full Flashduty push URL (starting with `https://` and including `integration_key`)
43-
4. Leave **Use Proxy**, **Basic Auth** and **Custom Headers** empty and click **Save**
43+
4. Leave **Use Proxy**, **Basic Auth** and **Custom Headers** empty and click **Create**
4444

4545
</Step>
4646

@@ -61,7 +61,7 @@ You can get the integration push URL in either of the following ways.
6161

6262
<Step title="Verify">
6363

64-
The Xray webhook page has no test button. Upload a component with a known vulnerability (for example `log4j-core` 2.14.1) to a watched repository, or run the watch manually from the watch list. Within a few minutes Flashduty shows an alert titled like `JFrog Xray: 7 violations in watch <watch name> (<policy name>)`.
64+
The Xray webhook page has no test button. Upload a component with a known vulnerability (for example `log4j-core` 2.14.1) to a watched repository. After Xray scans it, Flashduty shows an alert titled like `JFrog Xray: 7 violations in watch <watch name> (<policy name>)`.
6565

6666
</Step>
6767
</Steps>
@@ -116,7 +116,7 @@ One webhook holds every issue (`issues`) that the scan found under that rule.
116116
## Troubleshooting
117117
---
118118

119-
- **Flashduty receives nothing**: check that the policy rule's **Then** section has **Trigger webhook** selected with this webhook, that the policy is assigned to a watch, and that the watch is active. Xray sends a webhook only for newly found violations; saving a rule does not resend violations that already exist. You can run the watch manually from the watch list
119+
- **Flashduty receives nothing**: check that the policy rule's **Then** section has **Trigger webhook** selected with this webhook, that the policy is assigned to a watch, and that the watch is active. Xray sends a webhook only for newly found violations; saving a rule does not resend violations that already exist. **Apply on Existing Content** in the row actions of the watch does not resend them either. Upload a new vulnerable component to a watched repository to verify
120120
- **Flashduty returns a parameter error**: the body is not JSON, or it has no `watch_name`. Send the Xray violation webhook directly, not through a relay that rewrites the body
121121
- **One scan created several alerts**: Xray sends one webhook for each matched policy rule on the watch, and each becomes its own alert
122122
- **The alert never closes**: Xray sends no recovery notification. Turn on auto-close in the channel, or close the alert by hand

‎zh/on-call/integration/alert-integration/alert-sources/jfrog-xray.mdx‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -40,7 +40,7 @@ Xray 只在扫描发现违规时推送,问题修复后不会发恢复通知,
4040
1. 使用管理员账号登录 JFrog Platform,进入 **Administration → Xray Settings → Webhooks**,点击 **New Webhook**
4141
2. **Webhook Name** 填写名称,例如 `flashduty`;策略规则按这个名称引用 Webhook
4242
3. **URL** 填 Flashduty 集成的完整推送地址(以 `https://` 开头,包含 `integration_key`)
43-
4. **Use Proxy**、**Basic Auth** 和 **Custom Headers** 保持为空,点击 **Save**
43+
4. **Use Proxy**、**Basic Auth** 和 **Custom Headers** 保持为空,点击 **Create**
4444

4545
</Step>
4646

@@ -61,7 +61,7 @@ Xray 只在扫描发现违规时推送,问题修复后不会发恢复通知,
6161

6262
<Step title="验证">
6363

64-
Xray 的 Webhook 页面没有测试按钮。向被监视的仓库上传一个带已知漏洞的组件(例如 `log4j-core` 2.14.1),或在监视列表中手动运行一次监视,几分钟内 Flashduty 会出现一条告警,标题形如 `JFrog Xray: 7 violations in watch <监视名称> (<策略名称>)`。
64+
Xray 的 Webhook 页面没有测试按钮。向被监视的仓库上传一个带已知漏洞的组件(例如 `log4j-core` 2.14.1),Xray 完成扫描后,Flashduty 会出现一条告警,标题形如 `JFrog Xray: 7 violations in watch <监视名称> (<策略名称>)`。
6565

6666
</Step>
6767
</Steps>
@@ -116,7 +116,7 @@ Xray 每次扫描监视时生成一个 `alert_id`。一次扫描命中多个策
116116
## 排查问题
117117
---
118118

119-
- **Flashduty 没有收到推送**:确认策略规则的 **Then** 中勾选了 **Trigger webhook** 并选择了该 Webhook,且策略已分配给监视、监视处于启用状态。Xray 只为新发现的违规推送,已经产生过的违规不会因为保存规则而重新推送,可以在监视列表中手动运行监视
119+
- **Flashduty 没有收到推送**:确认策略规则的 **Then** 中勾选了 **Trigger webhook** 并选择了该 Webhook,且策略已分配给监视、监视处于启用状态。Xray 只为新发现的违规推送,已经产生过的违规不会因为保存规则而重新推送,在监视的操作菜单中选择 **Apply on Existing Content** 也不会重新推送。可以向被监视的仓库上传一个新的带漏洞组件来验证
120120
- **Flashduty 返回参数错误**:请求体不是 JSON,或缺少 `watch_name`。请直接使用 Xray 的违规 Webhook,不要经过会改写请求体的中转
121121
- **一次扫描出现了多条告警**:监视上每个命中的策略规则各推送一次,各自成为一条告警
122122
- **告警一直不关闭**:Xray 不发送恢复通知。请在协作空间中开启超时自动关闭,或手动关闭

0 commit comments

Comments
 (0)