You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: en/on-call/integration/alert-integration/alert-sources/jfrog-xray.mdx
+3-3Lines changed: 3 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -40,7 +40,7 @@ You can get the integration push URL in either of the following ways.
40
40
1. Sign in to the JFrog Platform as an administrator, go to **Administration → Xray Settings → Webhooks** and click **New Webhook**
41
41
2. In **Webhook Name**, enter a name such as `flashduty`; policy rules refer to the webhook by this name
42
42
3. In **URL**, paste the full Flashduty push URL (starting with `https://` and including `integration_key`)
43
-
4. Leave **Use Proxy**, **Basic Auth** and **Custom Headers** empty and click **Save**
43
+
4. Leave **Use Proxy**, **Basic Auth** and **Custom Headers** empty and click **Create**
44
44
45
45
</Step>
46
46
@@ -61,7 +61,7 @@ You can get the integration push URL in either of the following ways.
61
61
62
62
<Steptitle="Verify">
63
63
64
-
The Xray webhook page has no test button. Upload a component with a known vulnerability (for example `log4j-core` 2.14.1) to a watched repository, or run the watch manually from the watch list. Within a few minutes Flashduty shows an alert titled like `JFrog Xray: 7 violations in watch <watch name> (<policy name>)`.
64
+
The Xray webhook page has no test button. Upload a component with a known vulnerability (for example `log4j-core` 2.14.1) to a watched repository. After Xray scans it, Flashduty shows an alert titled like `JFrog Xray: 7 violations in watch <watch name> (<policy name>)`.
65
65
66
66
</Step>
67
67
</Steps>
@@ -116,7 +116,7 @@ One webhook holds every issue (`issues`) that the scan found under that rule.
116
116
## Troubleshooting
117
117
---
118
118
119
-
-**Flashduty receives nothing**: check that the policy rule's **Then** section has **Trigger webhook** selected with this webhook, that the policy is assigned to a watch, and that the watch is active. Xray sends a webhook only for newly found violations; saving a rule does not resend violations that already exist. You can run the watch manually from the watch list
119
+
-**Flashduty receives nothing**: check that the policy rule's **Then** section has **Trigger webhook** selected with this webhook, that the policy is assigned to a watch, and that the watch is active. Xray sends a webhook only for newly found violations; saving a rule does not resend violations that already exist. **Apply on Existing Content** in the row actions of the watch does not resend them either. Upload a new vulnerable component to a watched repository to verify
120
120
-**Flashduty returns a parameter error**: the body is not JSON, or it has no `watch_name`. Send the Xray violation webhook directly, not through a relay that rewrites the body
121
121
-**One scan created several alerts**: Xray sends one webhook for each matched policy rule on the watch, and each becomes its own alert
122
122
-**The alert never closes**: Xray sends no recovery notification. Turn on auto-close in the channel, or close the alert by hand
0 commit comments