gadirlabs.Fictional illustrative sample
Asterpath · Revision 4

Tooling notes · no scan results

JFrog Xray: dependency and artifact risk evidence.

Xray primarily covers software composition risk. First-party SAST and other advanced scans require the relevant add-on. No JFrog scan was performed for Asterpath.

Fictional, not a scanner result. FICTIONAL ILLUSTRATIVE SAMPLE. Asterpath, its product, evidence, findings and measurements are invented. No Asterpath application was inspected and no scanner was executed. These are original GadirLabs illustrations, not native vendor exports.

Availability / export noteActual run status: Not run

What this tool can contribute

TopicVerified product guidance
RoleDependency vulnerabilities, licence information and software bill of materials; not a substitute for first-party maintainability review.
Advanced SecurityAdds first-party SAST, contextual dependency analysis, secrets and misconfiguration scanning; available as an Enterprise X/Enterprise+ add-on.
Native reportsGit-repository security exports can use PDF, CSV or JSON; the selected scan and exported categories determine the contents.
CLI formatsjf audit documents table, JSON, simple-json, SARIF and CycloneDX. Legacy JSON omits some advanced scan results.
SBOMPlatform exports support SPDX and CycloneDX. A component inventory does not establish exploitability.
Execution and dataThe CLI may install dependencies and makes results available in the platform. Use an approved prepared checkout and retain outputs before on-demand results expire.

What an actual client export would show

A genuine export would identify the scanned commit or artifact, component versions, enabled engines, advisories/licences where found, policy filters and ignore decisions. Our review would distinguish reachable material risk from irrelevant or accepted candidates. This pack contains no invented CVEs, vendor severities or fabricated report IDs.

This is a GadirLabs-authored tool note, not a vendor report, endorsement or claim of account access. No result, pass/fail status or vendor severity is asserted.

Primary sources

Checked 11 September 2026. These optional reference links require internet access; the sample pack itself works offline.