Describe the bug
After scanning with Frogbot v3, the SAST scan results cannot be displayed in the xray-scanlist-git repository.
Current behavior
forgbot version:3.5.0
JFrog version : Saas
As shown in the logs, the SAST scan results are present in the scan logs. However, they are not displayed under Violations, and the SAST results are also not shown in the Xray Scan List Git Repository.However, when using Frogbot v2, the SAST scan results are displayed correctly.
06:35:41 [Info] Frogbot version: 3.5.0
06:35:42 [Info] Using API endpoint: https://api.github.com/
06:35:43 [Info] Using Config profile 'profile-Cpp_VulnCases_forgbot_v3-1147-1787553312140'
06:35:43 [Info] Running Frogbot "scan-repository" command
06:35:43 [Info] Getting resources (git repository: github.com/liwei2151284/Cpp_VulnCases_forgbot_v3.git) active watches...
06:35:43 [Info] Found 4 active watches in the following resources - git repository: github.com/liwei2151284/Cpp_VulnCases_forgbot_v3.git
06:35:45 [Info] [Thread 0] The 'Xray-Lib Plugin' app is not cached locally. Downloading it now...
06:35:45 [Info] Downloading JFrog's Dependency from https://releases.jfrog.io/artifactory/xray-scan-lib/xray-scan-lib-1.4.0-linux-amd64.tar.gz
06:35:47 [Info] Extracting archive: /tmp/jfrog.cli.temp.-1787553345-2653256203/xray-scan-lib-1.4.0-linux-amd64.tar.gz to /tmp/jfrog.cli.temp.-1787553345-2653256203/
06:35:47 [Info] Generating SBOM...
06:35:58 [Info] SBOM generated; found 11 library components (duration 10.720097078s)
06:35:58 [Info] Performing scans on project /tmp/jfrog.cli.temp.-1787553344-3163304133 [.NET, NuGet]
06:35:58 [Info] [Thread 1] Running SCA scan...
06:35:58 [Info] [Thread 4] The 'Analyzer Manager' app is not cached locally. Downloading it now...
06:35:58 [Info] Downloading JFrog's Dependency from https://releases.jfrog.io/artifactory/xsc-gen-exe-analyzer-manager-local/v1/1.50.0/linux-amd64/analyzerManager.zip
06:35:58 [Info] [Thread 1] No SCA vulnerabilities were found (duration 316.115941ms)
06:36:00 [Info] Extracting archive: /tmp/jfrog.cli.temp.-1787553358-1569241447/analyzerManager.zip to /tmp/jfrog.cli.temp.-1787553358-1569241447/
06:36:03 [Info] [Thread 3] Running Secrets scan...
06:36:03 [Info] [Thread 0] Running IaC scan...
06:36:03 [Info] [Thread 1] Running SAST scan...
06:36:10 [Info] [Thread 0] No IaC vulnerabilities were found (duration 7.202633071s)
06:36:17 [Info] [Thread 3] No Secrets exposures were found (duration 14.132462311s)
06:36:40 [Info] [Thread 1] Found 34 SAST vulnerabilities (duration 36.774300381s)
06:36:52 [Info] Xray is processing your scan results...
06:36:52 [Info] Fetching violations from Xray...
06:36:52 [Info] No violations found.
06:36:52 [Info] Xray scan completed
- You may view the scan results in the JFrog platform, under Xray -> Scans List -> Git Repositories:
***ui/scans-list/git-repos-scans/Cpp_VulnCases_forgbot_v3/scan-descendants/main?author=Wei%C2%A0+Li&branchId=1151&commitId=824c7e1166435da79344568fc7e051a619fc72ca&date=2026-08-24T06%3A36%3A45Z&isStaticSca=true&last_commit=https%3A%2F%2Fgithub.com%2Fliwei2151284%2FCpp_VulnCases_forgbot_v3%2Fcommit%2F824c7e1166435da79344568fc7e051a619fc72ca&package_id=generic%3A%2F%2Fsha256%3Afebc631d4d1c16b4ba3abef434b552b77254a6b30f1774fd49e1234db0e4fdd5%2Fsource_code_1787553400525.cdx.json&page_type=overview&path=frogbot%2Fgithub.com%2Fliwei2151284%2FCpp_VulnCases_forgbot_v3%2Fmain%2Fcommits%2Fsource_code_1787553400525.cdx.json&repoId=1147&repoName=Cpp_VulnCases_forgbot_v3&root_file_id=2091776709277560832&scanName=main&scanType=git-repos-scans&title=Update+README.md
Security Violations
+-----------------------------------+
| No security violations were found |
+-----------------------------------+
License Compliance Violations
+---------------------------------------------+
| No license compliance violations were found |
+---------------------------------------------+
Operational Risk Violations
+-------------------------------------------+
| No operational risk violations were found |
+-------------------------------------------+
Licenses
+------------------------+
| No licenses were found |
+------------------------+
Secret Violations
+----------------------------+
| No violations were found |
+----------------------------+
Infrastructure as Code Violations
+---------------------------------------------------+
| No Infrastructure as Code violations were found |
+---------------------------------------------------+
Static Application Security Testing (SAST) Violations
+----------------------------------------------------------------+
| No Static Application Security Testing violations were found |
Reproduction steps
No response
Expected behavior
No response
JFrog Frogbot version
3.5.0
Package manager info
cpp
Git provider
GitHub
JFrog Frogbot configuration yaml file
No response
Operating system type and version
github action
JFrog Xray version
saas
Describe the bug
After scanning with Frogbot v3, the SAST scan results cannot be displayed in the xray-scanlist-git repository.
Current behavior
forgbot version:3.5.0
JFrog version : Saas
As shown in the logs, the SAST scan results are present in the scan logs. However, they are not displayed under Violations, and the SAST results are also not shown in the Xray Scan List Git Repository.However, when using Frogbot v2, the SAST scan results are displayed correctly.
06:35:41 [Info] Frogbot version: 3.5.0
06:35:42 [Info] Using API endpoint: https://api.github.com/
06:35:43 [Info] Using Config profile 'profile-Cpp_VulnCases_forgbot_v3-1147-1787553312140'
06:35:43 [Info] Running Frogbot "scan-repository" command
06:35:43 [Info] Getting resources (git repository: github.com/liwei2151284/Cpp_VulnCases_forgbot_v3.git) active watches...
06:35:43 [Info] Found 4 active watches in the following resources - git repository: github.com/liwei2151284/Cpp_VulnCases_forgbot_v3.git
06:35:45 [Info] [Thread 0] The 'Xray-Lib Plugin' app is not cached locally. Downloading it now...
06:35:45 [Info] Downloading JFrog's Dependency from https://releases.jfrog.io/artifactory/xray-scan-lib/xray-scan-lib-1.4.0-linux-amd64.tar.gz
06:35:47 [Info] Extracting archive: /tmp/jfrog.cli.temp.-1787553345-2653256203/xray-scan-lib-1.4.0-linux-amd64.tar.gz to /tmp/jfrog.cli.temp.-1787553345-2653256203/
06:35:47 [Info] Generating SBOM...
06:35:58 [Info] SBOM generated; found 11 library components (duration 10.720097078s)
06:35:58 [Info] Performing scans on project /tmp/jfrog.cli.temp.-1787553344-3163304133 [.NET, NuGet]
06:35:58 [Info] [Thread 1] Running SCA scan...
06:35:58 [Info] [Thread 4] The 'Analyzer Manager' app is not cached locally. Downloading it now...
06:35:58 [Info] Downloading JFrog's Dependency from https://releases.jfrog.io/artifactory/xsc-gen-exe-analyzer-manager-local/v1/1.50.0/linux-amd64/analyzerManager.zip
06:35:58 [Info] [Thread 1] No SCA vulnerabilities were found (duration 316.115941ms)
06:36:00 [Info] Extracting archive: /tmp/jfrog.cli.temp.-1787553358-1569241447/analyzerManager.zip to /tmp/jfrog.cli.temp.-1787553358-1569241447/
06:36:03 [Info] [Thread 3] Running Secrets scan...
06:36:03 [Info] [Thread 0] Running IaC scan...
06:36:03 [Info] [Thread 1] Running SAST scan...
06:36:10 [Info] [Thread 0] No IaC vulnerabilities were found (duration 7.202633071s)
06:36:17 [Info] [Thread 3] No Secrets exposures were found (duration 14.132462311s)
06:36:40 [Info] [Thread 1] Found 34 SAST vulnerabilities (duration 36.774300381s)
06:36:52 [Info] Xray is processing your scan results...
06:36:52 [Info] Fetching violations from Xray...
06:36:52 [Info] No violations found.
06:36:52 [Info] Xray scan completed
***ui/scans-list/git-repos-scans/Cpp_VulnCases_forgbot_v3/scan-descendants/main?author=Wei%C2%A0+Li&branchId=1151&commitId=824c7e1166435da79344568fc7e051a619fc72ca&date=2026-08-24T06%3A36%3A45Z&isStaticSca=true&last_commit=https%3A%2F%2Fgithub.com%2Fliwei2151284%2FCpp_VulnCases_forgbot_v3%2Fcommit%2F824c7e1166435da79344568fc7e051a619fc72ca&package_id=generic%3A%2F%2Fsha256%3Afebc631d4d1c16b4ba3abef434b552b77254a6b30f1774fd49e1234db0e4fdd5%2Fsource_code_1787553400525.cdx.json&page_type=overview&path=frogbot%2Fgithub.com%2Fliwei2151284%2FCpp_VulnCases_forgbot_v3%2Fmain%2Fcommits%2Fsource_code_1787553400525.cdx.json&repoId=1147&repoName=Cpp_VulnCases_forgbot_v3&root_file_id=2091776709277560832&scanName=main&scanType=git-repos-scans&title=Update+README.md
Security Violations
+-----------------------------------+
| No security violations were found |
+-----------------------------------+
License Compliance Violations
+---------------------------------------------+
| No license compliance violations were found |
+---------------------------------------------+
Operational Risk Violations
+-------------------------------------------+
| No operational risk violations were found |
+-------------------------------------------+
Licenses
+------------------------+
| No licenses were found |
+------------------------+
Secret Violations
+----------------------------+
| No violations were found |
+----------------------------+
Infrastructure as Code Violations
+---------------------------------------------------+
| No Infrastructure as Code violations were found |
+---------------------------------------------------+
Static Application Security Testing (SAST) Violations
+----------------------------------------------------------------+
| No Static Application Security Testing violations were found |
Reproduction steps
No response
Expected behavior
No response
JFrog Frogbot version
3.5.0
Package manager info
cpp
Git provider
GitHub
JFrog Frogbot configuration yaml file
No response
Operating system type and version
github action
JFrog Xray version
saas