You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A discussion dedicated to the JFrog (Token) module. Share your thoughts, questions, and feedback here.
Module Scorecard
Presentation & Onboarding
Credential Hygiene
Restricted-Environment Readiness
Engineering Quality
Overall
17 / 17
12 / 20
11 / 20
10 / 10
75 / 100
Drilldown
Presentation & Onboarding — 17 / 17
Criterion
Max
Score
Notes
Configuration-mode examples
12
12
README documents every major mode: full install+configure+package managers, token-only mode (install_jfrog_cli = false, configure_jfrog_cli = false), pre-installed binary path, package-manager-only, code-server extension, and custom token description. Each has a complete module block with sensible defaults.
Visual preview
5
5
README embeds ; file verified to exist at 56.0 KB.
Credential Hygiene — 12 / 20
Criterion
Max
Score
Notes
Secrets marked sensitive
16
8
The artifactory_access_token input variable is not marked sensitive = true in main.tf. The access_token output is correctly marked sensitive = true, and README examples use var.artifactory_access_token (no inline secrets). Half credit: output is protected and README is clean, but the primary sensitive input lacks the sensitive flag.
Non-hardcoded auth path
4
4
README shows the admin token passed as a Terraform variable (var.artifactory_access_token); the module uses the jfrog/artifactory provider to mint a scoped token at apply time. No raw keys are pasted into templates.
Restricted-Environment Readiness — 11 / 20
Criterion
Max
Score
Notes
Mirrorable artifact source
5
0
run.sh hardcodes curl -fL https://install-cli.jfrog.io | sudo sh. No module input variable overrides this download URL. No variable can be named that replaces the install URL.
Bring-your-own binary
10
10
install_jfrog_cli (default true) is documented in the README "Token-only mode" section: "To configure a pre-installed jf binary, set only install_jfrog_cli = false." The script checks command -v jf and skips install when the flag is false.
Egress transparency
3
0
No dedicated README section enumerates external endpoints (install-cli.jfrog.io, the user's JFrog host, open-vsx.org for the code-server extension). Endpoints are only visible in run.sh source. No air-gapped or restricted-network guidance.
Runs without sudo
2
1
run.sh invokes sudo sh and sudo chmod 755 during CLI install. However, this path is optional (install_jfrog_cli = false bypasses it entirely), and the pre-installed-binary fallback works without sudo. Half credit per rubric.
Engineering Quality — 10 / 10
Criterion
Max
Score
Notes
Input quality
6
6
All 14 variables have descriptions and sensible defaults. jfrog_url and username_field carry regex validation blocks. package_managers has a detailed multi-line description with examples and a validation enforcing npm/pnpm list equality.
Test coverage
4
4
jfrog-token.tftest.hcl covers three business-logic modes (default, token-only, package-manager-only). main.test.ts runs 9 end-to-end tests against a local fake JFrog server, verifying generated script content for npm, pnpm, pip, docker, go, conda, maven, and the missing-CLI error path.
Overall — 75 / 100
Raw 50 / 67 → round(50 / 67 × 100) = 75
Track: Utility (package-manager/auth integration; not an AI agent or IDE)
Scored against SCORECARD.md on 2026-10-06 with solstice-1.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
A discussion dedicated to the JFrog (Token) module. Share your thoughts, questions, and feedback here.
Module Scorecard
Drilldown
Presentation & Onboarding — 17 / 17
install_jfrog_cli = false,configure_jfrog_cli = false), pre-installed binary path, package-manager-only, code-server extension, and custom token description. Each has a completemoduleblock with sensible defaults.; file verified to exist at 56.0 KB.Credential Hygiene — 12 / 20
artifactory_access_tokeninput variable is not markedsensitive = trueinmain.tf. Theaccess_tokenoutput is correctly markedsensitive = true, and README examples usevar.artifactory_access_token(no inline secrets). Half credit: output is protected and README is clean, but the primary sensitive input lacks thesensitiveflag.var.artifactory_access_token); the module uses thejfrog/artifactoryprovider to mint a scoped token at apply time. No raw keys are pasted into templates.Restricted-Environment Readiness — 11 / 20
run.shhardcodescurl -fL https://install-cli.jfrog.io | sudo sh. No module input variable overrides this download URL. No variable can be named that replaces the install URL.install_jfrog_cli(defaulttrue) is documented in the README "Token-only mode" section: "To configure a pre-installedjfbinary, set onlyinstall_jfrog_cli = false." The script checkscommand -v jfand skips install when the flag is false.run.shsource. No air-gapped or restricted-network guidance.run.shinvokessudo shandsudo chmod 755during CLI install. However, this path is optional (install_jfrog_cli = falsebypasses it entirely), and the pre-installed-binary fallback works without sudo. Half credit per rubric.Engineering Quality — 10 / 10
jfrog_urlandusername_fieldcarry regexvalidationblocks.package_managershas a detailed multi-line description with examples and a validation enforcing npm/pnpm list equality.jfrog-token.tftest.hclcovers three business-logic modes (default, token-only, package-manager-only).main.test.tsruns 9 end-to-end tests against a local fake JFrog server, verifying generated script content for npm, pnpm, pip, docker, go, conda, maven, and the missing-CLI error path.Overall — 75 / 100
Raw 50 / 67 → round(50 / 67 × 100) = 75
Track: Utility (package-manager/auth integration; not an AI agent or IDE)
Scored against SCORECARD.md on 2026-10-06 with
solstice-1.All reactions