Your manifest lists what you chose. Your image ships far more — JFrog Xray scans the packages, builds and images stored in Artifactory for CVEs, licences and malware — and blocks the ones that break policy at the registry, before any build can pull them.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers JFrog Xray — software composition analysis on every artifact. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
Software composition analysis inside Artifactory — CVEs, licences, malicious packages and operational risk, checked on the artifacts you store.
What consolidation actually replaces, dimension by dimension.
| Dimension | SCA scripted into every pipeline | JFrog Xray |
|---|---|---|
| Where scanning happens | In each repo's pipeline | Once, at the registry |
| What gets scanned | Declared manifests | The stored artifact and its layers |
| Blocking | A failed job someone reruns | Download blocked by a watch |
| SBOM | Assembled by hand per release | Exported as SPDX or CycloneDX |
| Licences | Reviewed at audit time | Checked as the package lands |
| What it is NOT | — | Not a scanner for anything outside Artifactory |
The fastest honest test: index one busy repository and one production image, and see what Xray finds that your manifests never mentioned.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Xray indexes what lands in Artifactory — packages, builds, Release Bundles and container images. What never passes through Artifactory, Xray never sees; that is the scope decision.
Updated automatically every day, faster during major incidents, with 4M+ open-source packages in the extended database. Air-gapped installs take the same data by offline sync.
Unpacks Docker image layers and nested archives to find the component inside the component — the library in the JAR in the image — and traces which builds carry it.
A policy defines the rule; a watch binds it to repositories, builds or Release Bundles. A violation can block the download — including artifacts not yet scanned.
Xray scans what Artifactory holds — then blocks what breaks policy before anyone can download it.
Xray scans what your registry actually holds — stored packages, image layers, builds, and the rest of the JFrog platform.
Direct and transitive dependencies checked against JFrog's database, updated daily — so an old artifact is re-flagged when a new CVE lands.
Recursive analysis of Docker image layers finds the vulnerable library buried in a base image, not just the packages your Dockerfile names.
Flags packages JFrog's research team has identified as malicious — 2,000+ disclosed so far, by JFrog's count — as they land in a repository.
Detects the licence on each component and flags the ones your policy forbids, before a copyleft dependency reaches a shipped release.
Exports SPDX or CycloneDX for a package, build or release — CycloneDX with VEX from Xray 3.67 — generated from the scanned artifact itself.
Scores components on version age, maintenance cadence, contributor count and end-of-life status — risk that has no CVE attached yet.
A watch can block download of an artifact that breaks policy — or one Xray has not scanned yet — so the build fails, not production.
Model files stored in Artifactory are scanned too; JFrog describes self-managed Pro X as Artifactory plus SCA and model security.
IDE plugins for VS Code, IntelliJ, Visual Studio and PyCharm, plus JFrog CLI, show the same findings to a developer before a push.
What Xray scans, how watches and policies enforce it, and the wider scan beyond CVEs.
What Xray scans, and where.
Watches, policies and licences.
Beyond CVEs: the wider scan.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Manifest scanners read package.json and pom.xml. Xray reads the binaries and images stored in Artifactory — including the base image and the library nobody declared. The SBOM it exports describes the artifact that shipped, not the one someone intended.
Every build pulls through the registry, so a policy there applies to every team at once. A watch can block the download of a violating or unscanned artifact — without a scanning step to maintain in fifty separate CI configurations.
Xray has no line-item price. It is not in SaaS Pro ($150/month list); it arrives with SaaS Enterprise X from $950/month or self-managed Pro X from $27,000 a year. The real question is whether you also need what else that tier brings.
Xray only scans what flows through Artifactory: a package pulled straight from the internet, or an image held in another registry, is invisible to it. CVE applicability, secrets detection and SAST belong to Advanced Security, a separate paid add-on.
List the repos, pipelines and registries that never touch Artifactory. Xray cannot see them — that gap is your real coverage.
On SaaS Pro, Xray means Enterprise X from $950/month; self-managed, Pro X from $27,000 a year. Price the step, not a line item.
Turn on indexing for a few busy repositories and let Xray scan what is already stored. The first baseline is loud — read it first.
Start with violations that notify rather than block. Tune severity, licence and malicious-package rules until developers accept them.
Enable Block Download, and Block Unscanned, on the critical repositories first, then widen the watches one repository at a time.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“Block Unscanned closed a gap we hadn't noticed: new artifacts were downloadable for minutes before their scan finished.”
“The image scan found an old OpenSSL in a base image three teams had inherited. Not one of their manifests mentioned it.”
“We were on Pro and assumed Xray came with it. It doesn't — budget the Enterprise X step before you plan the rollout.”
“Lots of findings and no applicability context without the add-on. Expect weeks of policy tuning before developers trust it.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the software composition analysis market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
JFrog is a Leader in Gartner's first SSCS MQ; Xray's scope is the registry.
The grid nobody publishes — how deeply a tool scans stored binaries and images vs how deeply it lives in the developer's IDE and pull request.
Scans the stored artifact and blocks it at the registry.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Snyk Open Source, Sonatype Lifecycle / Guide, Mend.io, Black Duck and GitHub Code Security — on scope, deployment, price, enforcement and India.
| Dimension | JFrog Xray | Snyk Open Source | Sonatype Lifecycle / Guide | Mend.io | Black Duck | GitHub Code Security |
|---|---|---|---|---|---|---|
| What it is | SCA inside the registry | Developer-first SCA | Policy-led SCA | AppSec platform SCA | Composition analysis | Repo-native SCA |
| Deployment | SaaS, self-host, air-gap | SaaS or private cloud | SaaS, cloud or self-host | SaaS-led | SaaS, on-prem, air-gap | GitHub.com or GHES |
| Formats & coverage | 25+ package types | Major ecosystems | Ask for the matrix | Code + containers | Source and binaries | GitHub repos only |
| Pricing model | Comes with a tier | Credits on Enterprise | Credits via Guide | Per contributing dev | Quote only | Per active committer |
| Published entry price | $950/mo · $27k/yr | Free; Team $25/mo | Free; Pro $1,200/yr | Up to $1,000/dev/yr | Not published | $30/committer/mo |
| Included vs add-on | Applicability is extra | Priced per product | Packs and Firewall | Broad bundle | Not published | Secrets sold apart |
| Scale limits | Consumption-metered | Plan caps | Credit-bounded | No scan caps | Not published | Committers, not scans |
| Scanning depth | CVE, licence, malware | Vulns + licences | Policy + quality data | SCA + SAST + container | Deep licence data | Advisory-based |
| Integrations | IDE, CLI, CI | Git, IDE, CI, registries | Nexus-native | Repos and CI | IDE plus CI | Inside GitHub |
| Governance & SSO | Watches + policies | Policies in PR and CI | Policy engine heritage | Repo-level policy | Project policies | Rulesets |
| India storage region | Mumbai · Pune | No India region | Self-host in India | India region (2026) | On-prem option | GHES on-prem |
| Support | 24/7 SLA | Confirm the SLA | Confirm the SLA | Confirm the SLA | Confirm the SLA | Enterprise support |
| Lock-in & exit | Tied to Artifactory | Registry-neutral | Best with Nexus | Registry-neutral | Tool-neutral | Tied to GitHub |
| Best fit | Artifactory estates | Developer-led teams | Nexus + policy shops | One AppSec bundle | Audit-heavy estates | All-in on GitHub |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
JFrog Xray is one of 35 developer tools products TechBag carries. The Developer Tools guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (releases shipped per year; engineer-hour cost). Estimates model the time spent checking each release's dependencies, licences and SBOM by hand, assuming 1.5 hours per release and that automated scanning removes 70% of it. Both are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Xray has no line-item price. It is not in SaaS Pro ($150/month list); it is included from SaaS Enterprise X (from $950/month, 125 GB/month of storage and transfer included) and self-managed Pro X (from $27,000/year). Advanced Security is a separate quote. TechBag prices the tier step against your usage, then quotes in INR with GST.
Best for cloud-first teams
Best for a broader rollout
Best for on-prem or air-gapped
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
What share of your packages, builds and images actually passes through Artifactory? Everything else is outside Xray's view.
Are you on SaaS Pro? Xray is not included there — what does the Enterprise X or Pro X step add, and do you need it?
Enterprise X includes 125 GB a month of storage and transfer. What does your current usage imply for overage?
Do you need CVE applicability, secrets or SAST? Those are Advanced Security, priced separately per contributing developer.
Which repositories will block downloads, and who approves an exception when a release build is stopped?
Which format do customers or auditors ask for — SPDX, or CycloneDX with VEX — and at build or release level?
If self-hosted and offline, who runs the offline database sync, and how often will it run?
If you choose a Mumbai or Pune SaaS region, is the storage location written into the contract?
Map how much of your estate passes through Artifactory and price the tier step first, or let a TechBag advisor run a trial against your own repositories.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.