Talk to us
by JFrogTechBag Intel Page

JFrog Xray

Your manifest lists what you chose. Your image ships far more — JFrog Xray scans the packages, builds and images stored in Artifactory for CVEs, licences and malware — and blocks the ones that break policy at the registry, before any build can pull them.

Scan the stored artifactBlock at the registryA tier step, not a line item

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
from Enterprise X / Pro X
Tier-gated
Gartner 2026
first SSCS Magic Quadrant
Leader
Coverage
package types, per JFrog
25+
India
SaaS regions, status page
Mumbai · Pune

Quick answer

JFrog Xray is software composition analysis built into Artifactory. It scans the packages, builds and container images you store there for known CVEs, licence violations, malicious packages and operational risk, scans ML models, exports SBOMs, and can block downloads that break policy. It only sees what flows through Artifactory. It is not in SaaS Pro: it comes with SaaS Enterprise X (from $950/month) or self-managed Pro X (from $27,000 a year). Read more ↓ Show less ↑
Part 01 · Orient

The JFrog platform family

This page covers JFrog Xray — software composition analysis on every artifact. The rest:

Quick facts

30-second orientation
Product
Software composition analysis (SCA)
Scans
Packages, builds, container images, ML models
Scope
Only what flows through Artifactory
SBOM
SPDX or CycloneDX, with VEX
Enforcement
Watches can block downloads
Not in
SaaS Pro ($150/month list)
Included from
Enterprise X $950/mo · Pro X $27,000/yr
Gartner 2026
Leader — first SSCS Magic Quadrant
India
Status page: Mumbai (AWS, GCP), Pune (Azure)
In India via
TechBag — INR/GST, scoping and support
Part 02 · Learn

Understand software composition analysis before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is JFrog Xray?

Software composition analysis inside Artifactory — CVEs, licences, malicious packages and operational risk, checked on the artifacts you store.

Scanning in every pipeline vs gating at the registry — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionSCA scripted into every pipelineJFrog Xray
Where scanning happensIn each repo's pipelineOnce, at the registry
What gets scannedDeclared manifestsThe stored artifact and its layers
BlockingA failed job someone rerunsDownload blocked by a watch
SBOMAssembled by hand per releaseExported as SPDX or CycloneDX
LicencesReviewed at audit timeChecked as the package lands
What it is NOT—Not a scanner for anything outside Artifactory

The fastest honest test: index one busy repository and one production image, and see what Xray finds that your manifests never mentioned.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
What gets scanned

Artifactory

The source of truth

Xray indexes what lands in Artifactory — packages, builds, Release Bundles and container images. What never passes through Artifactory, Xray never sees; that is the scope decision.

02
What it knows

Vulnerability data

JFrog's security database

Updated automatically every day, faster during major incidents, with 4M+ open-source packages in the extended database. Air-gapped installs take the same data by offline sync.

03
How it looks

Recursive scan

Layer by layer

Unpacks Docker image layers and nested archives to find the component inside the component — the library in the JAR in the image — and traces which builds carry it.

04
What it does about it

Watches & policies

The enforcement layer

A policy defines the rule; a watch binds it to repositories, builds or Release Bundles. A violation can block the download — including artifacts not yet scanned.

Xray scans what Artifactory holds — then blocks what breaks policy before anyone can download it.

Part 03 · Evaluate

Nine capabilities. Scan, govern, enforce.

Xray scans what your registry actually holds — stored packages, image layers, builds, and the rest of the JFrog platform.

Scan
CVEs

Known vulnerabilities, every artifact

Direct and transitive dependencies checked against JFrog's database, updated daily — so an old artifact is re-flagged when a new CVE lands.

Scan
Containers

Every layer of the image

Recursive analysis of Docker image layers finds the vulnerable library buried in a base image, not just the packages your Dockerfile names.

Scan
Malicious packages

Malware, not just bugs

Flags packages JFrog's research team has identified as malicious — 2,000+ disclosed so far, by JFrog's count — as they land in a repository.

Govern
Licences

Licence compliance by policy

Detects the licence on each component and flags the ones your policy forbids, before a copyleft dependency reaches a shipped release.

Govern
SBOM

SBOMs of what you actually ship

Exports SPDX or CycloneDX for a package, build or release — CycloneDX with VEX from Xray 3.67 — generated from the scanned artifact itself.

Govern
Operational risk

Stale and abandoned packages

Scores components on version age, maintenance cadence, contributor count and end-of-life status — risk that has no CVE attached yet.

Enforce
Block download

Stop it at the registry

A watch can block download of an artifact that breaks policy — or one Xray has not scanned yet — so the build fails, not production.

Enforce
ML models

Models scanned like packages

Model files stored in Artifactory are scanned too; JFrog describes self-managed Pro X as Artifactory plus SCA and model security.

Enforce
Developer

Findings in the IDE and CLI

IDE plugins for VS Code, IntelliJ, Visual Studio and PyCharm, plus JFrog CLI, show the same findings to a developer before a push.

See it, don’t just read it

Watch JFrog Xray in action

What Xray scans, how watches and policies enforce it, and the wider scan beyond CVEs.

JFrog (official)·Overview

Introduction to JFrog Xray

What Xray scans, and where.

JFrog (official)·Policies

Manage security and compliance with JFrog Xray

Watches, policies and licences.

JFrog (official)·Deep dive

Expanding the security frontier with JFrog Xray

Beyond CVEs: the wider scan.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why JFrog Xray

Most scanners read what you declared. Xray reads what you actually ship.

Here’s what genuinely sets it apart — and exactly where it stops.

01

It scans what you ship, not what you declared

Manifest scanners read package.json and pom.xml. Xray reads the binaries and images stored in Artifactory — including the base image and the library nobody declared. The SBOM it exports describes the artifact that shipped, not the one someone intended.

02

Enforcement sits where every build already goes

Every build pulls through the registry, so a policy there applies to every team at once. A watch can block the download of a violating or unscanned artifact — without a scanning step to maintain in fifty separate CI configurations.

03

Its price is a tier, so read the tier

Xray has no line-item price. It is not in SaaS Pro ($150/month list); it arrives with SaaS Enterprise X from $950/month or self-managed Pro X from $27,000 a year. The real question is whether you also need what else that tier brings.

04

Where it stops

Xray only scans what flows through Artifactory: a package pulled straight from the internet, or an image held in another registry, is invisible to it. CVE applicability, secrets detection and SAST belong to Advanced Security, a separate paid add-on.

The idea
Scan the artifact, not the manifest
The gate
Block downloads at the registry
The price
A tier step, not a line item
Proof, not promises

The numbers behind the platform

$950/month
SaaS Enterprise X starting price — the first SaaS tier with Xray
— Vendor
$27000/year
self-managed Pro X starting price — Artifactory plus Xray
— Vendor
25+
package types Xray scans, by JFrog's count
— Vendor
4M+
open-source packages in Xray's extended database
— Vendor
2000+
malicious packages disclosed by JFrog's research team
— Vendor
2026
Gartner MQ for Software Supply Chain Security — Leader, first edition
— Gartner

What your Xray rollout looks like

Week 1Scope

Map what bypasses Artifactory

List the repos, pipelines and registries that never touch Artifactory. Xray cannot see them — that gap is your real coverage.

Week 2Model

Price the tier step

On SaaS Pro, Xray means Enterprise X from $950/month; self-managed, Pro X from $27,000 a year. Price the step, not a line item.

Week 3Pilot

Index and take a baseline

Turn on indexing for a few busy repositories and let Xray scan what is already stored. The first baseline is loud — read it first.

Month 1Tune

Run policies in report mode

Start with violations that notify rather than block. Tune severity, licence and malicious-package rules until developers accept them.

Month 2Enforce

Switch on blocking

Enable Block Download, and Block Unscanned, on the critical repositories first, then widen the watches one repository at a time.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.3
180+ reviews*
86% would recommend
Container scanning4.5
Registry enforcement4.6
Licence compliance4.4
Alert noise3.6
Cost clarity3.7
5★
52%
4★
31%
3★
11%
2★
4%
1★
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
BFSI
“Block Unscanned closed a gap we hadn't noticed: new artifacts were downloadable for minutes before their scan finished.”
DevSecOps Lead
BFSI
SaaS
“The image scan found an old OpenSSL in a base image three teams had inherited. Not one of their manifests mentioned it.”
Platform Engineer
SaaS
E-commerce
“We were on Pro and assumed Xray came with it. It doesn't — budget the Enterprise X step before you plan the rollout.”
Engineering Manager
E-commerce
Manufacturing
“Lots of findings and no applicability context without the add-on. Expect weeks of policy tuning before developers trust it.”
Application Security Engineer
Manufacturing
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the software composition analysis market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Software Composition Analysis Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
JFrog XrayThis page

JFrog is a Leader in Gartner's first SSCS MQ; Xray's scope is the registry.

Grid 02 · The architecture

Artifact Scanning × Developer Workflow

The grid nobody publishes — how deeply a tool scans stored binaries and images vs how deeply it lives in the developer's IDE and pull request.

Code-first scannersFull-lifecycle SCABasic alertingRegistry-bound scanners
JFrog XrayThis page

Scans the stored artifact and blocks it at the registry.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

JFrog Xray vs the SCA field

Against Snyk Open Source, Sonatype Lifecycle / Guide, Mend.io, Black Duck and GitHub Code Security — on scope, deployment, price, enforcement and India.

DimensionJFrog XraySnyk Open SourceSonatype Lifecycle / GuideMend.ioBlack DuckGitHub Code Security
What it isSCA inside the registryDeveloper-first SCAPolicy-led SCAAppSec platform SCAComposition analysisRepo-native SCA
DeploymentSaaS, self-host, air-gapSaaS or private cloudSaaS, cloud or self-hostSaaS-ledSaaS, on-prem, air-gapGitHub.com or GHES
Formats & coverage25+ package typesMajor ecosystemsAsk for the matrixCode + containersSource and binariesGitHub repos only
Pricing modelComes with a tierCredits on EnterpriseCredits via GuidePer contributing devQuote onlyPer active committer
Published entry price$950/mo · $27k/yrFree; Team $25/moFree; Pro $1,200/yrUp to $1,000/dev/yrNot published$30/committer/mo
Included vs add-onApplicability is extraPriced per productPacks and FirewallBroad bundleNot publishedSecrets sold apart
Scale limitsConsumption-meteredPlan capsCredit-boundedNo scan capsNot publishedCommitters, not scans
Scanning depthCVE, licence, malwareVulns + licencesPolicy + quality dataSCA + SAST + containerDeep licence dataAdvisory-based
IntegrationsIDE, CLI, CIGit, IDE, CI, registriesNexus-nativeRepos and CIIDE plus CIInside GitHub
Governance & SSOWatches + policiesPolicies in PR and CIPolicy engine heritageRepo-level policyProject policiesRulesets
India storage regionMumbai · PuneNo India regionSelf-host in IndiaIndia region (2026)On-prem optionGHES on-prem
Support24/7 SLAConfirm the SLAConfirm the SLAConfirm the SLAConfirm the SLAEnterprise support
Lock-in & exitTied to ArtifactoryRegistry-neutralBest with NexusRegistry-neutralTool-neutralTied to GitHub
Best fitArtifactory estatesDeveloper-led teamsNexus + policy shopsOne AppSec bundleAudit-heavy estatesAll-in on GitHub
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose JFrog Xray if…

  • ✓Your packages, builds and images already flow through Artifactory
  • ✓You want policy enforced at the registry, not re-built in every pipeline
  • ✓You need SBOMs of the binaries and images you actually ship

Compare alternatives if…

  • ✓You are on SaaS Pro and SCA alone would force the Enterprise X step
  • ✓Much of your code and packages never pass through Artifactory
  • ✓Fix pull requests in the IDE and PR are the workflow you want first

Do not expect…

  • ✓Findings on anything that never enters Artifactory
  • ✓CVE applicability or secrets detection without Advanced Security
  • ✓A standalone Xray price to negotiate on its own

JFrog Xray is one of 35 developer tools products TechBag carries. The Developer Tools guide narrows them to a shortlist and shows the reasoning. →

Do the math

What does manual release review cost you?

Drag the sliders (releases shipped per year; engineer-hour cost). Estimates model the time spent checking each release's dependencies, licences and SBOM by hand, assuming 1.5 hours per release and that automated scanning removes 70% of it. Both are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual release-review cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Xray has no line-item price. It is not in SaaS Pro ($150/month list); it is included from SaaS Enterprise X (from $950/month, 125 GB/month of storage and transfer included) and self-managed Pro X (from $27,000/year). Advanced Security is a separate quote. TechBag prices the tier step against your usage, then quotes in INR with GST.

SaaS Enterprise X

Best for cloud-first teams

  • From $950/month
  • Xray SCA, SAML/SCIM, 24/7 SLA
  • 125 GB/month consumption included

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

Self-managed Pro X

Best for on-prem or air-gapped

  • From $27,000/year, 1 server
  • Artifactory plus Xray SCA and model security
  • Offline database sync for air-gaps

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Coverage

What share of your packages, builds and images actually passes through Artifactory? Everything else is outside Xray's view.

2
Tier

Are you on SaaS Pro? Xray is not included there — what does the Enterprise X or Pro X step add, and do you need it?

3
Consumption

Enterprise X includes 125 GB a month of storage and transfer. What does your current usage imply for overage?

4
Applicability

Do you need CVE applicability, secrets or SAST? Those are Advanced Security, priced separately per contributing developer.

5
Blocking

Which repositories will block downloads, and who approves an exception when a release build is stopped?

6
SBOM

Which format do customers or auditors ask for — SPDX, or CycloneDX with VEX — and at build or release level?

7
Air-gap

If self-hosted and offline, who runs the offline database sync, and how often will it run?

8
Storage

If you choose a Mumbai or Pune SaaS region, is the storage location written into the contract?

FAQ

Questions buyers ask

JFrog's software composition analysis for the artifacts stored in Artifactory. It checks packages, builds and container images for known CVEs, licence violations, malicious packages and operational risk, scans ML models and exports SBOMs. Policies and watches can block the download of an artifact that breaks the rules.

Ready to evaluate JFrog Xray?

Map how much of your estate passes through Artifactory and price the tier step first, or let a TechBag advisor run a trial against your own repositories.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.