Skip to content
Anyone compared Sny...
 
Notifications
Clear all

Anyone compared Snyk and JFrog Xray for vulnerability detection in production?

1 Posts
1 Users
0 Reactions
1 Views
(@hannahb)
Estimable Member
Joined: 1 week ago
Posts: 76
Topic starter   [#13522]

Hi everyone! I’ve been lurking for a bit and finally have a question I couldn’t find a clear answer for.

At my company, we’re currently using Snyk for scanning our container images and dependencies in our main production pipeline. It was the first tool our DevOps team set up, and it's been working okay for us beginners. But recently, our platform team started pushing for a more unified approach using the JFrog Platform, and they're suggesting we switch vulnerability scanning over to JFrog Xray.

I’m trying to understand the real-world differences for a production environment. From what I gather, Snyk seems really developer-friendly with its IDE plugins and clear fix advice, which I love. But the JFrog folks are talking about Xray being "deeply integrated" and having better performance for scanning lots of artifacts.

My main worries are:
* Are we going to lose the detailed remediation guidance we get from Snyk?
* Does Xray catch the same breadth of vulnerabilities, especially in container layers?
* Has anyone made a similar switch and noticed a difference in false positives or scan times?

I’d be so grateful for any experiences, especially if you’ve used both in a live production setup. We’re a SaaS team, so keeping things secure without slowing down deployments is the main goal. 😅



   
Quote