Skip to content
Notifications
Clear all

Anchore vs Xray - real-world numbers from our PoC

1 Posts
1 Users
0 Reactions
18 Views
(@backend_builder)
Prominent Member
Joined: 6 months ago
Posts: 605
Topic starter   [#28387]

We just wrapped up a six-week proof of concept comparing JFrog Xray and Anchore Enterprise for container vulnerability scanning in our CI/CD pipeline. We're a Python/Go shop running on Kubernetes, and we needed something that could integrate cleanly, give us actionable results, and not cripple deployment velocity. I want to share the raw performance and operational numbers we saw, because the docs from both vendors are… optimistic.

Our testbed was a mid-sized pipeline pushing ~50 unique images daily. We integrated both tools as a step in our GitLab CI, scanning images right after build. Here's the config snippet for Xray's scan step:

```yaml
scan_image_xray:
stage: security_scan
image: curlimages/curl:latest
script:
- |
curl -H "X-JFrog-Art-Api: $ARTIFACTORY_API_KEY"
-X POST "https://your-instance.jfrog.io/xray/api/v1/scan/build"
-H "Content-Type: application/json"
-d '{"buildName": "$CI_PROJECT_NAME", "buildNumber": "$CI_PIPELINE_IID"}'
```

**Key Findings:**

* **Scan Latency:** Anchore averaged **4.2 seconds** per image for the initial scan. Xray, because it leans on Artifactory, took **~8-9 seconds** on average. However, Xray's incremental scan on unchanged layers was near-instant.
* **Database & Caching:** Anchore's PostgreSQL instance required more frequent tuning for the vulnerability data updates. Xray's use of its own internal DB felt more opaque but was hands-off. Cache performance was critical for us; Redis for our own app data made the Xray integration slightly more complex.
* **Actionability:** Anchore's policy bundles were more flexible for our custom compliance rules. Xray's policies were easier to set up but felt more "all-or-nothing" for blocking deployments.
* **Cost:** This is the big one. Anchore's pricing per node was predictable. Xray's pricing model, based on Artifactory storage + scan volume, got murky fast as our artifact repository grew.

Ultimately, we valued the deep integration with our existing Artifactory setup, but the performance hit and cost uncertainty with Xray gave us pause. For teams already all-in on the JFrog ecosystem, Xray is a logical fit. For those needing granular policy control and predictable per-node costs, Anchore is a strong contender.

What have others seen in production? Especially around scaling to thousands of images and the operational overhead of the database layer for each tool?

--builder


Latency is the enemy, but consistency is the goal.


   
Quote