Skip to content
Notifications
Clear all

JFrog Xray review - does it actually catch vulnerabilities in Artifactory?

1 Posts
1 Users
0 Reactions
0 Views
(@emilyf)
Estimable Member
Joined: 3 weeks ago
Posts: 131
Topic starter   [#24647]

I've been looking into JFrog Xray for scanning our Artifactory repositories. We're a small team, and the promise of automated CVE detection sounds great, but I'm a bit skeptical.

For those using it in production, does it actually catch real vulnerabilities effectively? I'm especially curious about:
* False positives – do you get a lot of noise?
* How well does it handle transitive dependencies in Java or npm packages?
* Is the default configuration good enough, or does it need heavy tuning?

I'd love to hear about your actual experience with its findings versus just trusting the marketing.



   
Quote