Notifications
Clear all
Topic starter
07/08/2026 7:25 pm
I've been looking into JFrog Xray for scanning our Artifactory repositories. We're a small team, and the promise of automated CVE detection sounds great, but I'm a bit skeptical.
For those using it in production, does it actually catch real vulnerabilities effectively? I'm especially curious about:
* False positives – do you get a lot of noise?
* How well does it handle transitive dependencies in Java or npm packages?
* Is the default configuration good enough, or does it need heavy tuning?
I'd love to hear about your actual experience with its findings versus just trusting the marketing.