Hi everyone 👋 I'm still pretty new to the DevOps world, coming from a sysadmin background. We're currently using Docker and some basic Kubernetes, and we're looking to step up our container security scanning.
We've narrowed it down to JFrog Xray (since we're already on Artifactory) and Snyk. Our shop is mid-size, maybe 15 DevOps/engineers, and we need something that won't be a nightmare to manage.
Can anyone share their real-world experience? I'm especially curious about:
- How easy it is to integrate with a CI/CD pipeline (we use GitLab)
- The learning curve for the team
- Which one gives clearer, actionable results for fixing vulnerabilities
I've read the docs, but hearing from people who've used both would be super helpful. Thanks in advance!