APPSEC / JFrog

JFrog Xray, Advanced Security, and Curation

JFrog centers security on the artifact registry. Xray provides dependency analysis on artifacts already in Artifactory. Advanced Security is a documented add-on with Enterprise X or Enterprise+ that adds contextual analysis, SAST, secrets, and infrastructure as code. Curation addresses package intake. The teaching choice is registry admission and artifact context, not an IDE-first scanner.

Artifact-registry securityResearch reviewed

What you are evaluating

What Artifactory and Xray already cover, Advanced Security add-on entitlements, repository policy latency, and metadata or source handling must be confirmed. Registry policy is not builder isolation, and a signature elsewhere does not replace Xray's artifact analysis.

A useful evaluation context

A plausible evaluation context is an organization that already runs Artifactory and must distinguish Xray, Advanced Security add-on entitlements, and Curation policy latency.

Documented capabilities

The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.

  • Xray dependency analysis on artifacts stored in Artifactory.
  • Advanced Security add-on, documented with Enterprise X or Enterprise+, adding contextual analysis, SAST, secrets, and infrastructure as code.
  • Curation and repository policy for package intake before artifacts become generally available to builds.

Where it fits in the work

  1. Inventory what Xray already does on the Artifactory instance, then enable Advanced Security only if that add-on is entitled.
  2. Place a lab artifact with a seeded vulnerable dependency and, if testing Curation, a package that policy should block at intake.
  3. Measure whether policy and scan results arrive before developers consume the artifact, and retain metadata about source and digest.

APPLY THE IDEA / ILLUSTRATIVE EXERCISE

Make the outcome observable.

In a lab Artifactory you own, publish an artifact that depends on a pinned vulnerable library. If Curation is entitled, attempt to ingest a package that policy should reject. Enable Advanced Security only if licensed.

Evidence to look for

Xray reports the dependency on the stored artifact, Curation blocks or allows according to the lab policy, Advanced Security findings appear only when the add-on is entitled, and production repositories remain untouched.

Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.

Questions for your evaluation

  1. What does Xray already cover on this Artifactory instance without Advanced Security?
  2. Is the Advanced Security add-on entitled under Enterprise X or Enterprise+, and which of SAST, secrets, and infrastructure as code are included?
  3. How long after a package is ingested does Curation or Xray policy actually block or alert, and what source metadata is retained?

Names you may encounter: JFrog Xray · JFrog Advanced Security · JFrog Curation. Historical names do not establish current availability or feature equivalence.

Find your next idea.

Tip: press / to open search. Escape closes this window.