What you are evaluating
What Artifactory and Xray already cover, Advanced Security add-on entitlements, repository policy latency, and metadata or source handling must be confirmed. Registry policy is not builder isolation, and a signature elsewhere does not replace Xray's artifact analysis.
A useful evaluation context
A plausible evaluation context is an organization that already runs Artifactory and must distinguish Xray, Advanced Security add-on entitlements, and Curation policy latency.
Documented capabilities
The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.
- Xray dependency analysis on artifacts stored in Artifactory.
- Advanced Security add-on, documented with Enterprise X or Enterprise+, adding contextual analysis, SAST, secrets, and infrastructure as code.
- Curation and repository policy for package intake before artifacts become generally available to builds.
Where it fits in the work
- Inventory what Xray already does on the Artifactory instance, then enable Advanced Security only if that add-on is entitled.
- Place a lab artifact with a seeded vulnerable dependency and, if testing Curation, a package that policy should block at intake.
- Measure whether policy and scan results arrive before developers consume the artifact, and retain metadata about source and digest.
APPLY THE IDEA / ILLUSTRATIVE EXERCISE
Make the outcome observable.
In a lab Artifactory you own, publish an artifact that depends on a pinned vulnerable library. If Curation is entitled, attempt to ingest a package that policy should reject. Enable Advanced Security only if licensed.
Evidence to look for
Xray reports the dependency on the stored artifact, Curation blocks or allows according to the lab policy, Advanced Security findings appear only when the add-on is entitled, and production repositories remain untouched.
Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.
Questions for your evaluation
- What does Xray already cover on this Artifactory instance without Advanced Security?
- Is the Advanced Security add-on entitled under Enterprise X or Enterprise+, and which of SAST, secrets, and infrastructure as code are included?
- How long after a package is ingested does Curation or Xray policy actually block or alert, and what source metadata is retained?
Names you may encounter: JFrog Xray · JFrog Advanced Security · JFrog Curation. Historical names do not establish current availability or feature equivalence.