JFrog Xray vs Trivy comparison

Cancel
You must select at least 2 products to compare!
JFrog Logo
2,360 views|1,731 comparisons
100% willing to recommend
Aqua Security Logo
503 views|493 comparisons
Comparison Buyer's Guide
Executive Summary

We performed a comparison between JFrog Xray and Trivy based on real PeerSpot user reviews.

Find out what your peers are saying about Palo Alto Networks, Wiz, Microsoft and others in Container Security.
To learn more, read our detailed Container Security Report (Updated: April 2024).
771,157 professionals have used our research since 2012.
Featured Review
report
Use our free recommendation engine to learn which Container Security solutions are best for your needs.
771,157 professionals have used our research since 2012.
Questions from the Community
Top Answer:JFrog Xray shows us a list of vulnerabilities that can impact our code.
Top Answer:There is a tool called DefectDojo for reporting. Reporting is crucial, but it is lacking in the current tool. Every organization seeks specific data points rather than general information. Therefore… more »
Top Answer:We use this solution to identify vulnerabilities in the dependency file. We have the Artifactory package which integrates with Xray-like plugins. We can automatically plug this tool into Xray to… more »
Ask a question

Earn 20 points

Ranking
18th
out of 59 in Container Security
Views
2,360
Comparisons
1,731
Reviews
6
Average Words per Review
495
Rating
8.2
31st
out of 59 in Container Security
Views
503
Comparisons
493
Reviews
0
Average Words per Review
0
Rating
N/A
Comparisons
Black Duck logo
Compared 29% of the time.
Snyk logo
Compared 10% of the time.
Mend.io logo
Compared 8% of the time.
Veracode logo
Compared 8% of the time.
Kubescape logo
Compared 17% of the time.
SUSE NeuVector logo
Compared 9% of the time.
Veracode logo
Compared 8% of the time.
Also Known As
JFrog Security Essentials
Learn More
Overview

JFrog is on a mission to enable continuous updates through Liquid Software, empowering developers to code high-quality applications that securely flow to end-users with zero downtime. The world’s top brands such as Amazon, Facebook, Google, Netflix, Uber, VMware, and Spotify are among the 4500 companies that already depend on JFrog to manage binaries for their mission-critical applications. JFrog is a privately-held, global company, and is a proud sponsor of the Cloud Native Computing Foundation [CNCF].

If you are a team player and you care and you play to WIN, we have just the job you're looking for.

As we say at JFrog: "Once You Leap Forward You Won't Go Back!"​

Trivy is the most popular open source security scanner, reliable, fast, and easy to use. Use Trivy to find vulnerabilities & IaC misconfigurations, SBOM discovery, Cloud scanning, Kubernetes security risks,and more.

Sample Customers
google, amazon, cisco, netflix, oracle, vmware, facebook
Information Not Available
Top Industries
VISITORS READING REVIEWS
Financial Services Firm24%
Manufacturing Company15%
Computer Software Company12%
Insurance Company5%
VISITORS READING REVIEWS
Computer Software Company20%
Financial Services Firm12%
Manufacturing Company11%
Government7%
Company Size
REVIEWERS
Midsize Enterprise29%
Large Enterprise71%
VISITORS READING REVIEWS
Small Business14%
Midsize Enterprise10%
Large Enterprise76%
VISITORS READING REVIEWS
Small Business24%
Midsize Enterprise15%
Large Enterprise61%
Buyer's Guide
Container Security
April 2024
Find out what your peers are saying about Palo Alto Networks, Wiz, Microsoft and others in Container Security. Updated: April 2024.
771,157 professionals have used our research since 2012.

JFrog Xray is ranked 18th in Container Security with 7 reviews while Trivy is ranked 31st in Container Security. JFrog Xray is rated 8.2, while Trivy is rated 0.0. The top reviewer of JFrog Xray writes "An intelligent solution that prioritizes which vulnerability to target first in your project". On the other hand, JFrog Xray is most compared with Black Duck, Snyk, Mend.io, Veracode and Fortify Static Code Analyzer, whereas Trivy is most compared with Kubescape, SUSE NeuVector, Veracode, Tenable.io Container Security and Microsoft Defender for Cloud.

See our list of best Container Security vendors.

We monitor all Container Security reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.