Try our new research platform with insights from 80,000+ expert users

JFrog Xray vs Semgrep comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

JFrog Xray
Ranking in Software Composition Analysis (SCA)
7th
Average Rating
8.2
Number of Reviews
7
Ranking in other categories
Vulnerability Management (20th), Container Security (20th), Software Supply Chain Security (3rd)
Semgrep
Ranking in Software Composition Analysis (SCA)
16th
Average Rating
0.0
Number of Reviews
0
Ranking in other categories
Static Application Security Testing (SAST) (34th), Supply Chain Management Software (27th), Static Code Analysis (10th)
 

Featured Reviews

HS
Feb 21, 2024
A stable solution to identify vulnerabilities with embedded rules
JFrog Xray has many policies, settings, and rules embedded. JFrog's Artifactory contains all the dependency files. For instance, if a team is developing an application using Java, they might require certain dependency files. They can obtain all the artifacts from JFrog's Artifactory without accessing the internet, which securely stores these files. The application can retrieve the necessary files from there. Xray is a tool designed to ensure that all artifacts within JFrog's Artifactory are clean. It scans for vulnerabilities and flags them. Based on predefined rules that could potentially harbor vulnerabilities, the Accelerator tool notifies the development team, enabling them to review and fix any issues in the library.
Use Semgrep?
Share your opinion

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
report
Use our free recommendation engine to learn which Software Composition Analysis (SCA) solutions are best for your needs.
801,394 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
24%
Manufacturing Company
15%
Computer Software Company
13%
Government
5%
Financial Services Firm
23%
Computer Software Company
16%
Manufacturing Company
8%
Government
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

What do you like most about JFrog Xray?
JFrog Xray shows us a list of vulnerabilities that can impact our code.
What needs improvement with JFrog Xray?
There is a tool called DefectDojo for reporting. Reporting is crucial, but it is lacking in the current tool. Every organization seeks specific data points rather than general information. Therefor...
What is your primary use case for JFrog Xray?
We use this solution to identify vulnerabilities in the dependency file. We have the Artifactory package which integrates with Xray-like plugins. We can automatically plug this tool into Xray to co...
Ask a question
Earn 20 points
 

Comparisons

 

Also Known As

JFrog Security Essentials
Semgrep Code, Semgrep Supply Chain, Semgrep AppSec Platform
 

Learn More

 

Overview

 

Sample Customers

google, amazon, cisco, netflix, oracle, vmware, facebook
Policygenius, Tide, Lyft, Thinkific, FloQast, Vanta, and Fareportal
Find out what your peers are saying about Synopsys, Veracode, Snyk and others in Software Composition Analysis (SCA). Updated: August 2024.
801,394 professionals have used our research since 2012.