JFrog Xray and Legit Security compete in the security and vulnerability management category. JFrog Xray integrates robustly with DevOps tools, while Legit Security takes a more holistic approach with its infrastructure and code security. Each has strengths and addresses different aspects based on user needs.
Features: JFrog Xray provides comprehensive artifact scanning, deep CI/CD tool integration, and prioritization of vulnerabilities. Its integration with Artifactory allows seamless onboarding and management of dependencies. Legit Security offers continuous security policy monitoring, visibility across the development environment, and integration with multiple tools like GitHub and Jenkins, enhancing its infrastructure security.
Room for Improvement: JFrog Xray could benefit from enhancing its user interface and extending support for more external tools beyond Artifactory. Users have indicated room for improving its scanning speed and reducing false positives. Legit Security can improve its secret detection feature, experiencing a 10-20% false-positive rate. Streamlining the integration process further and enhancing the analysis of unmaintained repositories would help bolster its offering.
Ease of Deployment and Customer Service: JFrog Xray enables efficient deployment within DevOps pipelines with clear documentation and reliable support for troubleshooting. Legit Security provides adaptable deployment options catering to different environments, with a focus on proactive, personalized customer service for an enhanced customer experience.
Pricing and ROI: JFrog Xray offers a competitive structure with lower upfront costs, appealing for budget-conscious users, enhancing ROI by saving time in vulnerability management. Although Legit Security may involve higher initial costs, it provides considerable ROI through extensive security functionality and risk reduction.
JFrog is on a mission to enable continuous updates through Liquid Software, empowering developers to code high-quality applications that securely flow to end-users with zero downtime. The world’s top brands such as Amazon, Facebook, Google, Netflix, Uber, VMware, and Spotify are among the 4500 companies that already depend on JFrog to manage binaries for their mission-critical applications. JFrog is a privately-held, global company, and is a proud sponsor of the Cloud Native Computing Foundation [CNCF].
If you are a team player and you care and you play to WIN, we have just the job you're looking for.
As we say at JFrog: "Once You Leap Forward You Won't Go Back!"
Legit Security provides application security posture management platform that secures application delivery from code to cloud and protects an organization's software supply chain from attack. The platform’s unified application security control plane and automated SDLC discovery and analysis capabilities provide visibility and security control over rapidly changing environments and allow security issues to be prioritized based on context and business criticality to improve security team efficiency and effectiveness.
We monitor all Software Supply Chain Security reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.