CVE Binary Tool vs JFrog Xray
| CVE Binary Tool | JFrog Xray | |
|---|---|---|
| Free plan | No | No |
| Free trial | No | No |
| Paid from | — | — |
| Open source | No | No |
| Platforms | Linux, Windows | Web |
| Free plan | Yes | No |
| Supported ecosystems | Dart (pubspec.lock); Go (go.mod); Java (pom.xml, JAR/WAR/EAR); JavaScript (package-lock.json, yarn.lock); OpenWrt opkg (.control); Perl (cpanfile); Python (requirements.txt, PKG-INFO, METADATA, .whl, .egg); Rust (Cargo.lock); Ruby (Gemfile.lock); R (renv.lock); Swift (Package.resolved); Windows PE (.pyd) | Go, PHP, Java/Maven, Java/Gradle, Java/Ivy, Scala/SBT, JavaScript/npm, Bower, pnpm, Yarn, .NET/NuGet, Python/PyPI, Conda, RubyGems, CocoaPods, Conan, Rust/Cargo, R/CRAN, Swift/SwiftPM, Dart/Flutter/pub, Docker, OCI, Helm, Terraform State |
| SBOM generation | Yes | Yes |
| Pull request scanning | Yes | Yes |
| Deployment options | self_hosted | — |
| Reachability analysis | — | Yes |
| Monitored projects | — | 30 projects |
Both are listed in Best Software Composition Analysis Software. On Samsung Mobile US Press, CVE Binary Tool scores higher on our published basis.