# Migrate from JFrog Xray | 90-day coexistence ladder

> From Xray to Chainsaw in 90 days. Artifactory keeps running. Storage, identity, build promotion, replication untouched. Xray policy surface decommissions on a ladder.

Source: https://chain305.com/migrate/from-jfrog-xray/

---

Migration arc

# From Xray to Chainsaw in 90 days. Artifactory keeps running.

The install-path policy surface moves to Chainsaw one watch and one business unit at a time.

[Book scoping call →](https://cal.com/chain305/30min)

[Why move off Xray →](https://chain305.com/vs-jfrog-xray/)

90-day arc

## Week by week

Xray stays live until each Chainsaw equivalent has been enforcing.

1.  01 · Weeks 1–2
    
    Monitor one BU
    
    Mirrors one Xray watch. Xray enforces.
    
2.  02 · Weeks 3–4
    
    Decision diff
    
    Per-package verdicts side by side. False positives go to Billy.
    
3.  03 · Weeks 5–6
    
    First flip
    
    Chainsaw enforces. Xray drops to monitor.
    
4.  04 · Weeks 7–8
    
    Second BU
    
    The first Xray watch turns off.
    
5.  05 · Weeks 9–10
    
    K8s admission
    
    Gatekeeper package policies move into the signed Rego bundle.
    
6.  06 · Weeks 11–12
    
    Roll forward
    
    Remaining BUs onboard. Xray watches ladder off.
    

Rollback, any week, any BU. One Rego edit returns Chainsaw to monitor. Xray policies are not yet retired at that point in the ladder, so the prior enforcement state stays live.

Decommission ladder

## When each Xray watch comes off

Xray watch

Chainsaw equivalent

Target week

Vulnerabilities watch

Chainsaw CVE rule + 25-signal compound rules

6

License watch

Chainsaw license rule, same Rego

6

Operational-risk watch

Chainsaw publish-velocity, very-new-package and abandoned-repo signals

8

Custom policy

Customer Rego in signed policy bundle

10

Build-scan integration

Chainsaw install + publish gate with same Rego

10

Scope

## What gets touched. What does not.

Install-path routing in front of Artifactory

Touched

Xray watches

Mirrored, then laddered off

Xray policies

Re-expressed in Rego

K8s Gatekeeper / OPA package-admission policies

Touched

CI policy gates that call Xray

Touched

Artifactory storage, identity, namespacing

Not touched

Build promotion

Not touched

Replication and JFrog Distribution edges

Not touched

Existing webhook destinations

Not touched

Xray audit history

Exports preserved

Xray-licensed seats

Roll forward through the renewal

Renewal just signed?

## The 90-day arc preserves it.

Watches retire one at a time, only after their Chainsaw equivalents have been in enforce for two weeks. Before the scoping call you get a reference architecture, a decision-diff template, sample Rego rules, the watch-to-rule mapping and a rollback runbook.

[Book scoping call](https://cal.com/chain305/30min) [Download joint-evaluation kit (gated)](https://chain305.com/security/procurement/)

---

## Long form

The full text behind this page, including detail the page itself leaves out.

Migration arc

### From Xray to Chainsaw in 90 days. Artifactory keeps running.

Storage, identity, build promotion, replication — untouched. The install-path policy surface moves to Chainsaw on a ladder, one watch and one business unit at a time. Any week, any BU rolls back with a single Rego edit.

[Book scoping call →](#scoping)

[Why move off Xray →](https://chain305.com/vs-jfrog-xray/)

Scope

#### What gets touched. What does not.

Touched

-   Install-path routing in front of Artifactory.
-   Xray watches (mirrored, then laddered off).
-   Xray policies (re-expressed in Rego).
-   K8s Gatekeeper / OPA policies for package admission.
-   CI policy gates that today call Xray.

Not touched

-   Artifactory storage layer.
-   Artifact identity and namespacing.
-   Build promotion workflow.
-   Replication and JFrog Distribution edges.
-   Existing webhook destinations.

90-day arc

#### Week-by-week

Capability

Xray Existing policy surface

Chainsaw Install-path refusal

Week 1–2 · Monitor in front of one BU Chainsaw deployed in front of Artifactory for a single business unit. Monitor mode. Mirrors one existing Xray watch — same packages, same policy intent.

Xray enforce

Chainsaw monitor (mirrored watch)

Week 3–4 · Side-by-side decision diff Dashboard surfaces per-package verdicts from Xray and Chainsaw. False positives flow through Billy approval queue. Rules tuned via Bayesian feedback.

Xray enforce

Chainsaw monitor + diff

Week 5–6 · First flip Flip the mirrored watch: Chainsaw enforce on the install path, Xray drops to monitor on the same signals.

Xray monitor

Chainsaw enforce

Week 7–8 · Second BU + retire first Xray watch Extend to BU #2. Turn off the original Xray watch — it has been redundant for two weeks.

Xray watch off (BU #1)

Chainsaw enforce (BU #1 + BU #2)

Week 9–10 · K8s admission migrated Gatekeeper / OPA policies for package admission re-expressed in the same signed Rego bundle. One policy across PR, install, publish, admission, runtime; one audit row from install on, where the decision reaches the server.

Gatekeeper retired for package policies

Chainsaw same-Rego admission

Week 11–12 · Roll forward Remaining BUs onboard on the same template. Xray watches ladder off as their Chainsaw equivalents reach enforce.

Xray watches laddered off

Chainsaw across every BU

Decommission ladder

#### Xray watch → Chainsaw equivalent → when it comes off

Capability

Xray construct What is in place today

Chainsaw equivalent With decommission target

Vulnerabilities watch CVE-driven block / warn on cached artifacts.

Xray vulnerabilities watch

Chainsaw CVE rule + 25-signal compound rules. Decommission target: week 6.

License watch License-policy enforcement.

Xray license watch

Chainsaw license rule, same Rego. Decommission target: week 6.

Operational-risk watch Maintainer activity, package age, abandonment heuristics.

Xray operational-risk watch

Chainsaw publish-velocity, dormant-wake, first-publish risk signals. Decommission target: week 8.

Custom policy Bespoke org rules layered on Xray.

Xray custom policy

Customer Rego in signed policy bundle. Decommission target: week 10.

Build-scan integration Scan-on-build gate inside Artifactory build info.

Xray build-scan

Chainsaw install + publish gate with same Rego. Decommission target: week 10.

Rollback path

#### Any week, any BU.

Chainsaw carries a monitor-only flag per BU and per rule. Flipping it returns Chainsaw to passive observer; Xray policies have not been retired yet at that point in the ladder, so the prior enforcement state remains live. The rollback is a single Rego edit on the signed policy bundle. No redeploy, no artifact moves.

Preserved investment

#### What you do not lose.

-   **Artifactory storage, identity, replication.** Continue as-is.
-   **Existing Xray-licensed seats.** Roll forward through the renewal — the storage-tier value is intact while the policy surface migrates.
-   **Audit history.** Exports from Xray are preserved alongside the new signed audit row Chainsaw writes from week 1.
-   **Build promotion.** Untouched; Chainsaw evaluates on install, not on promotion.

Joint-evaluation kit

#### What lands in your inbox before the scoping call.

-   Reference architecture: Chainsaw in front of Artifactory, one org-wide policy across BUs.
-   Side-by-side decision diff template (per-package Xray verdict vs Chainsaw verdict).
-   Sample Rego rules — CVE, license, install-script exfiltration, maintainer takeover, publish-velocity.
-   Mapping doc: Xray watch type → Chainsaw rule, with decommission week.
-   Rollback runbook.

Renewal just signed?

#### The 90-day arc preserves it.

Chainsaw runs in front of Artifactory while Xray stays live. The decommission ladder retires watches one at a time, only after their Chainsaw equivalents have been in enforce for two weeks. Artifactory storage and identity remain on JFrog.

[Book scoping call](https://chain305.com/chainsaw/signup) [Download joint-evaluation kit (gated)](https://chain305.com/security/procurement/)
