Positioning
Keep Artifactory. Move the refusal.
Xray inspects what Artifactory has already cached. Chainsaw refuses on the install path, before the cache.
Peer framing
What stays. What moves.
Chainsaw replaces one layer: the policy seam in front of Artifactory. Storage stays.
-
01 · Developer or CI
npm install -
02 · Chainsaw (new, in front)
- refuses on the install path
- writes a signed audit row
-
Refused
never cached
Allowed
fetched into Artifactory (unchanged), served on the same URL
Structural diff
Where the two products draw the line
| Capability | JFrog Xray Policy layer on cached artifacts | Chainsaw Install-path refusal |
|---|---|---|
| Enforcement point | After the artifact reaches the cache. | Before the cache. A refused artifact is never resident. |
| Signal coverage | CVE feeds, license metadata, operational-risk heuristics. | CVE + license + 25 supply-chain signals. |
| Federation model | Per Artifactory instance; cross-BU consolidation is operational. | One org-wide policy set, repository-scoped rules, one audit stream. |
| Kubernetes admission | Separate Gatekeeper / OPA integration. | Same Rego at the PR check, install, publish, K8s admission, runtime. The PR check reads a dependency diff, so byte-level rules apply from install on. |
| AI coding-agent path | No native MCP surface. | MCP server exposes refusal + the Billy approval queue. |
| Air-gapped intel bundle | Manual feed updates. | Signed Sigstore bundle, hot-swappable. |
| False-positive loop | Manual policy edit; ticket round-trip. | Billy approval queue captures the override. |
Named signals
Supply-chain signals beyond CVE and license
Named by registry ID, so they can be argued with.
| Install script fetches remote content | The install or postinstall script pulls remote content at install time. sc.install_script_fetches_remote |
|---|---|
| Encoded eval in install script | An obfuscated or encoded payload decoded and executed during install. sc.install_script_eval_encoded |
| Publisher changed | The maintainer set differs from the previous version: the common shape of account takeover. sc.publisher_changed |
| Young maintainer account | The youngest maintainer account is under 90 days old. sc.maintainer_account_young |
| Shell access appeared | This version spawns a shell and the previous scanned version did not. sc.shell_access_appeared |
| Hidden Unicode | Invisible or bidirectional Unicode that can hide code from review. sc.hidden_unicode |
| Typosquat | The name is highly similar to a popular package. sc.typosquat_high |
| Publish-velocity anomaly | A publisher set pushed unusually many releases in 24 hours: the Shai-Hulud worm shape. sc.publish_velocity_anomaly |
| Manifest confusion | The registry's package.json and the tarball's package.json disagree. sc.manifest_confusion |
| Repo ownership mismatch | The advertised source repo belongs to a different account than the publisher. sc.repo_ownership_mismatch |
| Transitive malware | A package deeper in the dependency closure is on the known-malicious index. sc.transitive_malware |
| Provenance and signature | Verifiable Sigstore/SLSA provenance, and a signature checked against an independent trust root. sc.provenance_verified · sc.signature_verified |
| Dangerous pickle opcode | Model weights reference os, subprocess or eval. Loading the file runs code. ai.dangerous_pickle_opcode |
| Unverified MCP server | Declares an MCP server without provenance or a verified source repo. ai.mcp_server_unverified |
| Unpinned Action ref | A GitHub Action referenced by branch or tag instead of a commit SHA. action.unpinned_ref |
| Very new package | Under 30 days old, with few versions. maint.very_new_package |
Where Xray still wins
Keep Xray for these.
| Build promotion | Deeply integrated with the Artifactory artifact lifecycle. |
|---|---|
| Artifact lifecycle depth | Retention, staging and release-bundle plumbing. |
| JFrog Distribution | Edge replication for binary distribution at scale. |
| Generic-repo coverage | Generic binary repos beyond language packages. |
Just renewed Xray?
You do not have to rip it out.
Xray policies stay live through a 90-day side-by-side, then come off one watch at a time. Artifactory storage untouched.