JFrog Xray integrates with JFrog Artifactory to scan software artifacts and dependencies for security vulnerabilities and license compliance issues. It provides deep recursive scanning of components, including those within Docker images and zip files, and leverages a comprehensive vulnerability database from multiple sources such as NVD, GitHub, and the JFrog Security Research Team. Xray offers real-time alerts, impact analysis, and detailed reporting to help organizations maintain compliance and address security risks proactively. It also supports advanced features like container contextual analysis, detection of exposed secrets, and securing Infrastructure-as-Code files, while integrating with CI/CD tools and build servers to automate security checks and fail builds when vulnerabilities are detected.