
Cloudsmith
Artifactory
Sonatype Nexus Repository
packagecloud
Gemfury
CloudRepo
GitHub Actions
AWS CodeArtifact
Craftifact
Sonatype Nexus Repository
Artifactory
AWS CodeArtifact
Cloudsmith is a single source of truth for all your software assets, available to teams, individuals, customers and build processes anywhere on the planet. Cloudsmith is the only cloud-native, universal package management solution, allowing your organization to create, store and share packages in any format, to any place, with total confidence.
Craftifact is a European artifact repository SaaS for teams that need reliable package repositories and better visibility across their software supply chain.
It provides a central place to store, version, and distribute build artifacts across development, CI/CD, and deployment workflows. Beyond repository hosting, Craftifact connects package repositories with SBOMs, vulnerability findings, access controls, and policy signals so teams can make artifact-related security and compliance work more visible and repeatable.
The platform is especially relevant for teams preparing for CRA-related software supply chain requirements, including workflows around artifacts, SBOMs, vulnerability handling, access control, and operational evidence. Craftifact does not try to replace a full enterprise governance stack; it focuses on the repository layer where many of these signals originate or need to be tied together.
Craftifact is developed and operated in Europe, with attention to data protection, operational simplicity, predictable usage, and reduced vendor lock-in for modern engineering teams.
Cloudsmith
CraftifactNo Craftifact videos yet. You could help us improve this page by suggesting one.
Craftifact's answer:
Craftifact combines artifact repository hosting with software supply chain context.
Instead of treating package repositories as isolated storage, Craftifact connects artifacts with SBOMs, vulnerability findings, access control, and policy signals. This helps engineering teams understand not only where artifacts are stored, but also what security and compliance-relevant information is attached to them.
The product is built and operated in Europe, with a focus on secure defaults, operational simplicity, predictable pricing, and workflows that support CRA-relevant software supply chain work.
Craftifact's answer:
Teams should consider Craftifact when they want an artifact repository that is easier to operate than a large enterprise repository stack, but still supports modern software supply chain requirements.
Craftifact is a good fit for teams that need package repositories, SBOM handling, vulnerability visibility, access control, and CRA-relevant workflows in one repository-centered product. It is designed for engineering teams that want practical security and compliance visibility without adding unnecessary platform complexity.
It is also relevant for European teams that care about data protection, predictable pricing, and reducing dependency on large proprietary repository ecosystems.
Craftifact's answer:
Craftifact is built for software engineering, DevOps, platform engineering, and security teams that manage build artifacts across development, CI/CD, and deployment workflows.
The primary users are teams that need reliable package repositories, but also need better visibility into the software supply chain around those artifacts. This includes teams preparing for CRA-related requirements, teams working with SBOMs, and teams that want clearer links between repositories, vulnerabilities, access control, and policy evidence.
Craftifact is especially relevant for modern engineering organizations that want a focused repository layer rather than a large, complex enterprise artifact management platform.
Craftifact's answer:
Craftifact was created to give engineering teams a focused European alternative for managing software artifacts and related supply chain information.
Many artifact repository systems started as storage and distribution tools. Modern teams now need more than that: they need to understand which artifacts exist, where they are used, what vulnerabilities affect them, who can access them, and what evidence is available for security and regulatory workflows.
Craftifact focuses on this repository layer and connects it with SBOMs, vulnerability visibility, access control, and CRA-relevant workflows. The goal is to make artifact management simpler, more transparent, and more useful for teams that need secure software delivery without unnecessary enterprise complexity.
Based on our record, Cloudsmith seems to be more popular. It has been mentiond 2 times since March 2021. We are tracking product recommendations and mentions on various public social media platforms and blogs. They can help you identify which product is more popular and what people think of it.
Now, well beyond the fall of Newzbin, and with a stint in corporate land, security, and fintech, Iโm co-founder and CTO of Cloudsmith (website). We use our unique blend of cloud-native artifact management to secure the software supply chain for some of the biggest companies in the world. Weโve raised serious capital for a serious platform. And we started it from Belfast. - Source: dev.to / over 1 year ago
Linus Torvalds about this: https://www.youtube.com/watch?v=Pzl1B7nB9Kc Distros (Debian in particular comes to mind) have some really annoying packaging rules, and as a maintainer of a Go program, it's a huge pain, so we decided to just set up a repo with https://cloudsmith.com/ instead of trying to deal with that. They require every dependency (indirect or not) to be packaged separately. We don't have the time for... - Source: Hacker News / over 4 years ago
Artifactory - The worldโs most advanced repository manager.
Sonatype Nexus Repository - The world's only repository manager with FREE support for popular formats.
packagecloud - Free hosted Node.js, Debian, RPM, Java, Python and RubyGem repositories. Chef, Puppet, Jenkins, Buildkite, CircleCI and Travis CI integrations.
AWS CodeArtifact - DevOps, Build, Test, Deploy, and Hosted Package Repository
Gemfury - Gemfury is a hosted repository for your public and private packages, where they are safe and within reach.
CloudRepo - Public and Private Maven and Python (PyPi) repository package manager.