We adopted Cloudsmith as a modern, cloud‑native replacement for Artifactory to improve our software supply‑chain posture through mandatory authentication, fine‑grained access control, policy enforcement, and strong CI/CD integration. Our teams really value its broad support for package types (npm, NuGet, Docker, PyPI, raw binaries) and its ability to consolidate ingress mirroring, internal artifacts, and external distribution into a single platform, reducing fragmentation and bespoke solutions. The team at Cloudsmith has also been an incredible partner, working very closely with us on our migration as well as new features needed to meet our use cases. Review collected by and hosted on G2.com.
Moving from Artifactory with its file-system based organization of raw repos to Cloudsmith's label based organization can be tricky. Support for security scanning of AI models is not yet publicly available. Review collected by and hosted on G2.com.
We're glad to provide a more straightforward path for securing the software supply chain! Thanks for sharing your experience with Cloudsmith so far, and for confirming how much we put into the relationship AFTER the initial purchase. Multi-format, metadata-based repos is a change from JFrog Artifactory (and Sonatype Nexus), but it really provides a more flexible and powerful structure.







