shouldiuse.io

Report

Should I Use Cloudsmith?

cloudsmith.com·Analyzed 1 hour ago··Based on 14 sources

A fully-managed, enterprise-scale solution to control, secure, and distribute software packages and containers.

Depends

Depends

Buy if you're a scaling platform or security team wanting managed multi-format registries without running Artifactory.

Solid managed JFrog alternative for scaling teams; pricey at usage scale — small teams should use GitHub Packages instead.

Confidence: Medium

4.5/5

G2 rating

44 reviews

$99–$149/mo

Paid plans from

directories disagree; Core tier is free

Yes

Free tier

Core plan, $0/month for individual developers

$72M Series C

Funding

Led by TCV and Insight Partners

Value for money3

Usage costs outpace self-hosted rivals per independent guide

Ease of use4

Fully managed; users report smooth year-long use

Feature depth4

Universal formats plus scanning and policy management

Security posture4

Deep scanning features; third-party verified; rival critique exists

Pros

  • Fully managed SaaS — no repository server to run or patch14
  • Packages and containers supported universally in one platform²
  • Built-in vulnerability scanning and policy management
  • Repeatedly recommended on r/devops as a JFrog Artifactory alternative
  • Rated 4.5/5 on G2 across 44 reviews³

Cons

  • Usage costs escalate — independent guide cites $561.50/month example
  • Direct competitor JFrog published a critique of its security reporting
  • Advertised starting price conflicts across directories ($99 vs $149/month)
  • Small public review base (44 G2 reviews) versus entrenched rivals³

Gotchas

  • highSame usage costs $561.50/month per independent guide — model your volume before committing
  • mediumEntry price listed as both $99 and $149/month — get a real quote first
  • mediumFully cloud-native — teams needing on-prem artifact storage must look elsewhere¹

Best for

  • Platform teams shipping at enterprise scale
  • Multi-format package and container distribution
  • Supply chain security and compliance needs
  • Teams avoiding self-hosted Artifactory ops

Not for

  • Solo devs or tiny teams — free registries exist
  • Anyone just needing a simple Docker registry
  • Budget-sensitive teams storing large artifact volumes
  • Guess: orgs requiring on-prem/self-hosted artifact storage

Companies that use it

  • Kong13
  • Diligent
  • BHS Corrugated
  • Thrivent
  • DataHub

Pricing

Core

$0/month

  • For individual developers
  • Basic registry use

Teams

from $99–$149/month

  • Team registries
  • Entry price varies by source — confirm with sales

Velocity / Ultra

Not disclosed

  • Enterprise scale
  • Supply chain security features

Security

No known vulnerabilities found in the sources reviewed; a competitor blog criticizes its vulnerability reporting quality.

  • JFrog critique: 'Superficial Application Security'JFrog, a direct competitor, published a post arguing Cloudsmith reports some non-CVE vulnerabilities and its security is superficial. Treat with bias caution — it is competitor content, not an independent audit.

What users say

G2 users (4.5/5) and r/devops commenters recommend Cloudsmith as a managed JFrog alternative, with 538 companies detected using it.

Take a look at Cloudsmith. We use ist for one yea
Reddit, r/devops
I like that Cloudsmith offers excelle...
AWS Marketplace review
Cloudsmith is the only viable and reliable solutio...
LinkedIn, DataHub post

Alternatives

Compare Cloudsmith with each alternative.

JFrog Artifactory

Market incumbent with broader enterprise deployment and format coverage.

Sonatype Nexus

Popular self-hosted repository manager with long track record.

GitLab Package Registry

Built into GitLab CI you may already pay for.

S3 plus your CI

Cheap DIY artifact storage if you don't need registry features.

Full analysis

Based on ~25 public sources; several review snippets were truncated in the evidence set.

Sources

  1. official
  2. official
  3. review
  4. review
  5. review
  6. review
  7. review
  8. review
  9. security
  10. security
  11. news
  12. news
  13. official
  14. official

Rate this review

Anonymous. You can change your vote.

Loading votes…

Ask a follow-up

Ask if a use case fits. Answers stay inside this report and its sources.

    Comments

    One queue. No replies. Give a display name first. Limit: 7 comments per day.

    Save a name to write a comment.

    No comments yet.