Product

Overview

How it works Watch it work All 35 features Screenshots How ForgeRepo™ is secured

Keep bad packages out

Malware scanning Typosquat detection Dependency confusion protection Cooling off new releases Allow lists and block lists

When something goes wrong

Kill switch Who has it Lockdown and degraded modes Vulnerability monitoring

Developers and approvals

Requests and auto approve Check, walk and review Waivers Dry run
Formats

Languages

Private npm registry PyPI proxy and private index Private NuGet feed and proxy Maven repository proxy RubyGems mirror Composer and Packagist proxy

Apple, containers and Linux

CocoaPods CDN mirror Swift package registry Docker registry mirror RPM mirror for dnf and yum APT mirror for Debian and Ubuntu

Use it as

An npm firewall Artifacts, SBOMs and lifecycle More than one node SSO, roles and allow lists
Learn

Guides

Learn secure development Secure coding Secure pipelines Unsafe vs safe Security and development

Supply chain

Supply chain attacks, 2016 to 2026 Software supply chain security
Compare Side by side, all four ForgeRepo™ vs JFrog ForgeRepo™ vs Sonatype ForgeRepo™ vs Cloudsmith
Docs

Start

Getting started Download All documentation Questions

For developers

npm setup pip setup docker login Push a Docker image CI basics

For administrators

First setup Rules and their order Six incidents, walked through Backup and upgrade
Pricing Install it

An honest comparison

ForgeRepo™ vs Cloudsmith

Cloudsmith is a fully managed artifact platform: thirty three formats, a global CDN, and nothing for you to run. Its security policies, vulnerability, license, deny and malware, are on the Ultra and Enterprise plans, and policy as code, which includes the cooldown policy, is a paid add-on on those. There is no self hosted version.

ForgeRepo™ ahead on 20 Cloudsmith ahead on 8 level on 5 stars: ForgeRepo™ 127, Cloudsmith 100

Where Cloudsmith is better

  • Nothing to run: fully managed, with a global CDN and custom storage regions.
  • Thirty three formats.
  • Policy as code in OPA and Rego, with a simulate endpoint and a Terraform provider.
  • SAML with group sync, and SCIM.
  • Vendor support.
  • A full container registry with Cosign signing. ForgeRepo™ takes pushes, but does not sign.

Where ForgeRepo™ is better

  • SaaS only. It cannot run inside your network or air gapped.
  • Security policies are Ultra and Enterprise only, and cooldown needs the policy as code add-on.
  • Allow lists and exemptions are written in Rego. A request and approve flow is a GitOps suggestion, not built in.
  • Block until scan, and upstream trust for dependency confusion, are in early access.
  • Typosquats are only caught through the OpenSSF malicious packages feed.
  • ForgeRepo™ is MIT licensed, self hosted in one container, with every feature in the one free version.

Pick Cloudsmith if

You do not want to run anything, you need thirty formats and a CDN, you want policy as code in Git, or your organization does not host services itself.

Pick ForgeRepo™ if

Packages must stay inside your network, you need it air gapped, or you want a firewall, cooldown, kill switch and approvals built in and free, rather than on a top plan with an add-on.

What Cloudsmith costs

Read from their own pages on 18 September 2026. Prices change, so check the source before you quote us.

TierWhat you getSource
Core$0, 500 MB of storage and 1 GB of delivery. No security policies. (From search results of the pricing page, which refused our requests.) cloudsmith.com
Pro$149 a month, 5 GB of storage and 25 GB of delivery. (Same source, and matches a third party write up.) cloudsmith.com
Ultra and EnterprisePriced on request. This is where vulnerability, license, deny and malware policies are. docs.cloudsmith.com
Policy as codePaid add-on on Ultra and Enterprise. Needed for the cooldown policy. docs.cloudsmith.com
ForgeRepo™$0. Every feature on this site, self hosted, MIT licensed. No support contract. source

Row by row

The same rows as the full comparison, with just the two of us.

CapabilityForgeRepo™CloudsmithWhy
Somebody to call
The product around it
★★★★★
behind
★★★★★ First row, and the one we lose worst. All three sell support with an SLA: a number to ring at three in the morning and somebody obliged to answer. ForgeRepo™ is an open source project. When it breaks, the person fixing it is you, with the source and the docs. If that matters where you work, it matters more than every other row on this page.
How many package formats
The product around it
★★★★★
behind
★★★★★ ForgeRepo™ does eleven: npm (with pnpm, Yarn and Bun), PyPI, container images, NuGet, Maven (with Gradle and sbt), RubyGems, Composer, CocoaPods, Swift packages, and RPM and APT mirrors. JFrog lists about fifty repository types, Sonatype about thirty and Cloudsmith thirty three, including Go, Cargo, Helm and Hugging Face, which ForgeRepo™ does not have. Several of ours are pull only: you can publish npm, PyPI, NuGet and images to it, but not Maven, gems or the rest. If you need Go or Cargo behind the same policy, ForgeRepo™ is not your answer today.
A managed cloud service
The product around it
★★★★★
behind
★★★★★ ForgeRepo™ is self hosted only. There is nobody to run it for you. JFrog and Cloudsmith are strong SaaS products with CDNs and many regions, and Sonatype sells Nexus Repository and Firewall in the cloud too.
Run it yourself, including air gapped
The product around it
★★★★★
ahead
★★★★★ One container on your own Linux box, with the database and cache inside it, and nothing calling home. JFrog and Sonatype both have mature self hosted editions, air gapped included. Cloudsmith is SaaS only: it has an agent that runs on your network, but the registry itself is theirs.
Every format and the security, for free
The product around it
★★★★★
ahead
★★★★★ Everything on this page that ForgeRepo™ does is in the one free version. None of the three has a free tier that gives you npm, PyPI and Docker together with blocking before download. JFrog's open source Artifactory has no npm or PyPI, and Xray and Curation are paid. Nexus Community Edition is free with a cap of 40,000 components or 100,000 requests a day, and blocking needs the paid Firewall. Cloudsmith's free Core plan is 500 MB with no security policies.
Open source you can read and change
The product around it
★★★★★
ahead
★★★★★ ForgeRepo™ is MIT licensed, all of it. JFrog publishes Artifactory OSS under the AGPL, but that edition has none of the formats or security features compared here. Sonatype still publishes the Nexus core source under the EPL, but since early 2025 the free binaries are Community Edition under a Sonatype EULA. Cloudsmith is closed.
Allow and block rules by name and version
Keeping bad packages out
★★★★★
ahead
★★★★★ ForgeRepo™ takes exact names, scopes, wildcards and npm or pip version ranges, scoped to an application or environment, and strips blocked versions from metadata so clients resolve around them. JFrog Curation and Sonatype Firewall both have rich policy engines that do this and more. Cloudsmith has deny policies built in and does allow lists as policy as code in Rego, on its Ultra and Enterprise plans.
Malware blocked before download
Keeping bad packages out
★★★★★
ahead
★★★★★ ForgeRepo™ scans every file with ClamAV, a hash blocklist or a scanner of your own, and holds any version the OpenSSF malicious packages feed names before anybody gets it. A package reported malicious after it was cached goes on the kill switch by itself. It also looks at how a release behaves: a new version that suddenly runs code at install time is flagged or held, an npm listing that disagrees with the package.json in its tarball is held, and a version with less provenance than the ones before it is held. JFrog and Sonatype both run research teams and machine learning that read new packages as they are published, and block on that intelligence. That is still a real difference, which is why we score one below them. Cloudsmith uses ClamAV and the OpenSSF malicious packages feed, with block until scan in early access.
Its own malicious package research
Keeping bad packages out
★★★★★ ★★★★★ ForgeRepo™ has no research of its own. There is no team behind it reading npm all day. What it has is the public OpenSSF malicious packages feed, read through osv.dev, which only knows what somebody has already reported. JFrog publishes its research and Sonatype rates every release with its Release Integrity service. Cloudsmith draws on the same public data we do, which is why we both get one star.
Typosquat detection
Keeping bad packages out
★★★★★
ahead
★★★★★ ForgeRepo™ compares every name against well known npm and PyPI names and catches swaps, homoglyphs, moved separators, added words and flattened scopes, then warns or refuses. JFrog and Sonatype catch typosquats through their research data, which knows about ones a name comparison would miss. Cloudsmith relies on the OpenSSF feed.
Dependency confusion protection
Keeping bad packages out
★★★★★
ahead
★★★★★ ForgeRepo™ reserves names so they are never fetched from outside, and routes every scope to exactly one upstream with no silent fallback. Sonatype's Namespace Confusion Protection in Firewall does the same job well. JFrog has priority resolution and exclude patterns. Cloudsmith's upstream trust is in early access.
Cooling off period for new releases
Keeping bad packages out
★★★★★ ★★★★★ Everybody has this now and we are not going to pretend otherwise. ForgeRepo™ measures from the registry's publish time, trims young versions from metadata, has exemptions and waivers, and is free. JFrog Curation measures from publish time, as an add-on, and not for Docker. Sonatype measures from when it first cataloged the version and adds Release Integrity. Cloudsmith measures from publish time, as a policy as code add-on, with no exemptions.
Resolve around vulnerable versions
Keeping bad packages out
★★★★★
ahead
★★★★★ With safe version resolution on, ForgeRepo™ leaves versions with serious advisories out of the metadata, so a range settles on the newest safe version and nothing outside the range is swapped in. Sonatype does the same thing in Firewall and calls it Policy Compliant Component Selection. JFrog Curation blocks the version. We have not tested any of theirs side by side, so we have given them the benefit of the doubt.
License policy
Keeping bad packages out
★★★★★ ★★★★★ ForgeRepo™ reads npm, PyPI, NuGet, Maven, RubyGems, Composer, CocoaPods and RPM licenses into SPDX expressions and enforces allowed, review and blocked lists. Xray and Sonatype's policy engine have years of license data and obligations behind them, and handle more formats. Cloudsmith has an SPDX deny list, with no license detection for Docker.
Verifies Sigstore provenance on proxied packages
Keeping bad packages out
★★★★★
ahead
★★★★★ ForgeRepo™ checks npm SLSA provenance and PyPI PEP 740 attestations against a pinned Sigstore root on the server, holds a file whose provenance is invalid, and holds a new version built with less provenance than the ones before it, or built somewhere else. For images, a trust policy can require a cosign signature from your keys or from a keyless signer, checked against Fulcio and Rekor, and refuse unsigned pulls. JFrog passes npm attestations through so npm audit signatures works, and has an Evidence service. We could not find server side verification of proxied packages for Sonatype or Cloudsmith. If it is there, tell us and this row changes.
Quarantine and integrity
Keeping bad packages out
★★★★★ ★★★★★ ForgeRepo™ holds files for malware, licenses, provenance, fresh publishes and upstream bytes that changed, in permissive or strict mode. Sonatype Firewall quarantine is the benchmark, and it fails safe if the service is down. Cloudsmith quarantines from the UI, API or a policy. JFrog's model blocks at request time rather than holding files in a quarantine state.
Kill switch for a compromised package
When something goes wrong
★★★★★
ahead
★★★★★ ForgeRepo™ has a page for exactly this: kill a package, a range, one file hash, everything an advisory covers, or a CSV of hundreds, with your reason in every developer's error and an email listing who pulled it. The others can all do it with a policy, and Cloudsmith's deny policies act immediately. We found no single dedicated feature for it in JFrog or Sonatype.
Stop fetching from upstream
When something goes wrong
★★★★★
ahead
★★★★★ ForgeRepo™ has degraded and lockdown modes and an upstream switch, with ranges resolved among what is cached. Artifactory has had offline remote repositories and a global offline mode for years. Nexus can block outbound connections per proxy repository. We could not find an equivalent for Cloudsmith.
Who pulled it
When something goes wrong
★★★★★
ahead
★★★★★ ForgeRepo™ stamps every download with the token's application and environment and searches it by name, hash or CVE. JFrog does this through build info and Xray impact analysis, Sonatype through its application inventory. Cloudsmith has download logs.
Audit trail
When something goes wrong
★★★★★
ahead
★★★★★ All four keep one. ForgeRepo™ records before and after for every change, in the free version. JFrog's audit log is Enterprise X and up in the cloud, Sonatype lists it with Pro, and Cloudsmith keeps a year, searchable for 30 to 365 days by plan.
Request and approve, built in
Developers and approvals
★★★★★
ahead
★★★★★ In ForgeRepo™ a blocked install opens a request, the request is scanned on arrival, and an approver clicks approve, or auto approve does it for clean ones. JFrog Curation and Sonatype Firewall have waiver requests with decision owners, which are close. Cloudsmith suggests a GitOps flow and says it is not a built in feature.
Waivers that expire
Developers and approvals
★★★★★
ahead
★★★★★ ForgeRepo™ waivers are scoped, time boxed and name the advisory ids. JFrog Curation waivers run 1 to 365 days with automatic approval options, and Sonatype has had time based waivers and central waiver management for years. Both are more mature. Cloudsmith does exemptions in Rego.
Test a policy before enforcing it
Developers and approvals
★★★★★ ★★★★★ ForgeRepo™ replays up to 90 days of real downloads against a proposed rule and counts who it would break, and has an audit only learning mode. JFrog Curation policies can run in dry run, and Cloudsmith has a simulate endpoint for its Rego policies. Sonatype has warn actions rather than a replay.
Review a lockfile or SBOM against policy
Developers and approvals
★★★★★
ahead
★★★★★ ForgeRepo™ reviews npm, Python and Composer lockfiles, requirements, and CycloneDX and SPDX SBOMs covering every format it serves, in memory and lets you act on the result. JFrog does this with the jf CLI and Xray, and Sonatype has built its whole Lifecycle product around evaluating applications and SBOMs.
npm audit answered locally
Developers and approvals
★★★★★
ahead
★★★★★ ForgeRepo™ answers npm audit from its own findings, so nothing about your project leaves the box, and adds a warning to the install output. Nexus answers it when Firewall or Lifecycle is licensed. JFrog supports it but stopped enriching it from Xray and points people at jf audit. Cloudsmith passes it through.
npm registry and publishing
Formats and running it
★★★★★
behind
★★★★★ ForgeRepo™ proxies, caches and publishes npm under reserved names, with immutable versions, deprecations and dist-tags. The other three are mature npm registries with virtual repositories, replication and years of edge cases behind them.
PyPI index and uploads
Formats and running it
★★★★★
behind
★★★★★ ForgeRepo™ speaks PEP 503, 691, 658 and 700 and takes twine uploads for reserved projects. Same story as npm: the others have done it longer.
Docker and OCI images
Formats and running it
★★★★★
behind
★★★★★ ForgeRepo™ mirrors and scans images, checks everything by digest, reads the packages inside every layer for advisories, can require cosign signatures before a pull, and takes pushes under reserved names, holding every layer until it scans clean. Pushed tags never move and nothing pushed is ever deleted. All three are full container registries with deletion, retention policies and replication, which ForgeRepo™ does not have. If that is what you need from a registry, theirs is more complete.
SBOM export
Formats and running it
★★★★★
ahead
★★★★★ ForgeRepo™ writes CycloneDX 1.5 and SPDX 2.3 per file and per application from what was actually downloaded. Xray exports SPDX 2.3, 3.0 and CycloneDX across its formats. Sonatype exports through Lifecycle, now part of Sonatype Guide. Cloudsmith generates SBOMs for container images.
Single sign on
Formats and running it
★★★★★
behind
★★★★★ ForgeRepo™ does OpenID Connect with PKCE, and nothing else: no SAML, no SCIM. JFrog has SAML, OIDC and SCIM on its higher tiers. Sonatype has SAML and OIDC on Pro. Cloudsmith has SAML with group sync and SCIM on Ultra.
SIEM and webhooks
Formats and running it
★★★★★
ahead
★★★★★ ForgeRepo™ sends signed webhooks, Splunk HEC and syslog in JSON or CEF, with retries, in the free version. JFrog has webhooks and log streaming on Enterprise+. Nexus has webhooks. Cloudsmith has webhooks and a Datadog integration.
High availability and scale
Formats and running it
★★★★★
behind
★★★★★ ForgeRepo™ runs more than one node against a shared MariaDB with the cache in S3 or Azure, and recommends active and passive. That is honest HA, not a cluster. JFrog sells multi site federation and very high uptime, Sonatype sells a resilient Pro deployment, and Cloudsmith runs it for you on a global CDN.
Cloud object storage
Formats and running it
★★★★★
ahead
★★★★★ ForgeRepo™ keeps its cache in S3 compatible storage or Azure Blob, hash checked both ways. Artifactory does S3, Azure and Google Cloud Storage with sharding. Nexus does S3 in every edition and Azure and Google on Pro. Cloudsmith manages storage for you, with custom regions, and we could not confirm bring your own bucket.

Questions

Is ForgeRepo™ a free alternative to Cloudsmith?

For npm, PyPI, container images, NuGet, Maven, RubyGems, Composer, CocoaPods, Swift, RPM and APT with blocking before download, yes, and it is MIT licensed with no paid tier. It is not a replacement for everything Cloudsmith does: it has eleven formats rather than thirty or more, no vendor support, and no malicious package research of its own, only the public OpenSSF feed.

Where is Cloudsmith better than ForgeRepo™?

Nothing to run: fully managed, with a global CDN and custom storage regions. Thirty three formats. Policy as code in OPA and Rego, with a simulate endpoint and a Terraform provider. SAML with group sync, and SCIM. Vendor support. A full container registry with Cosign signing. ForgeRepo™ takes pushes, but does not sign.

When should I pick ForgeRepo™ over Cloudsmith?

Packages must stay inside your network, you need it air gapped, or you want a firewall, cooldown, kill switch and approvals built in and free, rather than on a top plan with an add-on.

Also compared: JFrog and Sonatype.

Try it next to Cloudsmith

It takes about two minutes on a spare server, and it can run in audit only mode beside what you have, learning what your teams pull before it blocks anything.