Philip G.
PG
VP Engineering, IT, Security & Compliance | Chief Compliance Officer (CCO)
Mid-Market (51-1000 emp.)
"A Single, Secure Front Door for All Our Packages"
5/5
What do you like best about Cloudsmith?

Cloudsmith gives us one controlled front door for every package our engineers consume. We host our private packages and proxy/cache public upstreams through it, so builds don't break when a public registry has an outage, and we can see and govern exactly which open-source components enter our software. Vulnerability scanning and license policies turn supply-chain security from a manual review exercise into something enforced automatically at the registry. As the person accountable for both engineering and compliance, that combination is rare. Review collected by and hosted on G2.com.

What do you dislike about Cloudsmith?

Pricing scales with usage and storage, so it's worth planning retention and cleanup policies early rather than letting old artifacts accumulate. That said, the ROI versus running and securing our own registry infrastructure is clear. Review collected by and hosted on G2.com.

See what 45 reviewers think of Cloudsmith

4.5 out of 5 · Verified reviews from real users

Read all reviews