# Cloudsmith vs Pulp

**Leader by Vioscale score:** Cloudsmith

| Attribute | Cloudsmith | Pulp |
|---|---|---|
| **Vioscale score** | 66.4 (52% (medium)) | 43.7 (60% (medium)) |
| activity.commits_last_30d | - | 49 |
| adoption.dependent_repos | - | 65 |
| adoption.github_stars | - | 586 |
| deployment.options | `{"cloud":true}` | `{"cloud":true,"on_prem":true,"self_hosted":true}` |
| description.long | Universal artifact management solution for controlling, securing, and distributing packages and containers in your software supply chain with supply chain security, observability, and analytics. | Pulp enables developers and operators to fetch, upload, organize, and distribute software packages across on-premises infrastructure or cloud environments. It supports multiple content types through a plugin architecture and provides tools for repository management at scale. |
| features.capabilities | `{"web_ui":true,"hosting":"cloud","sbom_support":true,"image_signing":true,"oci_compliant":true,"private_repos":true,"artifact_types":"universal","cloud_iam_native":true,"pull_rate_limits":"tiered","pull_through_cache":true,"replication_mirroring":true,"vulnerability_scanning":true}` | `{"rbac":false,"web_ui":true,"hosting":"both","sbom_support":false,"image_signing":false,"oci_compliant":true,"private_repos":true,"artifact_types":"universal","cloud_iam_native":false,"pull_rate_limits":"none","high_availability":false,"pull_through_cache":false,"replication_mirroring":false,"vulnerability_scanning":false}` |
| integrations.count | 37 | 2 |
| integrations.list | `[{"name":"AWS CodeBuild"},{"name":"Aikido"},{"name":"Ansible"},{"name":"Argo CD"},{"name":"Azure AD SSO"},{"name":"Azure DevOps"},{"name":"Bitbucket Pipelines"},{"name":"Buildkite"},{"name":"Chainguard"},{"name":"Chef"},{"name":"CircleCI"},{"name":"Codefresh"},{"name":"Datadog"},{"name":"Dependabot"},{"name":"Drone CI"},{"name":"GitHub Actions"},{"name":"GitHub Secret Scanning"},{"name":"GitLab CI/CD"},{"name":"Google SSO"},{"name":"Harness"},{"name":"Jenkins"},{"name":"JumpCloud SSO"},{"name":"Kusari"},{"name":"Microsoft Teams"},{"name":"Octopus Deploy"},{"name":"Okta"},{"name":"OneLogin SSO"},{"name":"Ping Identity"},{"name":"Puppet"},{"name":"Roadie"},{"name":"Semaphore CI"},{"name":"Slack"},{"name":"Terraform Provider"},{"name":"Travis CI"},{"name":"VS Code Extension"},{"name":"Webhooks"},{"name":"Zapier"}]` | `[{"name":"OpenAI API"},{"name":"GitHub"}]` |
| language.primary | - | Python |
| license.spdx | - | GPL-2.0 |
| market.availability | `{"hqCountry":"GB","primaryMarkets":[],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` | `{"hqCountry":"US","primaryMarkets":[],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` |
| platform.support | `{"cli":true,"web":true}` | `{"cli":true}` |
| pricing | - | `{"type":"open_source","freeTier":true,"sourceUrl":"https://pulpproject.org","retrievedAt":"2026-08-16T21:32:46.974Z"}` |
| pricing.free_tier | - | yes |
| pricing.model | commercial | open_source |
| pricing.price_level | - | free |
| pricing.transparent | - | yes |
| release.history | - | `[{"url":"https://github.com/pulp/pulpcore/releases/tag/3.116.0","date":"2026-08-12T18:28:59Z","type":"stable","version":"3.116.0"},{"url":"https://github.com/pulp/pulpcore/releases/tag/3.105.16","date":"2026-08-12T16:55:30Z","type":"stable","version":"3.105.16"},{"url":"https://github.com/pulp/pulpcore/releases/tag/3.85.28","date":"2026-07-29T15:10:38Z","type":"stable","version":"3.85.28"},{"url":"https://github.com/pulp/pulpcore/releases/tag/3.63.45","date":"2026-07-29T15:11:51Z","type":"stable","version":"3.63.45"},{"url":"https://github.com/pulp/pulpcore/releases/tag/3.49.68","date":"2026-07-29T15:11:41Z","type":"stable","version":"3.49.68"},{"url":"https://github.com/pulp/pulpcore/releases/tag/3.115.3","date":"2026-07-28T20:41:04Z","type":"stable","version":"3.115.3"},{"url":"https://github.com/pulp/pulpcore/releases/tag/3.105.15","date":"2026-07-28T20:40:51Z","type":"stable","version":"3.105.15"},{"url":"https://github.com/pulp/pulpcore/releases/tag/3.105.14","date":"2026-07-28T08:02:29Z","type":"stable","version":"3.105.14"},{"url":"https://github.com/pulp/pulpcore/releases/tag/3.85.27","date":"2026-07-28T20:40:30Z","type":"stable","version":"3.85.27"},{"url":"https://github.com/pulp/pulpcore/releases/tag/3.73.41","date":"2026-07-28T20:40:26Z","type":"stable","version":"3.73.41"},{"url":"https://github.com/pulp/pulpcore/releases/tag/3.63.44","date":"2026-07-28T20:39:47Z","type":"stable","version":"3.63.44"},{"url":"https://github.com/pulp/pulpcore/releases/tag/3.49.67","date":"2026-07-28T20:39:20Z","type":"stable","version":"3.49.67"},{"url":"https://github.com/pulp/pulpcore/releases/tag/3.105.13","date":"2026-07-27T14:15:34Z","type":"stable","version":"3.105.13"},{"url":"https://github.com/pulp/pulpcore/releases/tag/3.115.2","date":"2026-07-22T12:50:08Z","type":"stable","version":"3.115.2"},{"url":"https://github.com/pulp/pulpcore/releases/tag/3.115.1","date":"2026-07-21T17:06:56Z","type":"stable","version":"3.115.1"},{"url":"https://github.com/pulp/pulpcore/releases/tag/3.115.0","date":"2026-07-21T15:16:40Z","type":"stable","version":"3.115.0"},{"url":"https://github.com/pulp/pulpcore/releases/tag/3.114.2","date":"2026-07-20T17:19:08Z","type":"stable","version":"3.114.2"},{"url":"https://github.com/pulp/pulpcore/releases/tag/3.105.12","date":"2026-07-20T17:20:16Z","type":"stable","version":"3.105.12"},{"url":"https://github.com/pulp/pulpcore/releases/tag/3.85.26","date":"2026-07-20T17:20:28Z","type":"stable","version":"3.85.26"},{"url":"https://github.com/pulp/pulpcore/releases/tag/3.73.40","date":"2026-07-20T17:21:51Z","type":"stable","version":"3.73.40"}]` |
| reliability.status_page | yes | - |
| security.disclosure_policy | yes | - |
| security.gdpr | - | yes |
| security.iso27001 | yes | - |
| security.soc2 | yes | - |
| security.vulnerabilities | - | `{"count":2,"source":"https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=pypi&package_name=pulpcore&per_page=100","last_12m":0,"max_severity":"HIGH"}` |

## Capabilities (Container Registries)

| Capability | Cloudsmith | Pulp |
|---|:--:|:--:|
| **Deployment** |  |  |
| Hosting | Cloud only | Cloud + self-hosted |
| **Standards** |  |  |
| OCI Distribution Spec compliant | ✓ | ✓ |
| **Scope** |  |  |
| Artifact types | Universal (images + language packages) | Universal (images + language packages) |
| **Security** |  |  |
| Built-in vulnerability scanning | ✓ | ✗ |
| Image signing (Cosign/Notation) | ✓ | ✗ |
| SBOM generation / storage | ✓ | ✗ |
| **Access** |  |  |
| Fine-grained RBAC / robot accounts | - | ✗ |
| Private repositories | ✓ | ✓ |
| **Distribution** |  |  |
| Geo-replication / mirroring | ✓ | ✗ |
| Pull-through cache / proxy | ✓ | ✗ |
| **Integration** |  |  |
| Native cloud IAM integration | ✓ | ✗ |
| **Pricing** |  |  |
| Pull-rate limits | Tiered by plan | None |
| **UX** |  |  |
| Web UI / console | ✓ | ✓ |
| **Ops** |  |  |
| High-availability deployment | - | ✗ |

*Source: Vioscale. Generated 2026-09-01T16:37:11.349Z. "-" = undocumented, not absent.*
