SEE WHY COMPANIES ARE MOVING TO CLOUDSMITH
Package security without a second tool
Cloudsmith combines artifact management, package curation, vulnerability scanning, and policy enforcement - all in one platform. Talk to our team about switching

JFrog moved package blocking out of Xray and into a separate product
Ingestion-time blocking now lives in JFrog Curation, not Xray - a separate product with its own license, price tag, and configuration. Without it, packages reach your pipeline without policy checks. With Cloudsmith, policy enforcement at ingestion is built into the same platform you use to manage artifacts. Before you sign on for another product to regain this functionality, let’s chat.
Migrate to Cloudsmith
Cloudsmith replaces Artifactory, Xray, and Curation with a single product: artifact management, policy enforcement, and vulnerability scanning under one license. You also get one team that works with you year-round, not just when your contract's up for renewal.
- Prevent newly published packages from being consumed until a configurable time window elapses.
- Define usage policies via pre-set templates or in industry-standard OPA Rego.
- Detect malware at ingestion and quarantine it automatically.
- Apply one set of policies to every package and container, across every format and repository.
- Continuously recheck existing packages against the latest malware and CVE data.
- Trigger policy actions automatically, from quarantine to alerts.
- Prioritize fixes by EPSS exploit probability, so your team works on what matters first.
- Manage 30+ package formats, including containers and ML models, in one place.
- Govern every package with built-in risk detection and policy enforcement.
- Serve artifacts from 750+ global points of presence, with high availability built in.
- Configure everything as code with Terraform, and leave upgrades, patching and scaling to us.
Every package is checked against your policies at ingestion so only trusted packages reach your builds
Packages are continuously re-evaluated against the latest advisories, surfacing newly disclosed risks automatically
Artifact management, security, and global delivery come together on one fully-managed cloud-native platform
A dedicated technical team with enterprise-scale migration expertise
- A dedicated customer success manager who plans your migration around your environment.
- Engineer-led support for deeply technical assistance.
- A shared Slack channel for support that fits in your workflows.
Every migration is different. You get a dedicated team that plans around your repos, pipelines and timelines, and stays with you after go-live.
0%
of our customers migrate from JFrog
The switch is easier than you think
Before you spend more money on Curation, make sure you're working with the right partners.



