📂 Subcategories

🔧 Tools in Artifact Management

Endor Labs

The Dependency Lifecycle Management Platform.

A platform focused on securing the software supply chain by managing dependency lifecycle.

For more tool information ➜

Bytesafe

Secure your dependencies. The secure dependency firewall and supply chain platform.

A SaaS platform focused on securing the software supply chain by managing dependencies.

For more tool information ➜

Cloudsmith

Universal, cloud-native, artifact management.

A fully managed, cloud-native artifact management platform for securely storing and distributing software packages.

For more tool information ➜

Cloudsmith

Your single source of truth for software assets.

A universal, cloud-native package management platform.

For more tool information ➜

Cloudsmith

Software delivery, simplified. The only cloud-native, universal package manager.

A cloud-native, universal package management service.

For more tool information ➜

Cloudsmith

Software delivery, simplified. Universal, cloud-native, and secure artifact management.

A universal, cloud-native artifact repository for developers and enterprises.

For more tool information ➜

Cloudsmith

Universal, cloud-native, private package management.

A cloud-native platform for managing and distributing software packages and artifacts.

For more tool information ➜

Composer

Dependency Manager for PHP

The standard dependency management tool for PHP.

For more tool information ➜

Rezilion

Eliminate 85% of your vulnerability backlog.

An automated vulnerability management platform that prioritizes based on runtime execution.

For more tool information ➜

GitHub Packages

Your packages, at home with their code.

A software package hosting service that allows you to host your software packages privately or publicly and use them as dependencies in your projects.

For more tool information ➜

GitHub Packages

A software package hosting service that allows you to host your software packages privately or publicly and use them as dependencies in your projects.

Host and manage packages directly within your GitHub repositories.

For more tool information ➜

GitHub Packages

Your packages, at home with their code.

A software package hosting service integrated with GitHub.

For more tool information ➜

Bundler

The best way to manage a Ruby application's gems.

The standard dependency manager for the Ruby language.

For more tool information ➜

PyPI (Python Package Index)

The Python Package Index.

The official third-party software repository for Python.

For more tool information ➜

Packagecloud

All your packages, in one place.

A hosted package repository service for various package types.

For more tool information ➜

GitHub Packages

A software package hosting service that allows you to host your software packages privately or publicly and use them as dependencies in your projects.

Host and manage packages, including containers and other dependencies, right next to your code.

For more tool information ➜

packagecloud

Hosted package repositories for your company.

A hosted service for managing private software packages.

For more tool information ➜

GitHub Advanced Security

Find and fix vulnerabilities with ease.

A suite of security tools integrated into the GitHub platform.

For more tool information ➜

Cargo

The Rust package manager.

The official build tool and package manager for the Rust programming language.

For more tool information ➜

Packagecloud

Your packages, delivered.

A cloud-based service to store and distribute software packages in a secure and reliable way.

For more tool information ➜

Packagecloud

All your packages, in one place.

A hosted package repository service for various package types like RPM, DEB, and Maven.

For more tool information ➜

Wiz

The Cloud Security Platform.

A CNAPP platform that provides full-stack visibility of cloud risks, including SBOM.

For more tool information ➜

Amazon Elastic Container Registry (ECR)

Easily store, manage, and deploy container images.

A fully-managed Docker container registry from AWS.

For more tool information ➜

Google Artifact Registry

Store, manage, and secure your container images and language packages.

A universal repository manager for packages and container images on Google Cloud.

For more tool information ➜

GitHub Packages

Your packages, at home with their code.

A software package hosting service integrated with GitHub.

For more tool information ➜

Trivy

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more.

A popular open-source security scanner for a wide range of artifacts.

For more tool information ➜

Amazon ECR (Elastic Container Registry)

Easily store, manage, and deploy container images.

A fully-managed Docker container registry that makes it easy for developers to store, manage, and deploy Docker container images.

For more tool information ➜

Harbor

An open source registry that secures artifacts with policies and role-based access control.

An open-source, cloud-native container registry.

For more tool information ➜

Google Artifact Registry

Store, manage, and secure your container images and language packages.

A universal package manager for container images and language packages on Google Cloud.

For more tool information ➜

Harbor

An open source trusted cloud native registry project that stores, signs, and scans content.

An open-source container image registry with security and identity features.

For more tool information ➜

Yarn

Fast, reliable, and secure dependency management.

A package manager for JavaScript that focuses on speed and reliability.

For more tool information ➜

npm

The package manager for JavaScript.

The world's largest software registry, containing over 1.3 million packages of open-source code for JavaScript and Node.js.

For more tool information ➜

ProGet

Your Universal Package Manager.

A private package server to host and manage your software assets.

For more tool information ➜

Harbor

An open source trusted cloud native registry project that stores, signs, and scans content.

An open-source container image registry with security scanning and access control.

For more tool information ➜

Snyk

Developer security that helps you build secure applications, faster.

Finds and fixes vulnerabilities in open source dependencies and container images.

For more tool information ➜

GitLab Package Registry

Manage packages and dependencies with the GitLab Package Registry.

A built-in package management solution for GitLab.

For more tool information ➜

Pip (Python)

The package installer for Python.

The standard package manager for Python.

For more tool information ➜

Harbor

An open source registry for cloud native artifacts.

An open-source registry that secures artifacts with policies and role-based access control, ensures images are scanned and free from vulnerabilities, and signs images as trusted.

For more tool information ➜

Google Artifact Registry

Store, manage, and secure your container images and language packages.

A universal package manager for container images and language packages on Google Cloud.

For more tool information ➜

Docker Scout

Turn supply chain complexity into your competitive advantage.

A software supply chain security tool integrated into the Docker ecosystem.

For more tool information ➜

GitLab Package Registry

Manage packages and dependencies for your entire DevOps lifecycle.

A built-in package manager for GitLab, supporting various common package formats.

For more tool information ➜

Azure Artifacts

Create, host, and share packages with your team.

Integrated package management for Azure DevOps.

For more tool information ➜

Go Modules

Managing dependencies in Go.

The official dependency management system for the Go programming language.

For more tool information ➜

NuGet

The package manager for .NET.

The package manager for .NET, providing a central repository for developers to share and consume reusable code.

For more tool information ➜

Gitea

A painless self-hosted Git service.

A lightweight, self-hosted Git service with a built-in package registry.

For more tool information ➜

Azure Artifacts

Create, host, and share packages with your team.

A service within Azure DevOps for managing software packages and dependencies.

For more tool information ➜

Sonatype Nexus Repository

The World's #1 Repository Manager.

Manage binaries and build artifacts across your entire software supply chain.

For more tool information ➜

GitLab

The DevSecOps Platform.

A single platform for the entire software development lifecycle.

For more tool information ➜

Packagecloud

All your packages, in one place.

A unified, developer-friendly package repository service.

For more tool information ➜

Google Artifact Registry

Store, manage, and secure your container images and language packages.

A single place for your organization to manage container images and language packages (like Maven and npm).

For more tool information ➜

DigitalOcean Container Registry

Store and manage private container images.

A private, secure container registry integrated with the DigitalOcean platform.

For more tool information ➜

Sonatype Nexus Repository

The world's #1 repository manager.

A universal repository manager for software components, binaries, and build artifacts.

For more tool information ➜

Prisma Cloud

The most complete Cloud-Native Application Protection Platform (CNAPP).

Palo Alto Networks' CNAPP platform, providing security from code to cloud.

For more tool information ➜

JFrog Artifactory

The Universal Artifact Repository Manager for All Your Software Packages, Binaries, and Dependencies.

A universal artifact repository manager for all major package formats.

For more tool information ➜

Google Artifact Registry

Store, manage, and secure your container images and language packages.

A universal package manager for container images and language packages on Google Cloud.

For more tool information ➜

Harness Artifact Registry

AI-native, universal artifact management.

An AI-native, universal artifact management solution by Harness.

For more tool information ➜

GitLab Package Registry

Manage packages and dependencies for your entire DevOps lifecycle.

A built-in package manager for GitLab projects.

For more tool information ➜

Gitea Package Registry

A painless self-hosted Git service.

An integrated package registry within the Gitea self-hosted Git service.

For more tool information ➜

Veracode SCA

Secure your software with a single platform.

An SCA solution that is part of Veracode's comprehensive application security platform.

For more tool information ➜

Docker Hub

Build and Share Container Images.

The world's largest library and community for container images.

For more tool information ➜

Legit Security

Application Security Posture Management.

A platform for securing the software supply chain and development environments.

For more tool information ➜

Cybeats

SBOM Management and Software Supply Chain Security.

An enterprise platform for managing SBOMs and securing the software supply chain.

For more tool information ➜

Apiiro

The Proactive Application Risk Management Platform.

Connects application risks from code to cloud, providing context and prioritization.

For more tool information ➜

npm

The package manager for JavaScript.

The default package manager for the Node.js runtime environment.

For more tool information ➜

Conan

The C and C++ Package Manager.

An open-source, decentralized package manager for C and C++ developers.

For more tool information ➜

Helm

The package manager for Kubernetes.

A tool for managing applications on Kubernetes clusters.

For more tool information ➜

Sonatype Nexus Repository

The world's #1 repository manager.

A repository manager that stores and distributes software components for development, deployment, and provisioning.

For more tool information ➜

GitLab Package Registry

Manage packages and dependencies with GitLab.

A private package registry for your team, with support for a variety of common package managers.

For more tool information ➜

Azure Artifacts

Create, host, and share packages with your team.

A service that enables you to create, host, and share packages from public and private sources.

For more tool information ➜

Azure Container Registry

A private registry for managing container images and related artifacts.

A managed, private Docker registry service based on the open-source Docker Registry 2.0.

For more tool information ➜

CloudRepo

Maven & Python Repositories for Modern Teams.

A cloud-based artifact repository solution, supporting various package formats including Maven, npm, and Docker.

For more tool information ➜

Sonatype Nexus Repository

The world's #1 binary repository. Free to use.

A universal repository manager for caching, hosting, and managing software components.

For more tool information ➜

Azure Artifacts

Create, host, and share packages with your team.

Manages dependencies and stores software artifacts within Azure DevOps.

For more tool information ➜

Azure Container Registry

Build, store, secure, scan, replicate, and manage container images and artifacts.

A managed, private Docker registry service on Microsoft Azure.

For more tool information ➜

npm Private Packages

Host, manage, and distribute private JavaScript packages.

A hosted private registry for npm packages, from the maintainers of the public registry.

For more tool information ➜

Sonatype Nexus Repository

The World's #1 Repository Manager

Manage binaries and build artifacts across your entire software supply chain.

For more tool information ➜

GitLab Package Registry

Manage packages and dependencies with GitLab.

A private package registry built into the GitLab platform.

For more tool information ➜

Azure Artifacts

Create and share Maven, npm, NuGet, and Python package feeds.

A package management solution integrated with Azure DevOps.

For more tool information ➜

Gradle

The modern build automation tool.

A flexible build automation tool for multi-language development.

For more tool information ➜

NuGet

The package manager for .NET.

The central package repository for .NET developers.

For more tool information ➜

Sonatype Nexus Lifecycle

The industry's most powerful software supply chain management platform.

Policy-based automation for managing open source risk across the SDLC.

For more tool information ➜

Aqua Security

The Cloud Native Security Platform.

Provides security for cloud native applications, from containers to serverless.

For more tool information ➜

Sysdig

Secure. From source to run.

A cloud security platform for monitoring and securing cloud native applications.

For more tool information ➜

Veracode

The Application Security Company.

A comprehensive platform for application security testing.

For more tool information ➜

FOSSA

Complete open source management.

Manages open source license compliance and security vulnerabilities.

For more tool information ➜

Mend.io

Application Security without the noise.

An application security platform for managing open source security and compliance.

For more tool information ➜

Checkmarx SCA

The Enterprise Application Security Platform.

A software composition analysis tool that is part of the Checkmarx One platform.

For more tool information ➜

Microsoft Defender for Cloud

Protect multi-cloud and hybrid environments with Microsoft Defender for Cloud.

A unified CNAPP that includes vulnerability management and SBOM capabilities.

For more tool information ➜

AWS CodeArtifact

Secure, scalable, and cost-effective artifact management for software development.

A fully managed artifact repository service that makes it easy for organizations of any size to securely store, publish, and share software packages used in their software development process.

For more tool information ➜

Docker Hub

Build and share container images.

A cloud-based registry service that allows you to link to code repositories, build your images and test them, stores manually pushed images, and links to Docker Cloud so you can deploy images to your hosts.

For more tool information ➜

JFrog Artifactory

The Universal Artifact Repository Manager for all your software packages, container images and Helm charts.

A universal artifact repository manager for all major package formats.

For more tool information ➜

AWS CodeArtifact

A secure, scalable, and cost-effective artifact management for software development.

A fully managed artifact repository service from AWS.

For more tool information ➜

Docker Hub

The world's largest library and community for container images.

A cloud-based registry for finding and sharing container images.

For more tool information ➜

JFrog Artifactory

The Universal Artifact Repository Manager for all major package formats.

A universal artifact repository manager for software packages, container images, and Helm charts.

For more tool information ➜

Docker Hub

The world's largest library and community for container images.

A cloud-based registry service for building and shipping containerized applications.

For more tool information ➜

AWS CodeArtifact

A secure, scalable, and cost-effective artifact management for software development.

A managed artifact repository service from AWS for storing and sharing software packages.

For more tool information ➜

JFrog Artifactory

The Universal Artifact Repository Manager

A universal artifact repository manager for all major package formats.

For more tool information ➜

AWS CodeArtifact

Secure, scalable, and cost-effective artifact management for software development.

A fully managed artifact repository service from AWS.

For more tool information ➜

Apache Maven

A software project management and comprehension tool.

A build automation tool primarily for Java projects.

For more tool information ➜

AWS CodeArtifact

Secure, scalable, and cost-effective artifact management for software development.

A fully managed artifact repository service from AWS.

For more tool information ➜

Quay

Build, analyze, and distribute your container images.

A container image registry that provides security scanning, image rollbacks, and automation.

For more tool information ➜

ProGet

Your Universal Package Manager.

A universal package manager that lets you host and manage your own private packages, as well as proxy and cache packages from public repositories.

For more tool information ➜

Red Hat Quay

Build, analyze, and distribute your container images.

An enterprise container registry for building, storing, and distributing containers.

For more tool information ➜

Perforce Helix Core

The version control for innovators who need to move faster.

A version control system that can also manage large binary files.

For more tool information ➜

ProGet

Your Universal Package Manager.

A self-hosted package manager for NuGet, Docker, npm, and more, from Inedo.

For more tool information ➜

Red Hat Quay

Build, analyze, and distribute your container images.

An enterprise container registry for building, storing, and distributing container images.

For more tool information ➜

sbt (Scala)

The interactive build tool.

A primary build tool for the Scala and Java ecosystems.

For more tool information ➜

Quay.io

Build, Analyze, and Distribute Your Container Images.

An enterprise container registry by Red Hat.

For more tool information ➜

ProGet

Your Universal Package Manager.

A universal package manager by Inedo for self-hosting.

For more tool information ➜

Helix Core

The Version Control for Large Scale Development.

A version control system that also manages large binary files and digital assets.

For more tool information ➜

Anchore Enterprise

Secure Your Software Supply Chain.

A platform for container security and software supply chain management.

For more tool information ➜

Synopsys Black Duck

Comprehensive Software Composition Analysis (SCA).

Comprehensive SCA for managing security, license, and quality risks in open source.

For more tool information ➜

Anchore

Secure your software supply chain. From code to cloud.

A platform for container security and software supply chain management.

For more tool information ➜

JFrog Artifactory

Universal Artifact Repository Manager

A universal artifact repository manager that supports all major package formats, CI/CD tools, and DevOps technologies.

For more tool information ➜

MyGet

Your packages, your rules.

A hosted package repository for NuGet, npm, Bower, Maven, and VSIX packages.

For more tool information ➜

MyGet

Your packages, your rules.

A hosted universal package manager for .NET and beyond.

For more tool information ➜

Oracle Container Registry

A highly available private container registry service for storing and sharing container images.

A private container registry service on Oracle Cloud Infrastructure (OCI).

For more tool information ➜

MyGet

Your packages, your rules. Universal Package Manager for NuGet, npm, Bower, Maven, and VSIX.

A hosted package management service with a strong focus on the .NET ecosystem.

For more tool information ➜

MyGet

Your own NuGet, npm, Bower, Maven, VSIX and Symbol Server.

A hosted universal package manager with a focus on the .NET ecosystem.

For more tool information ➜

JFrog Xray

Universal Software Composition Analysis (SCA).

Scans binaries for security vulnerabilities and license compliance issues.

For more tool information ➜

Pulp Project

A platform for managing repositories of software packages.

An open-source platform for managing and distributing software packages.

For more tool information ➜

Apache Archiva

The Build Artifact Repository Manager.

An extensible repository management software that helps managing your own personal or enterprise-wide build artifact repository.

For more tool information ➜

Apache Archiva

The Open Source Artifact Repository.

An open-source artifact repository manager from the Apache Software Foundation.

For more tool information ➜

Apache Archiva

The Open Source Repository Manager.

An open-source repository manager from the Apache Software Foundation.

For more tool information ➜

Dist

The open-source artifact repository.

A lightweight, open-source artifact repository that focuses on simplicity and ease of use.

For more tool information ➜

Pulp

A platform for managing repositories of software packages.

An open-source platform for managing repositories of software packages and making them available to a large number of consumers.

For more tool information ➜

Linode Container Registry

Simple, private, and secure container image storage.

A private container registry from Linode (now Akamai).

For more tool information ➜

Dist

The secure, hosted private package repository.

A hosted private and proxy repository for Python and npm packages.

For more tool information ➜

dist

The universal package manager for your code.

A cloud-based, universal package manager for hosting and distributing private packages.

For more tool information ➜

Bytesafe

Secure your dependencies. The secure dependency firewall and private registry for npm and Maven.

A security-focused private registry and dependency firewall.

For more tool information ➜

dist.dev

The universal package manager for developers.

A universal, cloud-based package manager with a focus on simplicity.

For more tool information ➜

Conda-forge

A community-led collection of recipes, build infrastructure and distributions for the conda package manager.

A community-driven package repository for the Conda ecosystem.

For more tool information ➜

Baget

A lightweight NuGet and symbol server.

An open-source, lightweight implementation of a NuGet server.

For more tool information ➜

Chainguard

The safest way to build and run your code.

Provides secure-by-default container base images and software supply chain tools.

For more tool information ➜

Syft

A CLI tool and Go library for generating a Software Bill of Materials (SBOM) from container images and filesystems.

A powerful open-source tool for generating SBOMs from various sources.

For more tool information ➜

Grype

A vulnerability scanner for container images and filesystems.

An open-source vulnerability scanner that uses Syft for SBOM generation.

For more tool information ➜

Dependency-Track

Continuous SBOM Analysis.

An open-source platform that consumes and analyzes SBOMs for vulnerabilities and risks.

For more tool information ➜