Average Ratings 0 Ratings
Average Ratings 0 Ratings
Description
Craftifact serves as a European SaaS platform designed for software teams that require dependable package distribution alongside enhanced supply-chain transparency. It offers various repository types including hosted, proxy, and group repositories for technologies such as Maven, npm, Python, OCI/Docker, and Go, all accompanied by a user-friendly browser interface for managing artifact metadata and repositories. Users can upload CycloneDX SBOMs and, for certain hosted items, generate them to be associated with specific artifacts or OCI digests. Teams have the capability to scrutinize dependencies and assess vulnerability, licensing, exposed-secret, and policy alerts in close proximity to the associated artifact. Access management is facilitated through OIDC, RBAC, group configurations, robot accounts, and scoped tokens, all supported by APIs designed for CI/CD and evidence workflows. Operated by a German firm under EU jurisdiction, Craftifact includes features such as managed updates, monitoring, and backups within the plan’s scope, ensuring predictable pricing that does not rely on seat counts. While it aids teams in fulfilling CRA-relevant technical preparations, it is important to note that it does not serve as a substitute for legal advice or conformity assessments. This combination of features makes Craftifact an essential tool for teams focused on both efficiency and compliance in their software development processes.
Description
CycloneDX is an efficient standard for Software Bill of Materials (SBOM) that is specifically crafted for application security and the analysis of supply chain components. The governance and ongoing development of this specification are overseen by the CycloneDX Core working group, which has its roots in the OWASP community. A thorough and precise catalog of both first-party and third-party components is crucial for identifying potential risks. Ideally, BOMs should encompass all direct and transitive components, as well as the interdependencies that exist among them. By implementing CycloneDX, organizations can swiftly fulfill essential requirements and progressively evolve to incorporate more advanced applications in the future. Furthermore, CycloneDX meets all SBOM criteria set forth in the OWASP Software Component Verification Standard (SCVS), ensuring comprehensive compliance and security management. This capability makes it an invaluable tool for organizations aiming to enhance their software supply chain integrity.
API Access
Has API
No
API Access
Has API
No
Integrations
Anchore
No
ArmorCode
No
Bytesafe
No
Cloudsmith
No
Contrast Security
No
Cybeats
No
Cybellum
No
Debricked
No
DefectDojo
No
Endor Labs
No
Integrations
Anchore
Yes
ArmorCode
Yes
Bytesafe
Yes
Cloudsmith
Yes
Contrast Security
Yes
Cybeats
Yes
Cybellum
Yes
Debricked
Yes
DefectDojo
Yes
Endor Labs
Yes
Pricing Details
€99/month
Optional add-ons and annual discount available.
Free Trial
Yes
Free Version
No
Pricing Details
No price information available.
Free Trial
No
Free Version
No
Deployment
Web-Based
Yes
On-Premises
No
iPhone App
No
iPad App
No
Android App
No
Windows
No
Mac
No
Linux
No
Chromebook
No
Deployment
Web-Based
Yes
On-Premises
No
iPhone App
No
iPad App
No
Android App
No
Windows
No
Mac
No
Linux
No
Chromebook
No
Customer Support
Business Hours
No
Live Rep (24/7)
No
Online Support
Yes
Customer Support
Business Hours
No
Live Rep (24/7)
No
Online Support
Yes
Types of Training
Training Docs
Yes
Webinars
No
Live Training (Online)
No
In Person
No
Types of Training
Training Docs
No
Webinars
No
Live Training (Online)
No
In Person
No
Vendor Details
Company Name
SoluForge
Founded
2025
Country
Germany
Website
craftifact.com
Vendor Details
Company Name
CycloneDX
Website
cyclonedx.org