Dieser Report dokumentiert die strukturierte, evidenzbasierte Auswahl einer IT-Lösung für Generic Artefact Manager Services. Er stellt 5 marktrelevante Produkte gegenüber, bewertet sie gegen 123 gewichtete Anforderungen aus 11 Kategorien und leitet daraus ein nachvollziehbares Ranking sowie eine begründete Empfehlung ab.
Standard-Anforderungskatalog ergänzt um projektspezifische Anforderungen aus dem Kunden-Kontext.
Identifikation relevanter Anbieter und Produkte inkl. kompakter Unternehmens-Eckdaten.
Zweistufige Gewichtung: Kategorie-Gewicht × Anforderungs-Gewicht, je Kategorie auf 100 % normalisiert.
Jede Anforderung wird je Produkt anhand einer verankerten 1–5-Skala bewertet und begründet.
Aggregation zu gewichteten Gesamt-Scores, Kategorie-Auswertung und einer begründeten Empfehlung.
Hinweis: Produkt- und Unternehmensdaten sowie die Einzelbewertungen beruhen auf modellgestützter Einschätzung (Quelle: KI-Kontext) und sind als Entscheidungsgrundlage gedacht – sicherheitskritische Punkte sollten vor Vertragsabschluss verifiziert werden.
| Phase | Modell | Calls | Input-Tok. | Output-Tok. | Kosten (geschätzt) |
|---|---|---|---|---|---|
| audit | claude-sonnet-4-6 | 75 | 190,800 | 114,220 | $2.2857 |
| requirements_context | claude-sonnet-4-6 | 1 | 791 | 10,183 | $0.1551 |
| feature_extraction | claude-sonnet-4-6 | 5 | 3,022 | 8,428 | $0.1355 |
| feature_consolidation | claude-sonnet-4-6 | 1 | 2,609 | 4,774 | $0.0794 |
| vendor_discovery | claude-sonnet-4-6 | 1 | 1,042 | 2,083 | $0.0344 |
| recommendation | claude-opus-4-8 | 1 | 918 | 639 | $0.0206 |
| vendor_profile | claude-haiku-4-5 | 5 | 2,314 | 1,613 | $0.0104 |
| Gesamt: | $2.7211 | ||||
Schätzung auf Basis der von der API gemeldeten Token-Nutzung und öffentlicher Listenpreise – keine Rechnung.
🥇 JFrog Artifactory
JFrog · 4.10/5 (77.6%)
JFrog Artifactory wird als Lösung empfohlen und führt das Evaluierungsfeld mit einem Gesamtscore von 4,1 (77,6 %) klar an. Ausschlaggebend sind die herausragende Funktionsabdeckung (4,92), die starke Integrationsfähigkeit (4,73) sowie das umfangreiche Produkt-Feature-Set (4,6), die es vom nächstplatzierten Wettbewerber deutlich abheben.
| ID | Anforderung | JFrog Artifact JFrog | GitLab Package GitLab | Sonatype Nexus Sonatype | Inedo ProGet Inedo | Pulp Pulp Project |
|---|---|---|---|---|---|---|
| Coverage of Functionality | ||||||
| FUNC-01 | Supported Package Formats |
5 | 2 | 4 | 2 | 2 |
| FUNC-02 | Remote Repository Proxying + Caching |
5 | 2 | 5 | 4 | 4 |
| FUNC-03 | Repository Grouping |
5 | 2 | 5 | 3 | 2 |
| FUNC-04 | Artifact Search Capabilities |
5 | 3 | 3 | 3 | 2 |
| FUNC-05 | Metadata Management |
5 | 2 | 3 | 4 | 2 |
| FUNC-06 | Comprehensive REST API |
5 | 4 | 4 | 4 | 5 |
| FUNC-07 | Command-Line Interface (CLI) |
5 | 2 | 2 | 3 | 4 |
| FUNC-08 | CI/CD Integration & Build Info |
5 | 5 | 3 | 3 | 2 |
| FUNC-09 | Webhook/Event Support |
5 | 4 | 4 | 4 | 2 |
| FUNC-10 | Vulnerability Scanning |
5 | 5 | 5 | 4 | 2 |
| FUNC-11 | License Compliance Analysis |
5 | 4 | 5 | 5 | 1 |
| FUNC-12 | Fine-Grained Access Control |
5 | 3 | 4 | 4 | 3 |
| FUNC-13 | Identity Management (IdM) Integration |
5 | 5 | 4 | 4 | 2 |
| FUNC-14 | Artifact Lifecycle Management |
4 | 3 | 4 | 3 | 2 |
| FUNC-15 | Replication & Distribution |
5 | 4 | 3 | 4 | 3 |
| FUNC-16 | Federated Repositories |
5 | 2 | 3 | 3 | 2 |
| FUNC-17 | Import/Export Capabilities |
5 | 4 | 3 | 3 | 4 |
| FUNC-18 | High Availability (HA) Architecture ⚠ |
5 | 4 | 5 | 5 | 3 |
| FUNC-19 | Cloud Storage Integration (Self-Hosted) ⚠ |
5 | 5 | 4 | 5 | 5 |
| FUNC-20 | System Backup & Restore |
4 | 4 | 3 | 3 | 2 |
| Coverage of Data & Business Objects | ||||||
| DATA-01 | Master data objects (e.g. material, supplier, |
3 | 3 | 3 | 3 | 2 |
| DATA-02 | Transactional data objects (sales order, pur |
4 | 4 | 3 | 4 | 3 |
| DATA-03 | Artifact repository domain objects (packages, |
5 | 4 | 4 | 4 | 4 |
| Integration | ||||||
| INT-01 | General Interfaces/APIs |
5 | 4 | 4 | 4 | 3 |
| INT-02 | Interface monitoring |
3 | 3 | 3 | 3 | 2 |
| Non-Functional Requirements | ||||||
| NFR-01 | Authorization |
5 | 3 | 4 | 4 | 4 |
| NFR-02 | IDM connection |
5 | 5 | 3 | 3 | 2 |
| NFR-03 | Single Sign-On |
5 | 5 | 3 | 3 | 3 |
| NFR-04 | Client/Instances |
5 | 5 | 3 | 3 | 3 |
| NFR-05 | Storage of data (Metadata) |
5 | 4 | 4 | 4 | 4 |
| NFR-06 | Artifact Storage Backend (Blob Storage) |
5 | 5 | 4 | 4 | 5 |
| NFR-07 | Artifact Archiving & Cleanup |
4 | 4 | 4 | 4 | 2 |
| NFR-08 | Hosting Flexibility ⚠ |
5 | 5 | 5 | 4 | 4 |
| NFR-09 | Hardware and Component Requirements |
3 | 3 | 4 | 5 | 4 |
| NFR-10 | Installation Mode (automatic / manual) |
4 | 5 | 4 | 4 | 4 |
| NFR-11 | Multi-location Deployment Options ⚠ |
5 | 4 | 4 | 4 | 3 |
| NFR-12 | Application Performance |
5 | 4 | 4 | 4 | 3 |
| NFR-13 | Scalability (manage increase No. of users) |
5 | 4 | 4 | 3 | 3 |
| NFR-14 | Remote Performance for foreign locations |
5 | 3 | 3 | 3 | 3 |
| NFR-15 | Deployment of Customizing --> no coding |
4 | 3 | 4 | 4 | 2 |
| NFR-16 | Deployment of Development --> coding |
4 | 4 | 3 | 3 | 4 |
| NFR-17 | Experience/Possibility with/of offshore devel |
4 | 4 | 4 | 4 | 3 |
| NFR-18 | Flexibility via side-by-side or other extensi |
4 | 4 | 3 | 3 | 4 |
| NFR-19 | Maintenance and consistency of control tables |
5 | 4 | 4 | 4 | 3 |
| NFR-20 | Source code availability |
2 | 4 | 3 | 2 | 5 |
| NFR-21 | Maintenance effort (upgrades & testing) |
4 | 4 | 4 | 3 | 3 |
| NFR-22 | Backup & Recovery/Redundancy layer in case of |
5 | 4 | 4 | 3 | 3 |
| NFR-23 | Availability (Maintenance windows, unannounce ⚠ |
4 | 3 | 3 | 3 | 3 |
| NFR-24 | Availability defined/possible SLA ⚠ |
4 | 3 | 2 | 2 | 1 |
| Usability & User Experience | ||||||
| UX-01 | Ease of Use |
3 | 3 | 3 | 3 | 2 |
| UX-02 | Consistent, seamless user interface |
3 | 4 | 3 | 3 | 2 |
| UX-03 | Explicit user guidance |
3 | 3 | 2 | 3 | 2 |
| UX-04 | Use-case-oriented design |
4 | 4 | 3 | 3 | 2 |
| UX-05 | Flexibility of UI |
3 | 3 | 2 | 2 | 2 |
| UX-06 | Customizable by end-user / user groups |
2 | 3 | 1 | 2 | 1 |
| UX-07 | Language Capabilities |
2 | 3 | 2 | 2 | 1 |
| UX-08 | Design thinking approach |
2 | 3 | 2 | 2 | 1 |
| IT Compliance | ||||||
| COMP-01 | Single Source of Truth for each data object |
3 | 3 | 3 | 3 | 3 |
| COMP-02 | Where is the cloud server located? (country) ⚠ |
4 | 4 | 3 | 3 | 3 |
| COMP-03 | Does the cloud service provide the encryption |
4 | 4 | 4 | 3 | 3 |
| COMP-04 | GDPR and BDSG |
3 | 3 | 3 | 2 | 2 |
| COMP-05 | ISO certificates |
4 | 4 | 3 | 2 | 1 |
| COMP-06 | Data export and import |
5 | 4 | 4 | 4 | 5 |
| Risks & Opportunities | ||||||
| RISK-01 | Dependencies and Lock-In from Software Vendor |
2 | 2 | 3 | 4 | 5 |
| RISK-02 | Project team setup and continuity |
4 | 4 | 4 | 3 | 3 |
| RISK-03 | Time to Market |
4 | 4 | 4 | 4 | 2 |
| RISK-04 | Skill of supplier |
4 | 4 | 4 | 2 | 2 |
| RISK-05 | Size of supplier (Skalierbarkeit für Großkund |
4 | 4 | 3 | 2 | 3 |
| RISK-06 | World wide rollout |
4 | 4 | 3 | 2 | 2 |
| RISK-07 | Dependencies to other strategic projects |
3 | 4 | 3 | 3 | 3 |
| RISK-08 | Development method (agile or waterfall) |
5 | 5 | 4 | 4 | 4 |
| Total Cost of Ownership | ||||||
| TCO-01 | Setup/Project Costs |
2 | 4 | 3 | 4 | 2 |
| TCO-02 | Implementation Costs |
2 | 4 | 3 | 4 | 2 |
| TCO-03 | Maintenance / Operation Costs |
2 | 3 | 2 | 3 | 2 |
| TCO-04 | License Costs |
2 | 4 | 3 | 5 | 5 |
| TCO-05 | expected benefit/efficiency |
4 | 4 | 4 | 4 | 3 |
| Support & Operations | ||||||
| SUP-01 | 1st level |
4 | 3 | 3 | 2 | 1 |
| SUP-02 | 2nd level |
4 | 4 | 3 | 3 | 1 |
| SUP-03 | 3rd level |
4 | 4 | 4 | 3 | 2 |
| SUP-04 | General support concept/approach |
4 | 4 | 3 | 2 | 1 |
| SUP-05 | SLA for tickets |
4 | 4 | 3 | 2 | 1 |
| SUP-06 | Support coverage |
4 | 4 | 3 | 1 | 1 |
| SUP-07 | Training, tool documentation |
5 | 4 | 4 | 3 | 3 |
| Projektspezifische Anforderungen | ||||||
| CTX-01 | Verbindliche Self-Hosted Deployment Option |
5 | 4 | 5 | 5 | 5 |
| CTX-02 | Migrationspfad von JFrog Artifactory |
2 | 2 | 3 | 2 | 1 |
| CTX-03 | Universelle Artefakt-Repository-Unterstützung |
5 | 4 | 4 | 4 | 3 |
| CTX-04 | Skalierbarkeit für 50.000 Benutzer |
5 | 3 | 3 | 2 | 2 |
| CTX-05 | Transparenz des Lizenzmodells für Verhandlung |
3 | 4 | 3 | 5 | 5 |
| CTX-06 | Open-Source-Tauglichkeit und Pulp Project Bew |
2 | 4 | 5 | 3 | 4 |
| CTX-07 | Native CI/CD-Tool-Integrationen |
5 | 4 | 4 | 3 | 2 |
| CTX-08 | Unterstützung des Beschaffungsprozesses durch |
5 | 4 | 4 | 3 | 1 |
| CTX-09 | Proxy-Repository und Upstream-Caching Funktio |
5 | 3 | 5 | 5 | 4 |
| CTX-10 | Software Supply Chain Security und SBOM-Unter |
5 | 4 | 4 | 4 | 2 |
| CTX-11 | Multi-Site Replikation und Geo-Redundanz |
5 | 3 | 3 | 3 | 2 |
| CTX-12 | Kubernetes-native Deployment und Helm-Chart-U |
5 | 4 | 4 | 3 | 4 |
| CTX-13 | Flexibles Storage-Backend für Self-Hosted |
5 | 4 | 3 | 3 | 4 |
| CTX-14 | Vollständige REST API und Infrastructure-as-C |
5 | 5 | 3 | 3 | 4 |
| CTX-15 | Granulares Permission-Modell auf Repository-E |
5 | 4 | 4 | 4 | 3 |
| CTX-16 | Vendor-Stabilität und Marktreife als Alternat |
5 | 5 | 5 | 3 | 1 |
| CTX-17 | Risikoarmes Upgrade-Verfahren und Long-Term-S |
5 | 3 | 3 | 3 | 3 |
| CTX-18 | Datenbankunterstützung und externe Datenbank- |
5 | 3 | 3 | 2 | 3 |
| CTX-19 | Artefakt-Nutzungsanalyse und Storage-Optimier |
5 | 3 | 3 | 3 | 2 |
| CTX-20 | Proof-of-Concept-Unterstützung und Trial-Verf |
4 | 4 | 4 | 4 | 5 |
| Produkt-Features | ||||||
| FEAT-104 | Hochverfügbarkeit & Clustering |
5 | 4 | 4 | 4 | 3 |
| FEAT-105 | Horizontale Skalierbarkeit |
5 | 4 | 3 | 3 | 4 |
| FEAT-106 | Pluggable Storage-Backend |
5 | 5 | 4 | 3 | 4 |
| FEAT-107 | Content-Deduplizierung |
5 | 3 | 3 | 2 | 5 |
| FEAT-108 | Automatisiertes Cleanup & Disk-Management |
4 | 3 | 4 | 3 | 3 |
| FEAT-109 | Vulnerability Scanning & CVE-Analyse |
5 | 5 | 5 | 4 | 1 |
| FEAT-110 | Quarantäne & automatische Blockierung unsiche |
5 | 3 | 5 | 4 | 1 |
| FEAT-111 | SBOM-Generierung & Export |
5 | 4 | 4 | 2 | 1 |
| FEAT-112 | Paket-Genehmigungsworkflow (Approval Workflow |
3 | 2 | 3 | 5 | 2 |
| FEAT-113 | Granulare Zugriffskontrolle & Content-Filteru |
5 | 4 | 4 | 4 | 3 |
| FEAT-114 | Artefakt-Signierung (Content Signing) |
4 | 3 | 3 | 2 | 4 |
| FEAT-115 | Typosquatting- & Malicious-Package-Erkennung |
3 | 2 | 5 | 4 | 1 |
| FEAT-116 | Staging & Promotion Workflows |
5 | 4 | 4 | 4 | 2 |
| FEAT-117 | Release-Management & Artifact-Bundles |
5 | 5 | 2 | 2 | 2 |
| FEAT-118 | Detailliertes Audit-Logging |
5 | 4 | 3 | 4 | 2 |
| FEAT-119 | Build-to-Artifact-Traceability |
5 | 5 | 2 | 3 | 1 |
| FEAT-120 | Kubernetes-natives Deployment (Operator/Helm) |
5 | 5 | 3 | 2 | 4 |
| FEAT-121 | Air-Gapped / Offline-Betrieb |
5 | 3 | 5 | 4 | 5 |
| FEAT-122 | Pull-Through-Cache / Proxy-Repository |
5 | 3 | 5 | 4 | 4 |
| FEAT-123 | Kostenfreie / Open-Source-Basistier |
3 | 4 | 5 | 5 | 5 |
| ID | Name | Beschreibung | Quelle | Anwendbarkeit |
|---|---|---|---|---|
| FUNC-01 | Supported Package Formats | Ability to natively manage a wide range of package formats (e.g., Maven, npm, PyPI, Docker, Conan, NuGet). | standard | |
| FUNC-02 | Remote Repository Proxying + Caching | Ability to proxy public repositories (e.g., Maven Central, npmjs.org) and act as a cache. | standard | |
| FUNC-03 | Repository Grouping | Ability to group multiple repositories (local, remote) into a single logical URL (e.g., "virtual repositories"). | standard | |
| FUNC-04 | Artifact Search Capabilities | Provides advanced search for artifacts based on metadata, filenames, checksums, or properties. | standard | |
| FUNC-05 | Metadata Management | Ability to enrich artifacts with custom metadata and properties (key-value pairs). | standard | |
| FUNC-06 | Comprehensive REST API | Provides a complete and well-documented REST API to automate all aspects of repository management. | standard | |
| FUNC-07 | Command-Line Interface (CLI) | "Provides a native CLI for simple interaction and integration into scripts and CI/CD processes. | standard | |
| FUNC-08 | CI/CD Integration & Build Info | "Deep integration with CI/CD tools (e.g., Jenkins, GitLab CI) and the ability to store ""Build Info"" (which build produ… | standard | |
| FUNC-09 | Webhook/Event Support | Ability to trigger webhooks on specific events (e.g., artifact upload, deletion) to start downstream processes. | standard | |
| FUNC-10 | Vulnerability Scanning | Native ability to scan artifacts and their dependencies for known security vulnerabilities (CVEs). | standard | |
| FUNC-11 | License Compliance Analysis | Ability to analyze component licenses and enforce policies to ensure license compliance. | standard | |
| FUNC-12 | Fine-Grained Access Control | Detailed permission management based on users/groups for repositories, paths, and individual artifacts. | standard | |
| FUNC-13 | Identity Management (IdM) Integration | Ability to connect to external identity providers like LDAP, Active Directory (AD), or SAML/OAuth for Single Sign-On (SS… | standard | |
| FUNC-14 | Artifact Lifecycle Management | Provides configurable rules to automatically manage the lifecycle of artifacts, including their deletion or movement to … | standard | |
| FUNC-15 | Replication & Distribution | Ability for (multi-site) replication of repositories between different instances to support distributed teams and for di… | standard | |
| FUNC-16 | Federated Repositories | Ability to create a federation of multiple, geographically distributed instances that behave as a single logical reposit… | standard | |
| FUNC-17 | Import/Export Capabilities | Provides robust functions for importing and exporting repository content and configurations for easy migrations. (Phase … | standard | |
| FUNC-18 | High Availability (HA) Architecture | Describes the native architecture for achieving high availability and redundancy. | standard | ⚠ eingeschränkt |
| FUNC-19 | Cloud Storage Integration (Self-Hosted) | For self-hosted deployments, the ability to use cloud-native object storage (e.g., Amazon S3, Azure Blob Storage) as the… | standard | ⚠ eingeschränkt |
| FUNC-20 | System Backup & Restore | Provides a comprehensive, integrated mechanism for backing up and restoring the entire system state, including configura… | standard |
| ID | Name | Beschreibung | Quelle | Anwendbarkeit |
|---|---|---|---|---|
| DATA-01 | Master data objects (e.g. material, supplier, …) | Evaluates whether the solution can natively represent and enrich enterprise-relevant master-data-like structures around … | standard | |
| DATA-02 | Transactional data objects (sales order, purchase order, …) | Evaluates support for transactional or event-oriented data objects related to artifact lifecycle, such as publish histor… | standard | |
| DATA-03 | Artifact repository domain objects (packages, repositories, versions, metadata) | Evaluates how well the solution models the core domain objects of an enterprise artifact repository, such as repositorie… | standard |
| ID | Name | Beschreibung | Quelle | Anwendbarkeit |
|---|---|---|---|---|
| INT-01 | General Interfaces/APIs | - What kind of interface technologies are supported (e.g., Web Services, REST-APIs, …)? - Is there a documentation for a… | standard | |
| INT-02 | Interface monitoring | - Are there any functionalities to monitor the availability and performance of connected interfaces? | standard |
| ID | Name | Beschreibung | Quelle | Anwendbarkeit |
|---|---|---|---|---|
| NFR-01 | Authorization | - How flexible is the creation and adapation of authorizations and roles? - Are there predefined or recommended roles an… | standard | |
| NFR-02 | IDM connection | - Can user and role creation/provisioning/deletion be automated? - Is connection to active directory roles (using SCIM) … | standard | |
| NFR-03 | Single Sign-On | - Is Single-Sign-On supported using Azure AD (EntraID) with OIDC or SAML2.0 protocoll? - Can the customer configure the … | standard | |
| NFR-04 | Client/Instances | - is a (data) separation of several instances/clients supported? | standard | |
| NFR-05 | Storage of data (Metadata) | Evaluates the architecture for storing application metadata. Enterprise-readiness is demonstrated by the mandatory use o… | standard | |
| NFR-06 | Artifact Storage Backend (Blob Storage) | Evaluates the flexibility in choosing the storage backend for the actual artifacts (blobs). The ability to use modern, s… | standard | |
| NFR-07 | Artifact Archiving & Cleanup | How is the archiving of data supported and what options can be configured by the customer? | standard | |
| NFR-08 | Hosting Flexibility | Is hosting as SaaS supported? - running on preferred Hyperscalers (AWS, Azure)? Is hosting as PaaS supported? - flexibi… | standard | ⚠ eingeschränkt |
| NFR-09 | Hardware and Component Requirements | - What are the minimum and recommended hardware requirements for installing the solution? (e.g., memory, CPU cores, hard… | standard | |
| NFR-10 | Installation Mode (automatic / manual) | - What are the steps for installing the solution? - Is there an automated installation process available? | standard | |
| NFR-11 | Multi-location Deployment Options | - What are the deployment options for a distributed environment? - Is a central data repository supported when using a m… | standard | ⚠ eingeschränkt |
| NFR-12 | Application Performance | Evaluates expected response and execution performance for typical package operations (browse/search/publish/download), c… | standard | |
| NFR-13 | Scalability (manage increase No. of users) | Evaluates behavior under high concurrency and parallel transactions, including scaling options, queue/task handling, and… | standard | |
| NFR-14 | Remote Performance for foreign locations | Evaluates sensitivity to bandwidth and latency in distributed usage (including remote/offshore teams), and whether archi… | standard | |
| NFR-15 | Deployment of Customizing --> no coding | Ability to configure and customize the solution behavior without writing custom code, including role/permission setup, f… | standard | |
| NFR-16 | Deployment of Development --> coding | Ability for customer-side teams to implement code-based extensions/integrations, including APIs, scripting/plugin models… | standard | |
| NFR-17 | Experience/Possibility with/of offshore development | Ability to onboard and govern distributed or offshore development teams through external user integration, role-based ac… | standard | |
| NFR-18 | Flexibility via side-by-side or other extension points | Evaluates whether the platform provides supported extension points for side-by-side capabilities, such as plugins, scrip… | standard | |
| NFR-19 | Maintenance and consistency of control tables | Assesses how easily repository/feed control structures (for example repository/feed definitions, access/permission rules… | standard | |
| NFR-20 | Source code availability | Evaluates source-code availability and modifiability of the product itself, including whether customers can review inter… | standard | |
| NFR-21 | Maintenance effort (upgrades & testing) | Evaluates release/maintenance model for functionality upgrades, bug fixes, and security updates, including release caden… | standard | |
| NFR-22 | Backup & Recovery/Redundancy layer in case of break down | Evaluates resilience concepts for hardware/software failure, including high-availability patterns, backup/restore option… | standard | |
| NFR-23 | Availability (Maintenance windows, unannounced maintenance) | Evaluates whether planned updates can be applied with no or low downtime, considering rolling/blue-green capabilities, m… | standard | ⚠ eingeschränkt |
| NFR-24 | Availability defined/possible SLA | Evaluates formal availability commitments (SLA) and practical service availability expectations, including whether the p… | standard | ⚠ eingeschränkt |
| ID | Name | Beschreibung | Quelle | Anwendbarkeit |
|---|---|---|---|---|
| UX-01 | Ease of Use | Evaluates how quickly typical users can understand and use core package/repository workflows (browse, search, publish, c… | standard | |
| UX-02 | Consistent, seamless user interface | Evaluates visual and interaction consistency across the product experience, and practical ability to align appearance/us… | standard | |
| UX-03 | Explicit user guidance | Evaluates explicit in-product guidance (assistants/wizards, contextual help, guided setup steps) for complex setup and o… | standard | |
| UX-04 | Use-case-oriented design | Evaluates whether the UI design fits real artifact-repository use cases (developer and admin tasks), including clarity o… | standard | |
| UX-05 | Flexibility of UI | Evaluates productivity features for experienced users, including shortcuts, efficient navigation, and fast filtering/sea… | standard | |
| UX-06 | Customizable by end-user / user groups | Evaluates end-user and group-level adaptability of the interface, including personal preferences (theme/layout/behavior)… | standard | |
| UX-07 | Language Capabilities | Evaluates language and localization capabilities in the UI (multi-language support, locale/time settings) and practical … | standard | |
| UX-08 | Design thinking approach | Evaluates accessibility and inclusive interaction support (keyboard accessibility and efficient non-mouse operation) for… | standard |
| ID | Name | Beschreibung | Quelle | Anwendbarkeit |
|---|---|---|---|---|
| COMP-01 | Single Source of Truth for each data object | - prevent replication of data wherever possible - usage of data from leading source systems (e.g. REF-MDS)by APIs | standard | |
| COMP-02 | Where is the cloud server located? (country) | - Does the vendor have cloud infrastructure in relevant countries? (e.g., EU, CN) - Does the vendor use a den bevorzugte… | standard | ⚠ eingeschränkt |
| COMP-03 | Does the cloud service provide the encryption of data at rest and in transit? | - Which kind of data are affected? - SC0,1,2,3 for confidentiality, availability, integrity | standard | |
| COMP-04 | GDPR and BDSG | - Are there further subcontractors with access to personal related data? - Is the cloud service provider compliant with … | standard | |
| COMP-05 | ISO certificates | - Does the cloud service provider (or Data Processor) hold an ISO 27001 certification? | standard | |
| COMP-06 | Data export and import | - Does the cloud service provider support data export (and import)? - Additional manual download/upload functions possib… | standard |
| ID | Name | Beschreibung | Quelle | Anwendbarkeit |
|---|---|---|---|---|
| RISK-01 | Dependencies and Lock-In from Software Vendor | The target is to minimize lock-in risks - How easy is it to de-integrate solution if necessary? - How easy is it to repl… | standard | |
| RISK-02 | Project team setup and continuity | - How is the setup of the development team? (Junior/Senior)? - Is the development team stable or are the fluctuations th… | standard | |
| RISK-03 | Time to Market | - How fast could a provider setup a possible project team (lead time)? - How fast can the solution be used productively? | standard | |
| RISK-04 | Skill of supplier | - What is the skill setup of possible project team? (Consulting/Concept/Implementation/Deployment) - What are the experi… | standard | |
| RISK-05 | Size of supplier (Skalierbarkeit für Großkunden), risk of insolvency | - How many employees in the company are working on supporting and developing the solution? | standard | |
| RISK-06 | World wide rollout | - Are there regional support teams and experiences in rollout and support of the solution across different regions? | standard | |
| RISK-07 | Dependencies to other strategic projects | - Are there positive or negative dependencies to other projects or programs e.g. S/4HANA etc. (regarding time, functiona… | standard | |
| RISK-08 | Development method (agile or waterfall) | - Which development methods (agile, waterfall or combination) are supported by the developer and does it fit to the type… | standard |
| ID | Name | Beschreibung | Quelle | Anwendbarkeit |
|---|---|---|---|---|
| TCO-01 | Setup/Project Costs | e.g., one-time costs for project setup, organization, concept.. | standard | |
| TCO-02 | Implementation Costs | e.g., development and customizing costs | standard | |
| TCO-03 | Maintenance / Operation Costs | Evaluates recurring maintenance and operational effort, including platform administration and day-2 operations. | standard | |
| TCO-04 | License Costs | Charging model (User, volume, …)? | standard | |
| TCO-05 | expected benefit/efficiency | Cost impact in subsequent years based on improved efficiencies | standard |
| ID | Name | Beschreibung | Quelle | Anwendbarkeit |
|---|---|---|---|---|
| SUP-01 | 1st level | - How can the 1st level support (e.g. hotlines) be organized in collaboration with the vendor of this solution? | standard | |
| SUP-02 | 2nd level | - How can the 2nd level support be organized in collaboration with the vendor of this solution? | standard | |
| SUP-03 | 3rd level | - How can the 3rd level support (e.g. bugfixing process) be organized in collaboration with the vendor of this solution? | standard | |
| SUP-04 | General support concept/approach | - Which support is offered by the vendor? - How can des Kunden be integrated into the support process? - Can the vendor … | standard | |
| SUP-05 | SLA for tickets | - Is there an SLA on how fast tickets are solved? - What are solution times for high, medium, low tickets? | standard | |
| SUP-06 | Support coverage | - Does the support cover 24/7 - Are there regional differences? | standard | |
| SUP-07 | Training, tool documentation | - Does the vendor offer trainings (tool embedded, videos, webinar, face to face, remote, ...)? - Are there specific trai… | standard |
| ID | Name | Beschreibung | Quelle | Anwendbarkeit |
|---|---|---|---|---|
| CTX-01 | Verbindliche Self-Hosted Deployment Option | Jede Lösung muss eine vollständig funktionsfähige, produktionsreife Self-Hosted/On-Premise Deployment-Option anbieten. S… | context | |
| CTX-02 | Migrationspfad von JFrog Artifactory | Da JFrog Artifactory das aktuelle Produktivsystem ist, muss der Anbieter nachweisbare Werkzeuge, Dokumentation und Migra… | context | |
| CTX-03 | Universelle Artefakt-Repository-Unterstützung | Als universelles Artefakt-Repository muss die Lösung alle gängigen Package-Formate nativ unterstützen, die typischerweis… | context | |
| CTX-04 | Skalierbarkeit für 50.000 Benutzer | Die Lösung muss nachweislich auf bis zu 50.000 gleichzeitig aktive Benutzer skalierbar sein. Dies beinhaltet horizontale… | context | |
| CTX-05 | Transparenz des Lizenzmodells für Verhandlungsgrundlage | Da ein zentrales Ziel dieser Evaluierung die Stärkung der Verhandlungsposition gegenüber JFrog ist, müssen alle Anbieter… | context | |
| CTX-06 | Open-Source-Tauglichkeit und Pulp Project Bewertungsrahmen | Der Open-Source-Kandidat Pulp Project muss nach denselben Enterprise-Kriterien bewertet werden wie kommerzielle Produkte… | context | |
| CTX-07 | Native CI/CD-Tool-Integrationen | Das Repository-Management muss nahtlos in bestehende CI/CD-Ökosysteme integrierbar sein. Erforderlich sind native Plugin… | context | |
| CTX-08 | Unterstützung des Beschaffungsprozesses durch den Vendor | Da die Evaluierung primär die Procurement-Abteilung bei Lizenzverhandlungen unterstützen soll, müssen Anbieter in der La… | context | |
| CTX-09 | Proxy-Repository und Upstream-Caching Funktionalität | Eine Kernfunktion universeller Repository-Manager ist das Proxying und Caching von öffentlichen Upstream-Repositories (z… | context | |
| CTX-10 | Software Supply Chain Security und SBOM-Unterstützung | Im Kontext moderner DevSecOps-Anforderungen muss der Repository-Manager Funktionen zur Absicherung der Software Supply C… | context | |
| CTX-11 | Multi-Site Replikation und Geo-Redundanz | Für Enterprise-Deployments mit bis zu 50.000 Benutzern und potenziell globaler Verteilung müssen Funktionen für Multi-Si… | context | |
| CTX-12 | Kubernetes-native Deployment und Helm-Chart-Unterstützung | Für moderne Enterprise-Deployments muss die Lösung selbst Kubernetes-native betrieben werden können. Dies erfordert: off… | context | |
| CTX-13 | Flexibles Storage-Backend für Self-Hosted | Im Self-Hosted-Betrieb müssen Unternehmen flexibel in der Wahl ihres Storage-Backends sein. Die Lösung soll mindestens f… | context | |
| CTX-14 | Vollständige REST API und Infrastructure-as-Code-Unterstützung | Für Enterprise-Automatisierung und GitOps-Workflows muss die gesamte Administrationsfunktionalität über eine dokumentier… | context | |
| CTX-15 | Granulares Permission-Modell auf Repository-Ebene | Bei 50.000 Benutzern ist ein feinkörniges, skalierbares Berechtigungsmodell unabdingbar. Die Lösung muss RBAC auf Reposi… | context | |
| CTX-16 | Vendor-Stabilität und Marktreife als Alternative zu JFrog | Da die Evaluierung explizit zur Stärkung der Verhandlungsposition gegenüber JFrog dient, müssen alternative Anbieter ein… | context | |
| CTX-17 | Risikoarmes Upgrade-Verfahren und Long-Term-Support | Für Enterprise-Kunden mit kritischen Produktionsdeployments sind stabile, risikoarme Upgrade-Pfade und definierte Long-T… | context | |
| CTX-18 | Datenbankunterstützung und externe Datenbank-Kompatibilität | Im Self-Hosted Enterprise-Betrieb muss die Repository-Lösung in bestehende Datenbankinfrastrukturen integrierbar sein. U… | context | |
| CTX-19 | Artefakt-Nutzungsanalyse und Storage-Optimierungsreports | Bei großen Repository-Deployments mit potenziell vielen TB an gespeicherten Artefakten sind umfassende Analyse- und Repo… | context | |
| CTX-20 | Proof-of-Concept-Unterstützung und Trial-Verfügbarkeit | Um eine fundierte Evaluierungsentscheidung zu ermöglichen, müssen Anbieter eine unkomplizierte Möglichkeit bieten, die L… | context |
| ID | Name | Beschreibung | Quelle | Anwendbarkeit |
|---|---|---|---|---|
| FEAT-104 | Hochverfügbarkeit & Clustering | Die Lösung soll native Unterstützung für HA-Cluster-Setups bieten, um Single Points of Failure zu eliminieren und unterb… | feature | |
| FEAT-105 | Horizontale Skalierbarkeit | Die Lösung soll durch horizontales Skalieren einzelner Komponenten (API, Worker, Storage) wachsenden Last- und Durchsatz… | feature | |
| FEAT-106 | Pluggable Storage-Backend | Die Lösung soll verschiedene Storage-Backends unterstützen (lokales Dateisystem, S3-kompatible Object-Stores, NFS etc.),… | feature | |
| FEAT-107 | Content-Deduplizierung | Identische Artefakte sollen nur einmal physisch gespeichert werden (z. B. via Content-Adressierung/Hash-basierung), um S… | feature | |
| FEAT-108 | Automatisiertes Cleanup & Disk-Management | Die Lösung soll konfigurierbare, automatisierte Richtlinien zur Bereinigung veralteter, ungenutzter oder abgelaufener Ar… | feature | |
| FEAT-109 | Vulnerability Scanning & CVE-Analyse | Die Lösung soll Artefakte auf bekannte Sicherheitslücken (CVEs) scannen können – entweder nativ oder über eine tiefe Int… | feature | |
| FEAT-110 | Quarantäne & automatische Blockierung unsicherer Artefakte | Die Lösung soll in der Lage sein, Artefakte, die Sicherheitsrichtlinien verletzen, automatisch in Quarantäne zu verschie… | feature | |
| FEAT-111 | SBOM-Generierung & Export | Die Lösung soll Software Bills of Materials (SBOMs) für Artefakte und Abhängigkeiten erzeugen und in gängigen Formaten (… | feature | |
| FEAT-112 | Paket-Genehmigungsworkflow (Approval Workflow) | Die Lösung soll einen formalisierten Genehmigungsprozess für Pakete aus externen Quellen unterstützen, sodass nur expliz… | feature | |
| FEAT-113 | Granulare Zugriffskontrolle & Content-Filterung | Die Lösung soll feingranulare Zugriffskontrollen auf Repository- oder Paket-Ebene ermöglichen, inklusive der Möglichkeit… | feature | |
| FEAT-114 | Artefakt-Signierung (Content Signing) | Die Lösung soll das kryptografische Signieren von Artefakten und/oder Repository-Metadaten unterstützen, um die Integrit… | feature | |
| FEAT-115 | Typosquatting- & Malicious-Package-Erkennung | Die Lösung soll Mechanismen bereitstellen, um potenziell bösartige Pakete zu erkennen, die interne Paketnamen imitieren … | feature | |
| FEAT-116 | Staging & Promotion Workflows | Die Lösung soll mehrstufige Promotion-Workflows unterstützen, bei denen Artefakte definierte Qualitätsgates (z. B. Test,… | feature | |
| FEAT-117 | Release-Management & Artifact-Bundles | Die Lösung soll die Bündelung mehrerer Artefakte (Packages, Binaries, Quellarchive) zu einem versionierten Release ermög… | feature | |
| FEAT-118 | Detailliertes Audit-Logging | Die Lösung soll ein vollständiges und manipulationssicheres Audit-Log aller relevanten Aktionen (Uploads, Downloads, Lös… | feature | |
| FEAT-119 | Build-to-Artifact-Traceability | Die Lösung soll Artefakte mit den Build-Metadaten (Build-Job, Commit, Pipeline, Branch) verknüpfen, die sie erzeugt habe… | feature | |
| FEAT-120 | Kubernetes-natives Deployment (Operator/Helm) | Die Lösung soll für den Betrieb auf Kubernetes geeignet sein und ein offizielles, gut gepflegtes Deployment-Artefakt (He… | feature | |
| FEAT-121 | Air-Gapped / Offline-Betrieb | Die Lösung soll den Betrieb in vollständig isolierten Netzwerkumgebungen (Air-Gapped) unterstützen, inklusive Import-/Ex… | feature | |
| FEAT-122 | Pull-Through-Cache / Proxy-Repository | Die Lösung soll als Caching-Proxy für externe Paketquellen (z. B. npmjs.com, Docker Hub, PyPI) fungieren können, um Band… | feature | |
| FEAT-123 | Kostenfreie / Open-Source-Basistier | Die Lösung soll eine dauerhaft kostenfreie oder Open-Source-Basisversion bereitstellen, die Kernfunktionalität für klein… | feature |