@cloudsmith

Ship trusted software, fast. Cloud-native artifact management for the AI era — security enforced before packages reach your build environment.

The Cloud (obviously)
Joined October 2015
We’ve joined @chainguard_dev's Athena as a mitigation partner. @alancarson shares why.
1
1
85
Open source registries changed how the world builds software. Protecting them as trustworthy, shared infrastructure, especially as they come under growing pressure from AI-powered threat actors, is a team sport. Here’s to a safer open source ecosystem for every developer 🤝
Athena's coalition is growing today with new shield and surface partners: @Ahead, @ApiiroSecurity, @cloudsmith, @hcltech, @manifestcyber, @OligoSecurity, @PaloAltoNtwks, @ReversingLabs, @trysurfai, and @sysdig Shield partners turn Athena's vulnerability and patch data into mitigations like firewall rules and exploit blocking. Surface partners flag vulnerable software in an organization's stack and show how to fix it. Together, these partners help close the gap between a fix existing and a fix being deployed. Learn more: chainguard.dev/unchained/ath…
2
5
256
🚀 Now live: policy management and continuous risk detection, open to everyone on Cloudsmith. Write the rules once and enforce them at the repo level, across every pipeline and every developer and agent pulling code in. See it in action. cloudsmith.com/product/softw…
1
68
Most security tools find problems after they're already in your environment. A dependency firewall catches them at the door before a bad package ever reaches a build. Here's what that actually looks like. cloudsmith.com/blog/how-to-u…
1
57
Every container inherits its base image. If that image carries unpatched CVEs, your app does too, before you've written a line of code. Here's how to make @wiz_io WizOS hardened images the frictionless default across your org. cloudsmith.com/blog/start-se…
2
95
The logic is rather simple: if you can compromise the framework itself, you have the ability to compromise highly sensitive infrastructure. Today, it's happened again - this time #Mastra was the target. Full attack breakdown: cloudsmith.com/blog/inside-t…
72
Move fast (with guardrails).
1
1
56
Your artifact registry and your deployment tool shouldn't be strangers. Cloudsmith decides what's allowed. @OctopusDeploy controls how it ships. Governance baked in, not bolted on. cloudsmith.com/blog/from-tru…
1
74
Valid SLSA attestations. Legitimate OIDC tokens. 73 repos down. The Miasma worm shows why signed isn't the same as safe. cloudsmith.com/blog/miasma-w…
61
AI coding tools are pulling in dependencies faster than any senior engineer can review them. AI's speed, matched with automation, guardrails, and a strong artifact management layer, provides a secure development foundation. Here's how we think about it. ↓
1
41
Join @cloudsmith, @rootlyhq, Mend.io, @ClickHouseDB, and @Docker in NYC for an evening of cocktails, conversations, and connections. 📍 Diamante’s | 410 8th Ave, NYC 📅 Wed, June 17 | 5:30-8:30 PM 🍸 RSVP: luma.com/odgqf98e?utm_source…
1
128
Are you at PlatformCon London? Join Spacelift and Cloudsmith TONIGHT at F1 Arcade London for an evening where competitive racing meets DevOps and platform engineering. Connect with peers, test your skills on full-spec racing simulators, and explore how to optimize your DevOps for both speed and control. 📅 Date: Wednesday, 25 June ⏰ Time: 7:00 PM - 10:00 PM BST 📍 Location: F1 Arcade London - 1 New Change, London EC4M 9AF, United Kingdom 🔥 Space is limited—reserve your spot now! 🔥 👉 events.spacelift.io/iac-gran… See you there!
1
4
1,062
Is your Helm a risk? 🔍 If your business or open-source project relies on Helm charts, join Nigel Douglas, Head of Developer Relations at Cloudsmith, in a hands-on, virtual workshop during PlatformCon 2025: "What Supply Chain Risks Are Hidden in Your Helm Charts?" Join this hands-on workshop to explore real-world Helm vulnerabilities and learn practical strategies to automate and strengthen your Kubernetes security posture. Reserve your spot 👉 platformcon.com/sessions/wha… 🗓️ Friday, 27 June at 4:00 PM BST / 11:00 AM EST 📍 Virtual #PlatformEngineering #PlatformCon2025 #KubernetesSecurity #Helm
1
1
4
828