Everything Cloudsmith shipped in Q3 2026

In Q3 we further improved platform security capabilities and enhanced developer experience.

In total, we published 25 changelog entries this quarter. This roundup provides a brief overview of each.

Policy and risk detection

Policy management and risk detection are key security features in Cloudsmith and they reached general availability this quarter.

Policy management

This is Cloudsmith’s policy engine that allows users to write policy-as-code across the web app, API, and Terraform provider.

With policy management you can write custom policies in Rego that are automatically enforced across your Cloudsmith account. This includes cooldown policies that hold newly released packages for a set period (see more on these below), policy templates to get started quickly, and decision logs that record evaluation. Everything lives under the Policies tab in the main navigation.

With policy management, rules about which packages are safe and acceptable are automatically enforced on every package at the registry, before they reach your build environment. Changes in threat intelligence or updates to policies automatically trigger re-evaluation so your risk exposure is always current.

Continuous risk detection

This feature automatically checks incoming packages and those already in your repository against known vulnerabilities and malicious packages. Detection is powered by OSV.dev, which triggers new evaluations as new threat intelligence hits the data feed.

This feature helps compress the gap between when new threat advisories are published and when organizations evaluate packages against those advisories. Because this feature runs continuously, teams don’t need to wait for the next scheduled scan, a delay that widens their exposure window.

Cooldown policies

Cooldown policies became generally available for npm and Python in Q2, and in Q3 we expanded support to six more formats: Go, NuGet, Maven, Conda, Docker, and Cargo. You can create cooldown policies via the web app, API, or Terraform. These updates extend the reach of cooldown policies beyond application libraries to include container images and Rust crates.

Catch policy errors before you save

This is an improvement in the policy editor that flags Rego problems as you write. On save, the web app and API reject disallowed builtins (such as http.send), type mismatches, incorrect argument counts, and unsafe or undeclared variables. The web app editor also warns when a policy is missing `package cloudsmith` or a match rule, highlights malformed Rego inline, and autocompletes schema field names.

Catching mistakes while you type means fewer policies that silently fail to do what you expect, and a shorter learning curve for teams new to Rego.

Download vulnerability findings from the web app

This feature lets users select Download vulnerability data on a package’s Overview tab to export every vulnerability and malicious package record matched to it as JSON. This data is also available from the Packages Vulnerabilities List API endpoint.

Simplify incident investigation and compliance audits by allowing security teams to send findings to a ticketing system, SIEM, or auditor in one click, without writing an API script.

Trusted upstreams

Hardened images tab for configuring upstreams

Upstream configuration now supports Docker Hardened Images (DHI), Chainguard Containers, and WizOS. The DHI Community and Chainguard Containers Free tiers come pre-configured. For paid tiers, the proxy URL is filled in for you, so you only name the upstream and add credentials.

Making hardened images quick to proxy lowers the cost of adopting them, and every pull is cached, logged, and subject to your policies.

Libraries tab for vendor-curated package registries

The new Libraries tab quick-configures library registries, which include vendor-curated feeds of open source packages that may be pre-vetted, rebuilt from source, and security scanned. Currently, this feature supports Chainguard Libraries (Maven, Maven Remediated, npm, PyPI, PyPI Remediated) and RapidFort Curated Libraries (npm).

Teams can adopt curated, rebuilt-from-source packages as a drop-in upstream and manage them alongside public upstreams and private packages in one place.

Go upstreams for any GOPROXY-compatible proxy

Go upstreams can now point to any GOPROXY-compatible module proxy, in addition to the public mirror at proxy.golang.org. That includes private proxies such as the Buf Schema Registry (BSR).

This feature gives you one control point for all Go dependencies, with caching, policy, and logging, instead of managing multiple GOPROXY settings.

CLI and CI/CD

CLI v1.19.0: automatic OIDC and Docker credential discovery

The Cloudsmith CLI automatically discovers OpenID Connect (OIDC) credentials for all major CI/CD platforms and includes a Docker credential helper to automatically authenticate to Cloudsmith registries. This eliminates the need for static API keys in CI/CD pipelines.

Long-lived API keys stored as CI secrets are one of the most common ways credentials leak. With OIDC discovery, there’s nothing to store, rotate, or leak.

CLI 1.20.0 no longer requires Python

The Cloudsmith CLI now ships as a standalone, self-contained binary for Linux, macOS, and Windows, eliminating its dependency on a local Python environment.

This means that pipelines no longer break when a runner’s Python version changes, and installs are faster and identical on every platform.

CLI v1.21.0 to v1.26.0: Nix, Cargo and pnpm helpers, and repo admin

Multiple updates to the Cloudsmith CLI with this changelog include:

  • Nix support: Treats Nix as a first-class format and users can push Nix packages and manage Nix channel upstreams
  • Credential helpers: Includes support for Cargo and pnpm, plus a generic helper that prints a credential as JSON for any script
  • Admin terminal commands: Users can manage signing keys with cloudsmith repos gpg and grant/revoke access with cloudsmith repos privileges
  • Debian: Cloudsmith can now push a Debian package by reading the .dsc of the source package
  • SSO tokens on headless and CI machines: SSO and OIDC sessions work in more places: encrypted file-based keyrings, new keyring environment variables, and cloudsmith auth --no-browser
  • macOS: Keychain prompts no longer reappear after every token refresh

Logs and visibility

Package logs

Package logs are now available in the web app under the Logs tab. This per-package audit trail allows users to track package actions, including copy, delete, hard delete, move, policy violation, quarantine, restore, resync, sync, and tag changes.

This update speeds up incident response and gives you ready-made compliance evidence.

Client logs show the full request chain behind a download

Client logs now capture format-specific metadata for every supported format, including metadata fetches and redirects, not just the final file download.

This helps you understand which version a build resolved and where that decision occurred. It also accelerates debugging questions around package selection and how certain packages made their way into specific builds.

Downloads, token use, and client logs in the Broadcasts app

This improvement to the Broadcasts app now shows how published packages are consumed: counts of broadcasting packages, entitlement tokens active this billing cycle, usage by repository, and top downloads. A world map and table break down delivery by country, and a filterable client log stream shows individual requests.

For users that distribute software to customers, this improvement puts adoption and per-customer usage data in one place. That can help with product decisions and license compliance, and makes unusual entitlement token activity easier to spot.

Formats and performance

Nix, with upstream support for NixOS

Cloudsmith can now serve as a public or private Nix binary cache. Teams that use Nix can push packages with the native nix copy command, and Cloudsmith signs store paths with the repository's Ed25519 key when they’re read, so key rotation takes effect immediately and multiple keys can be valid at once. Nix upstreams proxy and cache NixOS release channels, one upstream per channel.

Nix teams can retire self-hosted Nix caches and manage Nix packages with the same access control and visibility as their other formats. Signing on read means rotating a compromised key doesn’t require re-signing.

Faster Python builds with PEP 658

We added support for PEP 658, allowing Python package clients to fetch only metadata from the Simple API during dependency resolution.

Because you don’t need to download large archives, dependency resolution gets faster and more reliable, with less bandwidth and less load on upstream caches.

Account security and administration

Cloudsmith API keys are detectable by GitHub secret scanning

Cloudsmith joined the GitHub secret scanning partner program. API keys carry a unique prefix registered with GitHub, so a key committed to source, a config file, or a .env is flagged automatically, and Cloudsmith notifies the affected user and workspace owners to rotate it.

This program detects keys on push, not when someone misuses them, shrinking the window attackers have to exploit those keys.

Secret scanning alerts link to each detection location

Related to the previous changelog item, this update improves the email notification process by including detailed information about every place a key was found, grouped by files and commits, issues, pull requests, discussions, and wiki commits, with a direct link to each. Every detection also records an API_KEY_EXPOSED event in the workspace audit log.

This information can speed up remediation from exposed secrets and provides a documentation trail for incident reviews.

Read-only access to billing, usage, and OIDC data

Workspace owners can now separately grant members read access to billing information, usage data (including artifact storage and delivery quotas), and OIDC settings, without giving anyone the Manager or Owner role.

SCIM group provisioning is now generally available

You can now provision Cloudsmith team membership from groups in your identity provider (IdP). Adding or removing a user from a mapped group in your IdP updates their Cloudsmith team membership automatically. Users provisioned through SCIM groups get the Member role by default, which you can change from the Accounts tab.

With this update, your IdP becomes the single place to manage team membership across your organization, and Cloudsmith automatically follows, which also speeds up onboarding and offboarding. This functionality is available on Ultra and Enterprise plans.

A new bug bounty platform

Security researchers now submit reports through a dedicated platform at bounties.cloudsmith.com that shows where each report stands. Rewards are now paid once a qualifying defect is confirmed, rather than after a fix ships.

Subscribe to the changelog RSS feed to receive these updates as they ship or browse the full Cloudsmith changelog.