Secure ML workflows with Cloudsmith and Amazon SageMaker
Cloudsmith now provides a reference implementation guide for Amazon SageMaker. This resource demonstrates how to utilize Cloudsmith as a secure, central hub for the Hugging Face models, Docker images, and Python packages required for machine learning workflows…
Timeline to sunset the classic web app extended to the second half of 2026
We are extending the sunset timeline for the Cloudsmith classic web app. The classic app will now remain available through the second half of 2026…
CLI GitHub Action v2.0.0
The v2.0.0 release of the Cloudsmith CLI GitHub Action migrates the action to the Node.js 24 runtime and updates default OIDC audience claims to align with modern security standards…
Accelerating delivery in APAC: Cloudsmith Tokyo is now live
A crucial part of effective package management is package distribution. Whether you are dealing with distributed teams or deploying global applications, you need efficient, reliable delivery - anywhere in the world.
To support this, we are continuing to expand our global footprint and are now live in Tokyo.
What’s new
Expanded Package Delivery N…
CLI v1.10.1: Policy deny rules and usability improvements
This update to the Cloudsmith CLI introduces programmatic management for Policy Deny Rules, standardizes pagination parameters across the CLI, and upgrades core dependencies…
Download SBOMs directly from the web app
You can now download auto-generated Software Bills of Materials (SBOMs) for your Docker images directly from the Cloudsmith web app. This allows you to instantly export supply chain data for use in analysis tools or alongside release documentation…
Get a more granular view of incident impact with Cloudsmith’s reorganized Status Page
When Cloudsmith services experience an incident, we want you to know exactly how it impacts your builds, your deployments, and your teams. We’ve given the Cloudsmith Status Page an overhaul to provide a more granular and organized view of system health from our customers’ perspective…
Native OIDC authentication for Azure DevOps
We have updated the Cloudsmith Azure DevOps extension to support native Azure DevOps OIDC authentication. You can now authenticate pipelines using the Azure DevOps built-in issuer…
Troubleshoot failed download requests with client error logs
We have updated Client Logs to capture error events, ensuring platform engineering teams have the critical information needed to troubleshoot issues on behalf of their teams…
Deprecating historical scan results retention
On December 17th, 2025, Cloudsmith will no longer store historical scan results from Trivy scans; only the latest scan results from Trivy scans for each package will be available.
This change affects historical data that is exclusively available via the API. Historical scan results are not displayed in the Cloudsmith web app. Usage analysis indica…