Connect Cloudsmith to Datadog more easily with our Containerized Agent
You can now integrate Cloudsmith into Datadog using our prebuilt Datadog Agent container…
Cloudsmith now gives you stronger control over your software supply chain by blocking downloads of any package that doesn’t pass your organization's security and compliance policies, including packages fetched from upstream registries.
Until now, Cloudsmith applied policy enforcement after the first download of a package proxied from an upstream registry. The package would be served immediately, and if the upstream source was configured to proxy and cache, the package would then be scanned and checked for policy violations. This behavior was intentional. It let customers prioritize speed for their developers while building workflows that protected production environments from vulnerabilities. Subsequent requests for the package would be subject to policy checks.
As awareness of software supply chain risks has grown, customers are now looking to extend the same level of protection to every touchpoint, including developer machines, starting from the very first download.
Now, you can configure Cloudsmith to delay that first download entirely, preventing developers and build tools from downloading a vulnerable or non-compliant package.
This new enhancement to policy management acts as an important checkpoint option for all proxied package downloads. Here’s how it works:
We are launching this new option in early access to all current Ultra plan customers to gather valuable feedback from our users and ensure it meets their needs. Your input will be crucial in refining and perfecting this and future enhancements to our policy management features.
Reach out to us in order to start using this new feature and take your policy management to the next level.
You can now integrate Cloudsmith into Datadog using our prebuilt Datadog Agent container…
You can now use Cloudsmith’s package search syntax to refine the scope of your repository's retention rules when configuring them via the Cloudsmith API. This flexible query language lets you filter packages by tag, version, downloads and more, making it easier to target exactly which packages to keep or remove…
Cloudsmith has extended its support for the Go format by adding proxying support for the Go module proxy, making dependency management easier, faster, and more secure for your Go projects…
Cloudsmith’s CLI is now available as an official Homebrew tap, making installing the Cloudsmith CLI straightforward and quick. For developers already using Homebrew, simply add the tap and install the CLI. Since Homebrew manages dependencies, you don’t need to install or manage Python yourself. Homebrew takes care of it for you. Getting started F…
You can now publish and manage Helm charts in Cloudsmith using modern OCI-based workflows. Charts pushed via Helm V3 to our OCI-compatible registry are correctly identified in the UI and supported through a new dedicated endpoint: helm.oci.cloudsmith.io. These improvements build on our full support for OCI v1.1 compliance and make adopting Helm’s latest distribution model easier…
We’ve expanded the Cloudsmith Datadog integration to include new metrics and events that give you deeper visibility into your Cloudsmith workspace’s artifact usage, access patterns, and compliance…
By submitting this form, you agree to our privacy policy