Explore vulnerability details to better assess impact
You can now better assess a vulnerability's impact by exploring its key details directly within the vulnerabilities table for a package or container. We've introduced an expanded row layout that shows all available information for a specific finding, helping you make more informed decisions about your response.
Additionally, we’ve added CVSS score…
Recent improvements to the Cloudsmith web app
We’ve recently released a set of improvements across the Cloudsmith web app focused on logs, error messaging, and usability…
Improved Docker experience in the Cloudsmith web app
We’ve improved how Docker images are displayed and navigated in the web app, making it easier to work with tags, architectures and metadata to quickly find what you need…
Verify and inspect Docker images
Cloudsmith now displays Docker image signatures and SBOMs (Software Bill of Materials) directly in the web app, giving you greater trust and visibility into the images you use…
Filter CVEs by severity in the package vulnerability view
You can now filter vulnerabilities by Common Vulnerabilities and Exposures (CVE) severity in the package vulnerability view, using the quick filter selectors…
Faster access to Client Logs
We've reduced the delay between a download event and its appearance in Client Logs, giving you faster visibility into your package delivery pipeline. This makes it easier to analyze trends, troubleshoot issues, and keep your workflows moving…
Additional vulnerability data added to our web app
Packages added to Cloudsmith are scanned for vulnerabilities and malware, and passed through our policy engine. When we identify vulnerable packages, we produce and collate a range of descriptive data to help explain those vulnerabilities. Previously, that data was only available in our legacy web app, and more recently via our API. We've now broug…
Client log exports now include more HTTP Methods for improved package lifecycle visibility
Client log exports now provide a more comprehensive overview of package delivery. In addition to GET requests, client log exports will include other HTTP request types, including HEAD, POST, and OPTIONS requests. This gives you a full view of package delivery, moving beyond just download tracking to include metadata checks and other repository interactions…
Broadcasts now support custom domains for distribution
Broadcasts now support using your own domain as the endpoint for package distribution, helping you deliver a more consistent and trusted experience for developers and end users…
Improved sorting and filtering controls in the new web app
We have improved sorting and filtering in the new web application, making it easier to manage members, teams and service accounts in Cloudsmith…