CLI v1.21.0 to v1.26.0: Nix support, Cargo and pnpm credential helpers, and repository administration from your terminal

The Cloudsmith CLI has had six releases since our last update here. The headlines: you can now push Nix packages, let Cargo and pnpm authenticate automatically with credential helpers, and manage a repository's GNU Privacy Guard (GPG) key and access privileges without leaving your terminal. Along the way, the CLI got faster to start, kinder to macOS users, and better behaved on machines with no OS keyring.

Push Nix packages and mirror Nix channels

v1.25.0 adds Nix as a first-class format. Push packages with cloudsmith push nix and manage Nix channel upstreams with cloudsmith upstream nix, the same way you already do for other formats.

cloudsmith push nix your-org/your-repo hello-2.12.1.nixpkg

Cargo and pnpm now authenticate automatically

v1.19.0 introduced Docker credential discovery. The list of supported package managers keeps growing: the CLI can now handle authentication for Cargo (v1.26.0) and pnpm (v1.25.0) too.

cloudsmith credential-helper install cargo
cloudsmith credential-helper install pnpm

One install command each, and the tool authenticates to your Cloudsmith registries with your existing CLI credentials. No cargo login, no tokens copied into credentials.toml or .npmrc. The Cargo provider only ever answers for Cloudsmith registries, so crates.io and any other provider you use are left untouched. Both helpers support custom domains, dry runs, listing, and uninstalling. For more information, see the Cargo and npm credential helper documentation.

If your tool of choice has no dedicated helper yet, v1.21.0 added a generic one. cloudsmith credential-helper generic resolves a credential through the full chain (API key, credentials.ini, system keyring, OpenID Connect (OIDC)) and prints it as a small JSON document any script can consume:

{"version": 1, "username": "token", "password": "<token>"}

Administer repositories from the terminal

v1.26.0 brings two new command groups for repository administration.

cloudsmith repos gpg manages the GPG key your repository signs its package indexes with. View the active key, upload your own, or have Cloudsmith regenerate it. The CLI only ever reads key material from a file, stdin, or a hidden prompt, and a dry-run mode tells you exactly which key you are about to replace before anything happens.

cloudsmith repos gpg get your-org/your-repo
cloudsmith repos gpg upload your-org/your-repo --private-key-file signing.asc

cloudsmith repos privileges does the same for explicit repository access. List who can see a repository, grant or revoke access for teams, users and service accounts, or replace the whole privilege set from a JSON file for repeatable, reviewable access control.

cloudsmith repos privileges list your-org/your-repo
cloudsmith repos privileges set your-org/your-repo --team platform --privilege write

Push a Debian source package with just the .dsc

Since v1.22.0, the CLI reads the .dsc of a Debian source package and works out the --sources-file and --changes-file values by itself:

cloudsmith push deb your-org/your-repo/ubuntu/jammy foo_1.0-1.dsc

All Debian source formats are supported, and explicit flags still win if you want control.

Single sign-on (SSO) tokens on headless and CI machines

SSO and OIDC sessions work in more places:

  • The standalone binary now bundles encrypted file-based keyring backends (v1.23.0), so a headless Linux container with no OS keyring can still persist tokens.
  • CLOUDSMITH_KEYRING_BACKEND and CLOUDSMITH_KEYRING_KEY (v1.24.0) select and unlock a backend non-interactively, and CLOUDSMITH_KEYRING_FILE_PATH and CLOUDSMITH_KEYRING_DIR (v1.25.0) control where the tokens live.
  • cloudsmith auth --no-browser (v1.24.0) prints the SSO URL instead of launching a browser, for remote shells where that would go nowhere.

macOS keychain prompts stop reappearing after every token refresh

If you use the CLI on macOS with SSO, you have probably seen the "Cloudsmith wants to use your credential information" prompt more times than you would like, and clicking "Always Allow" never seemed to stick. v1.26.0 fixes the root cause: the CLI now updates keychain items in place instead of deleting and recreating them, so your permission grants survive every token refresh. Each profile also keeps its own session now, and a session the server has rejected cleans itself up and asks you to log in again instead of nagging you every half hour.

Faster startup

v1.25.0 and v1.26.0 moved the CLI's heavy dependencies out of the startup path; they now load only when a command needs them. You will notice it most in scripts and CI, where the CLI is often invoked many times in a row.

Also worth knowing

  • cloudsmith domains list (v1.22.0) shows every host Cloudsmith can authenticate for you, including your organization's custom domains.
  • The organization option is now simply --org (v1.22.0); --oidc-org still works as an alias.
  • Exit codes are reliable again everywhere, including python -m cloudsmith_cli (v1.24.0).
  • --debug now prints debug logs (v1.24.0).
  • Security assertion markup language (SAML) authentication handles two-factor authentication more gracefully, directing you from the browser back to the terminal and retrying rejected codes (v1.25.0).
  • cloudsmith copy reports what it copied, including the slug_perm, just like push (v1.26.0).

For the full list of changes, see the changelog on GitHub.

Keep up to date with our monthly product bulletin