---
title: "Continuous risk detection is now generally available"
description: "Every package in your workspace is now checked automatically against known vulnerabilities and malicious packages, with no scheduled or manual rescans required. This is powered by OSV.dev, which has driven policy evaluation since early access and now also replaces Trivy as the data source shown in the web app and API."
canonical_url: "https://cloudsmith.com/changelog/continuous-risk-detection-is-now-generally-available"
last_updated: "2026-08-12T11:08:28.375Z"
---
# Continuous risk detection is now generally available

Every package in your workspace is now checked automatically against known vulnerabilities and malicious packages, with no scheduled or manual rescans required. This is powered by [OSV.dev](https://osv.dev/), which has driven policy evaluation since early access and now also replaces Trivy as the data source shown in the web app and API.



## What's new

- **Compliance views at every level: **results appear in the web app's workspace, repository, and package-level compliance views, alongside the existing API.
- **Malicious package detection: **the OpenSSF Malicious Packages feed, added to Cloudsmith in [August 2025](https://cloudsmith.com/blog/malicious-package-detection-in-cloudsmith), now also flags packages directly in the web app and API.
- **Primary record selection: **duplicate advisory records are grouped into one, reducing noise in compliance reviews.
- **Threat ordering: **results are sorted by severity across compliance views.
- **Broader format coverage: **vulnerability detection now covers CRAN, plus Debian/Ubuntu, RPM (Red Hat, AlmaLinux, Rocky Linux), and Alpine packages, whether uploaded individually or bundled in a Docker image.



## How it works

### Detection

Detection runs automatically for every supported package format in your workspace, with no configuration required. Cloudsmith refreshes threat intelligence every 5 minutes, and whenever a new or updated record could affect packages already in your workspace, it checks for a match automatically, without requesting a rescan.

Packages are matched to advisories on a shared package URL (PURL). Cloudsmith supports SemVer and ecosystem-native version ranges when matching; see our [earlier changelog](https://cloudsmith.com/changelog/vulnerability-detection-now-covers-ecosystem-native-osv-advisories) on ecosystem-native OSV advisory support for more.

### Viewing results

The same vulnerability often has multiple records from different upstream databases. Cloudsmith groups these and surfaces one primary record per vulnerability, so counts stay accurate and reviews stay focused. See the Cloudsmith [documentation](https://docs.cloudsmith.com/supply-chain-security/risk-detection/vulnerability-detection#understanding-vulnerability-records) to learn how the primary record is selected.

Packages are sorted by severity, highest first: Malware, then Critical, High, Medium, Low, and Unknown.

```json
{
  "_key": "4ca53a105b9d",
  "_type": "image",
  "alt": "Packages with security issues view ",
  "asset": {
    "_createdAt": "2026-08-12T10:22:24Z",
    "_id": "image-da300c2630eaa5f718e60b65b0ebd386a0ca7de5-2040x2080-png",
    "_rev": "oE259PjhXs6AMNC0jq75BM",
    "_type": "sanity.imageAsset",
    "_updatedAt": "2026-08-12T10:22:24Z",
    "assetId": "da300c2630eaa5f718e60b65b0ebd386a0ca7de5",
    "extension": "png",
    "metadata": {
      "_type": "sanity.imageMetadata",
      "blurHash": "e8Ss1[R:T}s*h{g*Rjn2flXnpJa}nMWXT0-:WXWYWBWV$za|WrWBax",
      "dimensions": {
        "_type": "sanity.imageDimensions",
        "aspectRatio": 0.9807692307692307,
        "height": 2080,
        "width": 2040
      },
      "hasAlpha": true,
      "isOpaque": true,
      "lqip": "data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAUCAYAAACNiR0NAAAACXBIWXMAAAsTAAALEwEAmpwYAAACvElEQVR4nHVUa0/cQAy8///PoFU/FQpthYBrKRXc5bEvr+3dqezkjjvaRlolyjrjmfFsNsyCkDLmlMEisKv389VaB1VGTAWVGd1e/ufazLHg8dcr7p9eMMwZpSqq9LfFHcSKcU54ftljCgks6k3+CTjGiu3vGQ/PE573GbuZMUTFkBRjahiTIhRFzBVjSIi5gKpAtZ2r6MvaRFLsQ8XrRH4fogEKpqwI1BCpI/OBcQOxOGAVhWiHNvhi6WDt2OQqGEPBEArmzIhFEIogVUWRhlwVKTNyERRubonVRBJ/ptUaWptuciZMc8YYCaEwMqsv+8CA5ylheHrB9DKikIC4IdGyb/dkjc1nAViBTUkF0xQxzAlTKojEMNaxMEKuCLsR47c7hO09ahrBXF1uYXWGhZuzNLnSDLAYw4j9FNz0kAoysceEmFHHAXR3C3r8BBm+Q2mAiO0JKitYG7R1n7oPpeaCOEfMISEX8pyJqk9RVaDTAL6/AW8voPsrtPIKlYq6Aoq2Bax1n/am5opkzGJGpqXQwFpraCpo07gCXkL312+ANmkWz6RabV8BycyPxQM7x7zmjCFWKMZwhNzfQLaXaPsrdAfkBYzF66y5nZ6FocUgkYPa8TsCGkuXfGB4gba/XgHrkZ2skvtRcm0OaOyODK3zKeDDLXj7AW34gl52aMLO7gywn0iezyST++PeCEPHleHj+VDYErBKdg8PDDmTDyUm+zHwWcGZ5MfLVfLOGy0M5W+GUgglZeRcvGjZWFeTN4YnUxYLdz0wbMccLgyrwI5fWofhkekW0pXhe8C8AFrtMTa6KjJAOz5hHUryYC++LLE58dCDbQx3EJ/yIvuvYBda/sSnHtpJWU7LYco34B8foeNXdJo8n+9jc/BxYxuFCETVQc49VPQYID/voM+f0cIDOkc0a3gi9e0b4A9SARWj8QH3GAAAAABJRU5ErkJggg==",
      "palette": {
        "_type": "sanity.imagePalette",
        "darkMuted": {
          "_type": "sanity.imagePaletteSwatch",
          "background": "#2c3c4c",
          "foreground": "#fff",
          "population": 0,
          "title": "#fff"
        },
        "darkVibrant": {
          "_type": "sanity.imagePaletteSwatch",
          "background": "#92344c",
          "foreground": "#fff",
          "population": 0.04,
          "title": "#fff"
        },
        "dominant": {
          "_type": "sanity.imagePaletteSwatch",
          "background": "#e5a525",
          "foreground": "#000",
          "population": 0.17,
          "title": "#fff"
        },
        "lightMuted": {
          "_type": "sanity.imagePaletteSwatch",
          "background": "#afc4d6",
          "foreground": "#000",
          "population": 0.01,
          "title": "#fff"
        },
        "lightVibrant": {
          "_type": "sanity.imagePaletteSwatch",
          "background": "#fc7aac",
          "foreground": "#000",
          "population": 0.01,
          "title": "#fff"
        },
        "muted": {
          "_type": "sanity.imagePaletteSwatch",
          "background": "#6c74b4",
          "foreground": "#fff",
          "population": 0,
          "title": "#fff"
        },
        "vibrant": {
          "_type": "sanity.imagePaletteSwatch",
          "background": "#e5a525",
          "foreground": "#000",
          "population": 0.17,
          "title": "#fff"
        }
      },
      "thumbHash": "PQgCDwLjE/pohYp6doh3l4iIaTBXB3MF"
    },
    "mimeType": "image/png",
    "originalFilename": "image (4).png",
    "path": "images/rafvlnhi/production/da300c2630eaa5f718e60b65b0ebd386a0ca7de5-2040x2080.png",
    "sha1hash": "da300c2630eaa5f718e60b65b0ebd386a0ca7de5",
    "size": 335904,
    "uploadId": "a13aceafd809dc64da634b59d6edc3c314f9cc3d",
    "url": "https://cdn.sanity.io/images/rafvlnhi/production/da300c2630eaa5f718e60b65b0ebd386a0ca7de5-2040x2080.png"
  },
  "link": {
    "_type": "link",
    "href": null,
    "openInNewTab": false
  },
  "markDefs": null
}
```

##   
Using this data in policy management

Policies can act on this data automatically, quarantining or flagging a package the moment it matches, without manual review. This data has been actionable in policy management with policy as code since we first added it to the platform in early access, and nothing changes for policies you've already built. See the Cloudsmith [documentation](https://docs.cloudsmith.com/supply-chain-security/policy-as-code) to learn more about defining policies against this data.

## What's happening to Trivy

Trivy-based scan results remain available in the legacy web app and via existing API endpoints for now. Trivy will be deprecated in a future release; we'll share migration details ahead of that change.

  
For more details about continuous risk detection, see [our documentation](https://docs.cloudsmith.com/supply-chain-security/risk-detection).
