Introducing Private Broadcasts for secure software distribution
Private Broadcasts is now available in Early Access, providing a secure solution for distributing proprietary software, such as internal SDKs, libraries, and premium commercial content…
On December 17th, 2025, Cloudsmith will no longer store historical scan results from Trivy scans; only the latest scan results from Trivy scans for each package will be available.
This change affects historical data that is exclusively available via the API. Historical scan results are not displayed in the Cloudsmith web app. Usage analysis indicates that no customers currently access this historical data. If you interact with our vulnerability endpoints today, you are likely already focusing on the latest scan results, which will remain fully accessible.
We are removing this unused data to improve platform performance and prepare for upcoming security features.
The vulnerability API endpoints listed below will remain active and still return a list. The only change in behavior is that the data returned will be the latest scan result for a package, rather than historical scans.
For more information on the upcoming Continuous Security features, please read our documentation. If you have any questions or concerns about this upcoming change, please contact us.
Private Broadcasts is now available in Early Access, providing a secure solution for distributing proprietary software, such as internal SDKs, libraries, and premium commercial content…
We’ve introduced the cloudsmith download command to the Cloudsmith CLI, enabling users to programmatically retrieve packages from repositories…
We've significantly enhanced the Cloudsmith Terraform Provider with new data sources and expanded support for upstream formats…
Cloudsmith now provides official upstream proxying and caching support for Chainguard Libraries for Javascript in your npm repositories. This integration enables customers to use Cloudsmith as the primary, secure distribution platform for Chainguard’s malware-resistant, built-from-source JavaScript dependencies. Key benefits Centralized distribut…
We’ve added the --show-all flag to the Cloudsmith CLI, which simplifies your automation scripts by eliminating the need for pagination logic…
We've improved how package statuses are displayed and managed across the Cloudsmith web app to help you quickly understand if a package or container is available, safe, and compliant…