Track every change to your packages with package logs
Package logs are now available in the Cloudsmith web app, giving you a per-package audit trail: what changed, who changed it, and when…
Vulnerability and malicious package findings can now be exported as a JSON file directly from the web app.
Select Download vulnerability data on a package’s Overview tab to export a JSON file containing every vulnerability and malicious package record currently matched to that package.
Package vulnerability data is also available from the Packages Vulnerabilities List API endpoint.
Vulnerability and malicious package detection is available on Ultra and Enterprise plans.
Package logs are now available in the Cloudsmith web app, giving you a per-package audit trail: what changed, who changed it, and when…
Workspace owners can grant each privilege separately, without giving members the Manager or Owner role…
When an exposed Cloudsmith API key is detected in a GitHub repository, the email notification sent to the affected Cloudsmith user and workspace owners now lists every location the key was found in GitHub, with a direct link to each detection…
You can now apply cooldown policies to Cargo packages, protecting your supply chain from newly published versions that may carry malware or have not yet undergone sufficient community scrutiny…
You can now apply cooldown policies to Conda and Docker packages, protecting your supply chain from newly published versions that may carry malware or have not yet undergone sufficient community scrutiny…
See how published packages are being consumed - downloads, entitlement token use, and client logs - without leaving the Broadcasts app…