You can now download auto-generated Software Bills of Materials (SBOMs) for your Docker and OCI images directly from the Cloudsmith web app. This allows you to instantly export supply chain data for use in analysis tools or alongside release documentation.
Previously, SBOMs generated by Cloudsmith were only accessible via the packages API. Instead of scripting an API call to retrieve the manifest for a specific image, you can now grab the CycloneDX file with a single click, making SBOMs accessible to a broader range of users.
How it works
Navigate to an image in Cloudsmith
Click the Actions menu → "Download SBOM"
Download SBOMs directly from the web app
Technical notes
Downloads are provided in CycloneDX format.
This feature applies only to SBOMs automatically generated by Cloudsmith during the container image synchronization process.
Cloudsmith automatically generates SBOMs for Docker V2 and OCI V1 images.
This feature is live and available immediately for all Docker images. If you have any questions or feedback, please contact us.
When Cloudsmith services experience an incident, we want you to know exactly how it impacts your builds, your deployments, and your teams. We’ve given the Cloudsmith Status Page an overhaul to provide a more granular and organized view of system health from our customers’ perspective…
We have updated the Cloudsmith Azure DevOps extension to support native Azure DevOps OIDC authentication. You can now authenticate pipelines using the Azure DevOps built-in issuer…
We have updated Client Logs to capture error events, ensuring platform engineering teams have the critical information needed to troubleshoot issues on behalf of their teams…
On December 17th, 2025, Cloudsmith will no longer store historical scan results from Trivy scans; only the latest scan results from Trivy scans for each package will be available.
This change affects historical data that is exclusively available via the API. Historical scan results are not displayed in the Cloudsmith web app. Usage analysis indica…
Private Broadcasts is now available in Early Access, providing a secure solution for distributing proprietary software, such as internal SDKs, libraries, and premium commercial content…