Improved Docker experience in the Cloudsmith web app
We’ve improved how Docker images are displayed and navigated in the web app, making it easier to work with tags, architectures and metadata to quickly find what you need…
We’ve added a new policy action to Enterprise Policy Manager (EPM): Remove tag. This enables reversible tagging workflows - for example, if a package was previously tagged as risky due to a CVE policy violation but is later cleared because the CVE was withdrawn, downgraded, or assessed as low risk and approved for continued use, you can now remove that tag automatically.
With this addition, you can now create policies that both apply and remove tags as conditions change, enabling policies that keep tags in sync with the current state of risk.
👉 Learn how to build a security tagging workflow in the EPM docs. EPM is currently in Early Access - contact us to get started.
We’ve improved how Docker images are displayed and navigated in the web app, making it easier to work with tags, architectures and metadata to quickly find what you need…
Cloudsmith now displays Docker image signatures and SBOMs (Software Bill of Materials) directly in the web app, giving you greater trust and visibility into the images you use…
You can now host and distribute your machine learning (ML) models and datasets using Cloudsmith. This brings the same security, governance, and cloud-native performance you already rely on for packages, containers, and binaries to your AI workflows…
You can now filter vulnerabilities by Common Vulnerabilities and Exposures (CVE) severity in the package vulnerability view, using the quick filter selectors…
Cloudsmith now detects malicious packages using data from OSV.dev and the OpenSSF Malicious Packages project so you can see, stop, and govern open source packages designed to attack your supply chain before they reach your builds or customers…
You can now use Cloudsmith’s package search syntax to refine the scope of your repository's retention rules when configuring them via the Cloudsmith web application and via the Cloudsmith Terraform provider. This functionality builds on the existing support to scope retention rules by package search syntax via the API, and makes it easier to target exactly which packages to keep or remove…