Cooldown policies now support Cargo
You can now apply cooldown policies to Cargo packages, protecting your supply chain from newly published versions that may carry malware or have not yet undergone sufficient community scrutiny…
When an exposed Cloudsmith API key is detected in a GitHub repository, the email notification sent to the affected Cloudsmith user and workspace owners now lists every location the key was found in GitHub, with a direct link to each detection.
The email groups detections by location:
The Cloudsmith workspace audit log records an API_KEY_EXPOSED event for each detection, with the masked key and detection location.
Exposure detection for Cloudsmith API keys in GitHub runs through the GitHub secret scanning partner program. For more details, see GitHub secret scanning in the Cloudsmith documentation.
You can now apply cooldown policies to Cargo packages, protecting your supply chain from newly published versions that may carry malware or have not yet undergone sufficient community scrutiny…
You can now apply cooldown policies to Conda and Docker packages, protecting your supply chain from newly published versions that may carry malware or have not yet undergone sufficient community scrutiny…
See how published packages are being consumed - downloads, entitlement token use, and client logs - without leaving the Broadcasts app…
Library registries provide a vendor-curated feed of open source packages. Packages may be pre-vetted, rebuilt from source, and security scanned by the vendor…
Cloudsmith now supports the Nix format, letting you host a public or private Nix binary cache, complete with Ed25519-signed packages and upstream proxying and caching against NixOS release channels…
Go upstreams can now point to any GOPROXY-compatible module proxy, in addition to the public mirror at proxy.golang.org…