Introducing native Swift signing

Cloudsmith has extended our Swift support to include the native signing of Swift packages. This update brings seamless, secure, and high-performance signing capabilities directly to iOS developers, eliminating the need for third-party workarounds or custom implementations.

How it works

  • Swift packages are signed using an ECDSA private key and X.509 Certificate combination. With native Swift signing enabled, your repositories will automatically sign Swift packages when they are uploaded or synchronized.
  • Once the relevant security settings for the Swift CLI are configured, you can consume fully verifiable and signed Swift packages directly from Cloudsmith.

Why this matters

Native Swift package signing mitigates against package content tampering and provides an effective means of integrity verification using native tooling. Check out Signing Swift Packages for more information.

Keep up to date with our monthly product bulletin

By submitting this form, you agree to our privacy policy