More events now trigger policy evaluations

Two additional policy evaluation triggers are now available, ensuring that policies are enforced consistently across repositories without manual intervention.

Policy evaluations will now also trigger when:

  • A policy or policy action is created, edited, or deleted. Any change to your policy configuration immediately re-evaluates affected packages against the updated ruleset, so your policy coverage stays current without manual intervention.
  • A fallback scheduled evaluation runs. Any package that has not been evaluated against policies within the last 12 hours is automatically picked up for evaluation. This scheduled sweep runs every 12 hours, closing the gap for packages that may have been missed by event-driven triggers or that rely on a time-based value to determine what action to take.

These additional triggers are being rolled out to all early access customers over the next few weeks. They apply to policy-as-code configurations and do not affect legacy policies. An increase in policy matches is expected during this period as packages that were previously unevaluated are assessed for the first time.

These additional triggers complement the existing set, which includes package upload, resync, copy, manual scan, recurring scan, and when Cloudsmith receives updated package data, such as Common Vulnerability Scoring System (CVSS) or Exploit Prediction Scoring System (EPSS) updates.


Keep up to date with our monthly product bulletin