Policy management is now generally available

Following early access, policy management - Cloudsmith's policy-as-code system for enforcing rules across your software supply chain - is now generally available across the web app, API, and Terraform provider. This includes:

  • Custom policies: write your own logic in Rego, Cloudsmith's policy language, tailored to your specific security and compliance requirements
  • Always-on enforcement: policies are evaluated on package upload, and re-evaluated automatically as policies or threat intelligence changes
  • Cooldown policies: hold new package versions back from consumers for a set window before they're trusted
  • Policy templates: pre-built starting points so you don't need to write Rego from scratch
  • Decision logs: a full audit trail of every policy evaluation, viewable in the web app or downloadable via API

Continuous risk detection and policies

In addition to writing policies that act on package metadata, you can also write policies using Cloudsmith's continuous risk detection, which is also generally available.

Getting started

Policy management is available as an add-on for Ultra and Enterprise plans. Reach out to your account team to get started.

A separate set of baseline standard policies is included in both plans: CVE, license, package deny, and — newly added — malware policies. The package search field is no longer available when creating vulnerability and license policies in the web app, API, or Terraform. Existing policies using it are frozen and cannot be edited, but remain in place and continue to evaluate.

Policy management and baseline standard policies now live together under Policies in the main navigation:

For more details about Cloudsmith policy management, see:

Keep up to date with our monthly product bulletin