Quickly configure library registries as upstreams with the new Libraries tab

Library registries provide a vendor-curated feed of open source packages. Packages may be pre-vetted, rebuilt from source, and security scanned by the vendor. For details on which of these features are available for a specific registry, see the latest documentation for the registry vendor.

Currently supported quick configure vendors:

  • Chainguard Libraries:
    • Maven
    • Maven Remediated
    • npm
    • PyPI
    • PyPI Remediated
  • RapidFort Curated Libraries:
    • npm

Pick a vendor and library, name the upstream, and add your credentials - Cloudsmith fills in the proxy URL for you.

For more details, see our Chainguard Libraries and RapidFort Curated Libraries integration guides.

Other library registries can still be added as upstreams by using manual configuration. To register interest in additional quick configure vendor support, please contact us.


Keep up to date with our monthly product bulletin