At Cloudsmith, we recognize that security is a team sport. Meaningful improvements to our platform have come from researchers and security professionals who take the time to find issues and report them to us responsibly.
Today, we're launching a new bug bounty platform - now live at bounties.cloudsmith.com - built to make it faster, clearer, and more rewarding to submit security-related bugs to Cloudsmith.
Bug bounty programs are important
Our responsible disclosure program is a cornerstone of how we protect our customers. External reports have helped us discover and remediate vulnerabilities we might otherwise have missed - and almost always before they could affect actual users. Strong security programs are proactive, collaborative, and grounded in a shared goal of keeping the software supply chain safe.
We’ve relied historically on email inboxes and ticket-based systems, but Cloudsmith now serves a far larger enterprise customer base than we did in our early days. It was time to upgrade the process of submitting and processing reports..
The new platform is made for security researchers
With our new platform, each submission flows through a dedicated site designed for speed and transparency, showing researchers where each report stands.
In conjunction with this platform upgrade, we've made a significant change to payout timing. Rewards are now issued once we’ve confirmed a qualifying defect, rather than waiting for a fix to be deployed.
Thank you to our security researcher partners
Security is a shared responsibility, and our program reflects our commitment. We hope our new platform also reflects our commitment to encouraging security researchers to work with Cloudsmith.
If you've found something, we want to hear from you. Learn more at our Bug Bounty Program page. Thank you for helping us keep Cloudsmith secure.
The Cloudsmith CLI now eliminates the need for static API keys in CI/CD pipelines by automatically discovering OpenID Connect (OIDC) credentials for all major CI/CD platforms and includes a Docker credential helper to automatically authenticate to Cloudsmith registries…
You can now apply cooldown policies to Maven packages, protecting your supply chain from newly published versions that may carry malware or have not yet undergone sufficient community scrutiny…
You can now apply cooldown policies to NuGet packages, protecting your supply chain from newly published versions that may carry malware or have not yet undergone sufficient community scrutiny…
Cloudsmith has joined the GitHub secret scanning partner program. This integration helps prevent unauthorized use of your API keys by automatically detecting exposed keys before they can be exploited…