Strengthening security together: Updating our bug bounty platform

At Cloudsmith, we recognize that security is a team sport. Meaningful improvements to our platform have come from researchers and security professionals who take the time to find issues and report them to us responsibly.

Today, we're launching a new bug bounty platform - now live at bounties.cloudsmith.com - built to make it faster, clearer, and more rewarding to submit security-related bugs to Cloudsmith.

Bug bounty programs are important

Our responsible disclosure program is a cornerstone of how we protect our customers. External reports have helped us discover and remediate vulnerabilities we might otherwise have missed - and almost always before they could affect actual users. Strong security programs are proactive, collaborative, and grounded in a shared goal of keeping the software supply chain safe.

We’ve relied historically on email inboxes and ticket-based systems, but Cloudsmith now serves a far larger enterprise customer base than we did in our early days. It was time to upgrade the process of submitting and processing reports..

The new platform is made for security researchers

With our new platform, each submission flows through a dedicated site designed for speed and transparency, showing researchers where each report stands.

In conjunction with this platform upgrade, we've made a significant change to payout timing. Rewards are now issued once we’ve confirmed a qualifying defect, rather than waiting for a fix to be deployed.

Thank you to our security researcher partners

Security is a shared responsibility, and our program reflects our commitment. We hope our new platform also reflects our commitment to encouraging security researchers to work with Cloudsmith.

If you've found something, we want to hear from you. Learn more at our Bug Bounty Program page. Thank you for helping us keep Cloudsmith secure.

Keep up to date with our monthly product bulletin