Give members read-only access to billing, usage, and OIDC data
Workspace owners can grant each privilege separately, without giving members the Manager or Owner role…
Package logs are now available in the Cloudsmith web app, giving you a per-package audit trail: what changed, who changed it, and when.
Package logs sit alongside client and audit logs under Logs in the Cloudsmith web app:
Each entry records a timestamp, an action, the actor who performed it, and the affected package and version, plus detailed metadata such as package size and actor IP address.
You can filter the logs by action, target, and actor to isolate a single event or narrow an investigation.
Cloudsmith creates package logs for the following actions:
Package downloads are recorded in client logs.
For more details, see Package logs in the Cloudsmith documentation.
Workspace owners can grant each privilege separately, without giving members the Manager or Owner role…
When an exposed Cloudsmith API key is detected in a GitHub repository, the email notification sent to the affected Cloudsmith user and workspace owners now lists every location the key was found in GitHub, with a direct link to each detection…
You can now apply cooldown policies to Cargo packages, protecting your supply chain from newly published versions that may carry malware or have not yet undergone sufficient community scrutiny…
You can now apply cooldown policies to Conda and Docker packages, protecting your supply chain from newly published versions that may carry malware or have not yet undergone sufficient community scrutiny…
See how published packages are being consumed - downloads, entitlement token use, and client logs - without leaving the Broadcasts app…
Library registries provide a vendor-curated feed of open source packages. Packages may be pre-vetted, rebuilt from source, and security scanned by the vendor…