Verify and inspect Docker images

Cloudsmith now displays Docker image signatures and SBOMs (Software Bill of Materials) directly in the web app, giving you greater trust and visibility into the images you use.

SBOMs and signatures have been available through the API to enable client-side verification, but this update makes them directly accessible and easier to inspect in the web app.

  • SBOMs list every dependency, version, and license inside a Docker image, helping you understand what’s in your software supply chain.
Viewing a Docker image's SBOM in the web app
  • Signatures let you verify authenticity with Cosign, including viewing ECDSA key details and checking packages against a trusted public key.
Viewing a Docker image's signatures in the web app

This change is part of a wider set of improvements to Docker images in the web app. All of these enhancements are available today for customers using Docker images in Cloudsmith. Contact us if you have questions or feedback.

Keep up to date with our monthly product bulletin