Cloudsmith Joins Chainguard's Athena Coalition to Close the Gap Between Vulnerability Discovery and Customer Protection

Belfast, Northern Ireland - 28 September 2026 - Cloudsmith, the leading cloud-native enterprise artifact management platform, is now a member of Athena, the Chainguard-led industry coalition for the orchestrated defense of open source software. Cloudsmith customers get earlier and more comprehensive protection against vulnerabilities in open source software components.

Athena coalition members, including JPMorgan Chase, Cisco, Docker, and Kyndryl, shorten the window between vulnerability discovery and impact mitigation. The need for earlier protection is particularly important as threats targeting open source software become faster and more sophisticated. Recent Cloudsmith research found that just 38% of engineering teams screen software dependencies for threats before they enter their systems, despite 73% being confident their tooling can stop a malicious package before a security advisory exists.

As an Athena mitigation partner, Cloudsmith receives a dedicated pre-disclosure feed to protect customers before a patch is ready. Cloudsmith also contributes observed signs of active exploitation, strengthening threat intelligence for the coalition as a whole.

Protecting the software supply chain

Cloudsmith is the control plane for software dependencies in builds deployed to production systems. By joining Athena, Cloudsmith helps deliver a more secure software supply chain:

  • A safer Cloudsmith platform. Cloudsmith is critical infrastructure for delivering software, and will be more protected against novel malicious attacks.
  • Safer dependencies. By enriching Cloudsmith’s threat intelligence data set with findings sourced from Athena partners, Cloudsmith will be able to provide a better set of dependency choices to developers and AI agents, and pipelines.
  • A safer ecosystem. Cloudsmith will provide exploitation intelligence to Athena in order to help every mitigation partner respond faster.

Cloudsmith is building a more secure software supply chain. It’s a team sport, and we applaud Chainguard’s leadership in launching Athena. This is an innovative approach where vendors and consumers collaborate. Together, we protect the supply of open source artifacts. We’ve seen public registries come under unprecedented pressure from AI-powered threat actors. That said, we’re committed to keeping them safe. Open source public registries revolutionized how we build software, and we recognize our role alongside other Athena partners in protecting these registries as reliable sources of shared artifacts.

Glenn Weinstein

CEO, Cloudsmith

We built Athena because orchestrated defense is the only thing that keeps pace with AI-powered attacks. No single defender can cover the entire open source ecosystem alone. As a mitigation partner, Cloudsmith will play a vital role by delivering artifacts to developers and pipelines, bringing a uniquely valuable contribution to Athena.

Naveen Sharma

Global Vice President of Partnerships, Chainguard

What's next for customers

As Athena expands artifact coverage and adds partners, its vulnerability data and collaboration among members will produce better and more comprehensive protection of the global software supply chain.

Other press articles
Keep up to date with our monthly newsletter