Cloudsmith announces new features for enforcing software supply chain governance in artifact repositories

Cloudsmith, the leading cloud-native artifact management and software supply chain platform, today announced an expansion to its policy management and continuous risk detection capabilities, adding policy templates, cooldown policies, and expanded evaluation triggers.

The new features continue to strengthen the artifact repository as the most critical point of control for securing the software supply chain and providing proactive protection for developers.

Select customers have been testing the new features and reporting significant benefits, especially from new cooldown and malicious package policies. Attacks increasingly target pipelines and open source packages, so one misconfigured pipeline can result in an incident. Since Cloudsmith policies apply company-wide at the repository level, the risk of a misconfigured pipeline is greatly reduced.

Christian Jensen, VP of Engineering at Tricentis, said, “Cloudsmith is one way in which we identify vulnerabilities and manage artifacts across teams and products we support. It allows us to secure our supply chain by enforcing policies at the registry, which lets us stop malicious packages before they ever reach a developer or a pipeline, and gives us clear and consistent visibility into high and critical vulnerabilities within those packages across the organization.”

Cloudsmith reduces time to policy enforcement, minimizes friction for developers, and ensures policy changes take effect immediately across repositories. New features being announced today include:

  • Policy templates: pre-configured policies as code, written in the Rego language, to jump-start a set of recommended baseline controls to begin enforcement immediately.
  • Cooldown policies: Highly configurable cooldown policies that apply across repositories, teams, and formats. Cloudsmith cooldown policies work by creating a filtered view of upstream public registry package indexes, so that each developer or CI/CD pipeline’s package managers see only versions that meet policy and thus default to the latest compliant version automatically. This prevents build failures and eliminates the need to revise dependency files.
  • Expanded evaluation triggers: In addition to evaluating on package upload and when threat intelligence updates, Cloudsmith policies now also evaluate when a policy is created or updated, without the need for a manual backfill step.

Together, these capabilities strengthen Cloudsmith’s role as a comprehensive, centrally-managed control plane for the software supply chain.

Alison Sickelka, Cloudsmith’s VP of Product, said “We created our policy management feature set because we believe the artifact registry is the right place to enforce control of the software supply chain. It’s one of our most quickly adopted feature sets ever, especially for cooldown and malicious package policies. Security teams need better ways to react, and they need to stop unsafe software at the boundary of their environment, before unwanted packages can reach developers or pipelines. Today’s updates give organizations an even stronger enforcement point across every team, every pipeline, and every package format.”

Learn more about continuous risk detection and policy management from Cloudsmith.


About Cloudsmith

Cloudsmith is the leading cloud-native, fully managed universal artifact management platform that helps platform engineering, DevOps, and cybersecurity teams control, secure, and distribute software artifacts globally. Supporting over 30 artifact formats — including containers, language packages, OS packages, and AI/ML models — Cloudsmith delivers enterprise-grade features including continuous vulnerability and malware scanning, SBOM generation, cryptographic signing, a policy-as-code engine, and a global package delivery network with intelligent edge caching. Cloudsmith is built for scale, compliance, and automation, enabling customers in banking, fintech, telecom, software, and AI-native industries to modernize their software supply chains with confidence. Cloudsmith is ISO 27001 and SOC 2 certified and trusted by customers worldwide. Learn more at https://www.cloudsmith.com.

Media contact

Resonance - cloudsmith@resonancecrowd.com

Other press articles

Tech Crunch: Microsoft’s open source tools were hacked to steal passwords of AI developers

Microsoft has cut off access to dozens of its open source projects hosted on GitHub as it investigates how hackers apparently breached the projects and injected password-stealing malware into the code. According to security firm Cloudsmith and community-driven malware analysis site OpenSourceMalware, which were some of the first to flag the hack, the malware allowed the hackers to steal the users’ passwords and other sensitive credentials when they opened the compromised tools in their AI coding apps.

Keep up to date with our monthly newsletter