Policy management
Centralize control over your entire software supply chain - every package, dependency, format, and team - before software reaches developers, pipelines, or production.
Cooldown policies
Hold new package versions back for a set window so nothing untested lands in a build and package managers just resolve to the latest version that passes.
Security and Compliance Features
Features to safeguard your teams, customers, and reputation. Cloudsmith is a central checkpoint for software integrity.
Continuous risk detection
Surface newly disclosed risks automatically with continuous monitoring of packages against the latest security advisories.
Standard policies
Protect against CVEs, license compliance violations, malicious packages, and unwanted packages with built-in policy types.
Policy as code
Define rules with OPA/Rego, enforced automatically across every pipeline.
Cooldown policies
Prevent newly published packages from being consumed until a configurable time window elapses.
Upstream trust
Prevent trusted packages from being overridden by identically-named packages from untrusted sources.
Package quarantine
Prevent packages from being distributed to teams and pipelines when they fail policy checks.
Generate SBOMs for containers
Automatically generate SBOMs for container images including transitive dependencies and license metadata.
Host SBOMs
Store and distribute SBOM files alongside their corresponding packages or container images.
License reporting
Report on license types across repositories and organizations to support compliance management.
Package signing
Sign uploaded packages automatically with GPG or RSA.
Custom signing keys
Ensure packages have not been tampered with by signing with your own custom encryption keys.
Sigstore cosign support
Automatically verify your packages as part of your build pipeline using Sigstore.
Geographic location / IP restrictions
Ensure your software doesn't flow to problematic territories or specific IP ranges.
Custom storage regions
Remain in compliance with your corporate standards by specifying storage regions for your software artifacts.
Access Control Features
Features to control who can access the packages, containers, models and data managed in your Cloudsmith workspace.
Single sign-on via social auth
Use your existing social sign-on provider to authenticate against Cloudsmith.
Teams (team-based controls)
Assign privileges and permissions to groups of users organized in teams.
Service accounts
Allow bots and services to interact with your Cloudsmith resources using dedicated service accounts.
Log exports
Take your log data away for further analysis with automated log exports.
OpenID Connect
Use ephemeral OIDC tokens to connect Cloudsmith with third-party services, without long-lasting credentials.
Single sign-on via SAML
Use your existing ID provider like Okta to authenticate Cloudsmith users.
SAML groups
Model your org's teams and permissions in your ID provider, and automatically map to Cloudsmith.
SCIM
Automatically reflect changes to your real-world org in your Cloudsmith teams and users.
API key policies
Mitigate against security breaches by ensuring keys are updated regularly and automatically invalidated.
Documentation and Support
We are here to help!
Speak with one of our experts to see Cloudsmith’s feature set in action and get tailored advice to fit your use case