Software supply chain security with Cloudsmith

Enforce trust across your software supply chain.

Block malicious dependencies, define guardrails for what’s allowed, and enforce policies automatically as AI-assisted development introduces dependencies faster than ever.

Today's reality

Software assembly has gotten faster, more automated, and harder to manually review. The controls most teams rely on weren't built for this.

    Detection isn’t enough. Teams need enforcement.
    Most security controls evaluate software at a specific point in the pipeline: a PR check, a CI scan, a post-deploy audit. These points matter, but gaps remain. Not every pipeline is configured the same way and enforcement isn’t always consistent.
    Point-in-time evaluation has a shelf life.
    A package that cleared ingestion this morning can be a liability by afternoon if new CVEs drop or threat intelligence changes.
    AI has changed how fast dependencies get pulled.
    Developers ship faster and pull more dependencies than ever. Some are chosen deliberately; others installed at the tool's suggestion without a review. The volume of software entering your environment has outpaced any team’s ability to manually evaluate it.

Cloudsmith is the control plane for your software supply chain.

Control every dependency in your environment and enforce policy directly at the artifact repository every developer, pipeline, and AI agent pulls from.

Policy management

Secure your teams and pipelines. Use policy management to interpret threat signals and automate actions.

  • Apply cooldown policies to block newly published, untrusted packages
  • Use industry standard OPA Rego to define software usage policies
  • Apply policies from ingestion through production, to every package and container that flows through Cloudsmith
  • Perform actions based on your policies
  • Manage exemptions when a package needs to move forward outside standard policy

Cooldown policies stop newly published packages before they reach your developers.

  • Set a cooldown window that holds newly published packages until they clear policy checks
  • Resolve automatically to the latest compliant version so builds succeed on the first try
  • Enforce the cooldown at the repository, not in individual pipelines or client-side tooling
  • Now supports npm, Python, Go, Maven, and NuGet, giving teams consistent protection across the ecosystems they rely on most

Outcomes

Control what enters your environment.

  • Proxy and cache all registries through Cloudsmith, serving every dependency from a single trusted source
  • Set policy once and enforce it across every team, every pipeline, and every format.
  • Stop vulnerabilities, malicious packages, and license violations before they move downstream
  • Block dependency confusion attacks by defining trusted and untrusted sources

Stay current on the latest threats

  • Cloudsmith continuously ingests the latest vulnerability and malicious package intelligence
  • Checks your repository instantly when new records are published
  • New threats automatically trigger policy evaluation to flag or block affected packages before they reach downstream teams.

Govern dependency selection by your AI agents just like you do your developers.

  • Route every install, human or AI-driven, through one dependency firewall, leaving no separate path to govern
  • Apply the same policies to agent and assistant pulls automatically, catching unsafe packages before use
  • Enforce license policies at the repository, blocking incompatible licenses

Use SBOM data in your decision-making.

  • Generate SBOMs for container images automatically
  • Store and share SBOMs alongside the artifacts they describe
  • Surface risk in components already in your environment as threat intelligence changes

Continuous risk detection

Packages are continuously re-evaluated against the latest advisories, surfacing newly disclosed risks automatically.

License reporting

Report on license types across repositories and organizations to support compliance management.

Policy-as-code

Define rules with OPA/Rego, enforced automatically across every pipeline.

Cooldown policies

Prevent newly published packages from being consumed until a configurable time window elapses.

Package quarantine

Prevent packages from being distributed to teams and pipelines when they fail policy checks.

Upstream trust

Stop trusted packages from being overridden by identically-named packages from untrusted sources.

SBOM management

Automatically generate SBOMs for container images including transitive dependencies and license metadata.

Custom signing keys

Ensure packages have not been tampered with by signing with your own custom encryption keys.

Powerful Features. Simple Control.

See the software supply chain control plane in action

Ease of access to vulnerability information - and the ability to act on it - has been the biggest change for us... We’re a stone’s throw away from having zero high or critical vulnerabilities in our supply chain.

Rich Dammkoehler

VP Architecture & Governance @ ConstructConnect

Before

The InfoSec group at ConstructConnect demanded stronger software supply chain security. Artifact organization was fragmented, data usage and storage constraints were challenging to manage, and the JFrog platform lacked visibility, leading to limited overall control and security assurance. With their contract set to expire in July 2025, it became clear that staying on JFrog would continue to restrict velocity, security, and scalability.

With Cloudsmith
  • Secure software supply chain
  • Fully-managed, cloud-native platform
  • Scalable infrastructure
Results
  • Minimized high or critical vulnerabilities in our supply chain
  • Reduced the management burden
  • Faster, more reliable builds with automation and integrations

Additional Resources

Get started with Cloudsmith