Cloudsmith Blog

Featured
Integrations & partners
22 min read

Kubernetes 1.37 – What you need to know

Kubernetes 1.37 launches in August 2026. The Cloudsmith team breaks down all relevant enhancements across Networking, Scheduling, CLI and more…
Supply chain security
5 min read

Inside the AsyncAPI npm supply chain attack

On July 14th, an attacker hijacked AsyncAPI's own CI/CD pipeline to publish four trojanized npm packages under a trusted namespace – reaching 2.9 million weekly downloads before anyone noticed. No bad reputation, no known-malicious version, nothing for conventional defenses to catch. Here's how it happened, and what would have stopped it…
Latest
Series
Keep up to date with our monthly newsletter

By submitting this form, you agree to our privacy policy