Cloudsmith glossary
20 glossary definitions
A
C
Code signingCode Signing is the process of digitally signing software so users can verify two key facts:ComplianceCompliance refers to following the laws, regulations, standards, and internal policies that apply to an organization. These rules may relate to data protection, financial…CopyleftCopyleft is a licensing principle used in some open-source software that allows users to freely use, modify, and distribute code, as long as any…
D
G
General public licenseThe General Public License (GPL) is one of the most widely known copyleft open-source licenses. Created by the Free Software Foundation, its purpose is…GPG keyA GPG Key (GNU Privacy Guard Key) is a cryptographic key pair used for encryption and digital signatures. It allows users and systems to…
L
License complianceLicense Compliance is the practice of ensuring that all software within an organization is used in accordance with its licensing terms, whether the software…License managementLicense Management is the process of tracking, controlling, and optimizing software licenses across an organization. It ensures businesses remain compliant with license agreements while…
M
O
P
S
SBOM (Software Bill of Materials)A Software Bill of Materials (SBOM) is a detailed inventory of every software component that comprises an application, including open-source libraries, third-party dependencies, frameworks,…Security scanningSecurity Scanning is the process of automatically examining software, systems, code, and infrastructure to detect security vulnerabilities, misconfigurations, malware, and risky behavior before attackers…SIEM (Security Information and Event Management)Security Information and Event Management, or SIEM, helps solve cybersecurity problems by aggregating and analyzing log data from across an organization’s entire digital…Software license complianceSoftware License Compliance is the practice of ensuring that all software inside an organization from SaaS subscriptions to open-source libraries, is being used strictly…Software supply chain attackA software supply chain attack is a cyberattack that targets an organization by compromising the third-party components, tools, or processes used to build and…Software supply chain securitySoftware Supply Chain Security is the practice of protecting every stage of the software lifecycle, from coding and dependency selection, through building, signing, distribution,…