---
title: "Cloudsmith glossary"
description: "Definitions for software supply chain security, artifact management, compliance, and cloud-native delivery."
canonical_url: "https://cloudsmith.com/resources/glossary"
last_updated: ""
---
# Cloudsmith glossary

## A

### [Audit trail](https://cloudsmith.com/resources/glossary/audit-trail)

An Audit Trail is a chronological, tamper-resistant record of actions taken within a system, such as user logins, configuration changes, approvals, or data access…

## C

### [Code signing](https://cloudsmith.com/resources/glossary/code-signing)

Code Signing is the process of digitally signing software so users can verify two key facts:

### [Compliance](https://cloudsmith.com/resources/glossary/compliance)

Compliance refers to following the laws, regulations, standards, and internal policies that apply to an organization. These rules may relate to data protection, financial…

### [Copyleft](https://cloudsmith.com/resources/glossary/copyleft)

Copyleft is a licensing principle used in some open-source software that allows users to freely use, modify, and distribute code, as long as any…

## D

### [Data privacy](https://cloudsmith.com/resources/glossary/data-privacy)

Data Privacy refers to the responsible handling of personal and sensitive information, including how it is collected, stored, used, shared, protected, and eventually deleted.…

## G

### [General public license](https://cloudsmith.com/resources/glossary/general-public-license)

The General Public License (GPL) is one of the most widely known copyleft open-source licenses. Created by the Free Software Foundation, its purpose is…

### [GPG key](https://cloudsmith.com/resources/glossary/gpg-key)

A GPG Key (GNU Privacy Guard Key) is a cryptographic key pair used for encryption and digital signatures. It allows users and systems to…

## L

### [License compliance](https://cloudsmith.com/resources/glossary/license-compliance)

License Compliance is the practice of ensuring that all software within an organization is used in accordance with its licensing terms, whether the software…

### [License management](https://cloudsmith.com/resources/glossary/license-management)

License Management is the process of tracking, controlling, and optimizing software licenses across an organization. It ensures businesses remain compliant with license agreements while…

## M

### [Model cards](https://cloudsmith.com/resources/glossary/model-cards)

Model Cards are documentation frameworks used to describe machine-learning models in a transparent and understandable way. They explain how a model was trained, what…

## O

### [Open source license](https://cloudsmith.com/resources/glossary/open-source-license)

An Open Source License is a legal agreement that defines how open-source software may be used, modified, and distributed. It protects both developers and…

## P

### [Package signing](https://cloudsmith.com/resources/glossary/package-signing)

Package Signing is the process of cryptographically signing software packages – such as libraries, installers, updates, or container images, so users can verify their…

## S

### [SBOM (Software Bill of Materials)](https://cloudsmith.com/resources/glossary/sbom)

A Software Bill of Materials (SBOM) is a detailed inventory of every software component that comprises an application, including open-source libraries, third-party dependencies, frameworks,…

### [Security scanning](https://cloudsmith.com/resources/glossary/security-scanning)

Security Scanning is the process of automatically examining software, systems, code, and infrastructure to detect security vulnerabilities, misconfigurations, malware, and risky behavior before attackers…

### [SIEM (Security Information and Event Management)](https://cloudsmith.com/resources/glossary/siem)

Security Information and Event Management, or SIEM,  helps solve cybersecurity problems by aggregating and analyzing log data from across an organization’s entire digital…

### [Software license compliance](https://cloudsmith.com/resources/glossary/software-license-compliance)

Software License Compliance is the practice of ensuring that all software inside an organization from SaaS subscriptions to open-source libraries, is being used strictly…

### [Software supply chain attack](https://cloudsmith.com/resources/glossary/software-supply-chain-attack)

A software supply chain attack is a cyberattack that targets an organization by compromising the third-party components, tools, or processes used to build and…

### [Software supply chain security](https://cloudsmith.com/resources/glossary/software-supply-chain-security)

Software Supply Chain Security is the practice of protecting every stage of the software lifecycle, from coding and dependency selection, through building, signing, distribution,…

## T

### [Trusted publishers](https://cloudsmith.com/resources/glossary/trusted-publishers)

Trusted Publishers are verified organizations or developers who digitally sign and distribute software so users and systems can confirm the authenticity of the source.…

## V

### [Vulnerability management](https://cloudsmith.com/resources/glossary/vulnerability-management)

Vulnerability Management is the ongoing process of finding, assessing, prioritizing, and fixing security weaknesses in software, systems, and infrastructure. Instead of reacting only when…
