Axios. LiteLLM. Shai Hulud. All hit the same way. Here's how a control point at ingestion, policy-as-code, and continuous risk detection build a supply chain you can actually trust in 2026. Full breakdown ⬇️ cloudsmith.com/blog/trust-yo…
🚀 Now live: policy management and continuous risk detection, open to everyone on Cloudsmith. Write the rules once and enforce them at the repo level, across every pipeline and every developer and agent pulling code in. See it in action. cloudsmith.com/product/softw…
Most security tools find problems after they're already in your environment. A dependency firewall catches them at the door before a bad package ever reaches a build. Here's what that actually looks like.
cloudsmith.com/blog/how-to-u…
Kubernetes 1.37 drops August 26. Nigel from our team broke down everything worth knowing: new features, deprecations, and the DRA/AI stuff before it even ships. cloudsmith.com/blog/kubernet…
Malicious versions of #keyv and #cacheable are spreading through npm on their own; the payload runs on install, steals credentials, then uses them to infect more packages. 444 packages have been hit so far.
cloudsmith.com/blog/keyv-and…
Attackers didn't need a fake package this time. They hijacked #AsyncAPI's own CI/CD pipeline and shipped the malware through the real one – 2.9 million weekly downloads before anyone caught it. Full attack breakdown: cloudsmith.com/blog/inside-t…
A look at everything we shipped in Q2 2026, from connected repositories and policy automation to upstream improvements, package recovery, and more: in Q2🚀
cloudsmith.com/blog/what-clo…
Every container inherits its base image. If that image carries unpatched CVEs, your app does too, before you've written a line of code. Here's how to make @wiz_io WizOS hardened images the frictionless default across your org.
cloudsmith.com/blog/start-se…
Cloudsmith is now a @github secret scanning partner. If your API key ends up in a public repo, GitHub catches it and tells us. One more layer of control over your software supply chain 🛡️ github.blog/changelog/2026-0…
The logic is rather simple: if you can compromise the framework itself, you have the ability to compromise highly sensitive infrastructure. Today, it's happened again - this time #Mastra was the target. Full attack breakdown: cloudsmith.com/blog/inside-t…
Automate now > explain to regulators later.
87 days until the CRA's 24-hour reporting rule kicks in. We broke down what engineering teams should be working towards for compliance.
cloudsmith.com/blog/the-eu-c…
Your artifact registry and your deployment tool shouldn't be strangers. Cloudsmith decides what's allowed. @OctopusDeploy controls how it ships. Governance baked in, not bolted on. cloudsmith.com/blog/from-tru…
AI coding tools are pulling in dependencies faster than any senior engineer can review them.
AI's speed, matched with automation, guardrails, and a strong artifact management layer, provides a secure development foundation.
Here's how we think about it. ↓
Are you at PlatformCon London?
Join Spacelift and Cloudsmith TONIGHT at F1 Arcade London for an evening where competitive racing meets DevOps and platform engineering. Connect with peers, test your skills on full-spec racing simulators, and explore how to optimize your DevOps for both speed and control.
📅 Date: Wednesday, 25 June
⏰ Time: 7:00 PM - 10:00 PM BST
📍 Location: F1 Arcade London - 1 New Change, London EC4M 9AF, United Kingdom
🔥 Space is limited—reserve your spot now! 🔥
👉 events.spacelift.io/iac-gran…
See you there!
Is your Helm a risk? 🔍
If your business or open-source project relies on Helm charts, join Nigel Douglas, Head of Developer Relations at Cloudsmith, in a hands-on, virtual workshop during PlatformCon 2025: "What Supply Chain Risks Are Hidden in Your Helm Charts?"
Join this hands-on workshop to explore real-world Helm vulnerabilities and learn practical strategies to automate and strengthen your Kubernetes security posture.
Reserve your spot 👉 platformcon.com/sessions/wha…
🗓️ Friday, 27 June at 4:00 PM BST / 11:00 AM EST
📍 Virtual
#PlatformEngineering#PlatformCon2025#KubernetesSecurity#Helm
We're thrilled to be part of PlatformCon 2025, the world’s largest platform engineering conference! This year, we're bringing two high-impact virtual talks to the stage 💥
More Than Code: How Culture Defines Platform Success
Explore how team culture, not just tooling, shapes the true success of platform engineering 🌟
Artifact Management Unleashed: Powering Your Packages at Lightning Speed
Discover how to optimize package delivery and streamline your artifact workflows for peak performance 🚀
This week only, PlatformCon attendees can enter to win a $250 gift card at the end of each talk!
Watch now: cloudsmith.com/events/confer…#PlatformEngineering#PlatformCon25