Ship trusted software, fast. Cloud-native artifact management for the AI era — security enforced before packages reach your build environment.

The Cloud (obviously)
We’ve joined @chainguard_dev's Athena as a mitigation partner. @alancarson shares why.
8
Move fast (with guardrails).
1
1
56
Your artifact registry and your deployment tool shouldn't be strangers. Cloudsmith decides what's allowed. @OctopusDeploy controls how it ships. Governance baked in, not bolted on. cloudsmith.com/blog/from-tru…
1
74
Valid SLSA attestations. Legitimate OIDC tokens. 73 repos down. The Miasma worm shows why signed isn't the same as safe. cloudsmith.com/blog/miasma-w…
61
AI coding tools are pulling in dependencies faster than any senior engineer can review them. AI's speed, matched with automation, guardrails, and a strong artifact management layer, provides a secure development foundation. Here's how we think about it. ↓
1
41
Join @cloudsmith, @rootlyhq, Mend.io, @ClickHouseDB, and @Docker in NYC for an evening of cocktails, conversations, and connections. 📍 Diamante’s | 410 8th Ave, NYC 📅 Wed, June 17 | 5:30-8:30 PM 🍸 RSVP: luma.com/odgqf98e?utm_source…
1
128
Are you at PlatformCon London? Join Spacelift and Cloudsmith TONIGHT at F1 Arcade London for an evening where competitive racing meets DevOps and platform engineering. Connect with peers, test your skills on full-spec racing simulators, and explore how to optimize your DevOps for both speed and control. 📅 Date: Wednesday, 25 June ⏰ Time: 7:00 PM - 10:00 PM BST 📍 Location: F1 Arcade London - 1 New Change, London EC4M 9AF, United Kingdom 🔥 Space is limited—reserve your spot now! 🔥 👉 events.spacelift.io/iac-gran… See you there!
1
4
1,062
Is your Helm a risk? 🔍 If your business or open-source project relies on Helm charts, join Nigel Douglas, Head of Developer Relations at Cloudsmith, in a hands-on, virtual workshop during PlatformCon 2025: "What Supply Chain Risks Are Hidden in Your Helm Charts?" Join this hands-on workshop to explore real-world Helm vulnerabilities and learn practical strategies to automate and strengthen your Kubernetes security posture. Reserve your spot 👉 platformcon.com/sessions/wha… 🗓️ Friday, 27 June at 4:00 PM BST / 11:00 AM EST 📍 Virtual #PlatformEngineering #PlatformCon2025 #KubernetesSecurity #Helm
1
4
828
We're thrilled to be part of PlatformCon 2025, the world’s largest platform engineering conference! This year, we're bringing two high-impact virtual talks to the stage 💥 More Than Code: How Culture Defines Platform Success Explore how team culture, not just tooling, shapes the true success of platform engineering 🌟 Artifact Management Unleashed: Powering Your Packages at Lightning Speed Discover how to optimize package delivery and streamline your artifact workflows for peak performance 🚀 This week only, PlatformCon attendees can enter to win a $250 gift card at the end of each talk! Watch now: cloudsmith.com/events/confer… #PlatformEngineering #PlatformCon25
3
406
In April, Scattered Spider cracked M&S’s systems in a massive ransomware attack. It all started with the theft of an NTDS.dit file. See Nigel Douglas’s advice for practitioners securing their CI/CD pipelines against lateral movement: cloudsmith.com/blog/owasp-ci… Full guide: cloudsmith.com/campaigns/gui… #DevSecOps #OWASP #CI/CD
1
2
336
🌍 Cloudsmith is proud to sponsor PlatformCon 2025 - the worlds biggest platform engineering event! Join us for a full week of all things platform engineering—including free virtual sessions packed with insights into cloud-native artifact management at scale 🚀 Here’s what we’re bringing to the table: 💡 23-27 June | 2 Virtual Talks • More Than Code: How Culture Defines Platform Success — Explore how platform strategy aligned with company goals enables empowered engineering teams. • Artifact Management Unleashed: Powering Your Packages at Lightning Speed — Discover how smart caching and optimized registry access can supercharge your package delivery. 🇬🇧 25 June | London Live Day - Booth 8 • Stop by Booth 8 to see why Cloudsmith is the world’s best cloud-native artifact management platform—fully managed, built for scale, and designed to secure and streamline everything in your software supply chain. • Get hands-on with the Cloudsmith platform, enter to win great prizes, and take home great swag! 🗓️ When: Wednesday, 25 June 📍 Where: Convene Sancroft, St. Paul's - London 🛠️ 27 June | Virtual Workshop • What Supply Chain Risks Are Hidden in Your Helm Charts? — A hands-on deep dive into vulnerabilities, attack scenarios, and best practices for securing Helm charts, ensuring supply chain security and compliance. 👉 Learn more & explore our sessions: cloudsmith.com/events/confer… #PlatformEngineering #PlatformCon25 #ArtifactManagement
2
245
QA ≠ Admin Developer ≠ Release Manager Strong Pipeline-Based Access Controls (PBAC) rely on separating duties across the pipeline: cloudsmith.com/blog/owasp-ci… Download a full guide on OWASP’s CI/CD Top 10 risks: cloudsmith.com/campaigns/gui… #PBAC #OWASP #CI/CD
2
167
Look familiar? If you’d like a refresher on best practices for tackling Poisoned Pipeline Execution, we’re running through OWASP’s CI/CD Top 10 risks with advice on how to deal with these types of unauthorised executions. Check out Part 4: cloudsmith.com/blog/owasp-ci… Download the free guide: cloudsmith.com/campaigns/gui…
1
150
Is vibe coding more of a risk than a vibe? “Without security-aware tooling or policy enforcement, enterprises could end up unknowingly introducing vulnerabilities.” — said Nigel Douglas to The New Stack. Read more: thenewstack.io/vibing-danger…
126
“We wanted a product that was easy to use and hard to misuse.” 🎥 Listen to our CTO Lee Skillen discuss the mindset behind building for critical use: simple, secure, and cloud-native from day zero.
2
109
To help you combat the rise in seemingly harmless malicious packages, we’ve broken down some best practices in Part 3 of the Cloudsmith and OWASP CI/CD Top 10 series on Dependency Chain Abuse. Read the blog: cloudsmith.com/blog/owasp-ci… Download the free guide: cloudsmith.com/campaigns/gui…
2
113
If you’re looking to reduce exposure from over-permissive roles, stale access, or shared credentials, reviewing identity and access management best practice could make all the difference. In Part 2 of our OWASP CI/CD Top 10 series, we’re looking at CICD-SEC-2: Inadequate Identity and Access Controls. Read the blog: cloudsmith.com/blog/owasp-ci… Download the free guide: cloudsmith.com/campaigns/gui…
1
106
As software supply chain threats grow, securing your CI/CD pipeline is critical. Join Esteban Garcia (Principal Engineer, Cloudsmith), Liana Ertz (Product Manager, Cloudsmith), and Jason van Zyl (Senior Engineering Manager, Chainguard) for a 30-minute session covering: ➡️ Techniques for signing and verifying artifacts with open-source tools (SBOMs, provenance data) ➡️ Enforcing security policies to block unverified software from production ➡️ Managing and storing signed artifacts in CI/CD pipelines using Cloudsmith & Chainguard ➡️ Ensuring compliance with audit logs, tamper-proof metadata, and secure artifact lifecycle management 📅 June 3, 2PM EST — 30 minutes Live Q&A included | Recording sent to all registrants Register here ➡️   cloudsmith.com/webinars/unlo… #CICDSecurity #DevSecOps #Chainguard #Cloudsmith #OpenSourceSecurity #SoftwareDelivery #DevTools #Webinar #ArtifactSigning
111
Use CodeQL to detect vulnerabilities? Until recently, there was a big one hiding in plain sight. Researcher John Stawinski discovered a vulnerability (now patched) in the GitHub Action used by CodeQL. Check out the full article from DevClass here: devclass.com/2025/04/02/the-… #SoftwareSupplyChain #DevSecOps #ArtifactManagement #GitHubActions
2
119
Scrambling to pull together chain of custody for security audits? See how Diligent transformed its secure software delivery with Cloudsmith: cloudsmith.com/customers/clo… #SoftwareSupplyChain #DevSecOps #ArtifactManagement #SBOM
1
92
Attackers are increasingly targeting containers, artifact registries, and CI/CD pipelines, burdening DevOps orgs with more responsibility to secure build processes. In our 30-minute live webinar - State of the Union: Modern Security Approaches for the Software Supply Chain - Michael Donovan (VP of Product, Docker, Inc), Ralph McTeggart (Principal Engineer, Cloudsmith), and Jack Gibson (Senior Software Engineer, Cloudsmith) will discuss: 🔹 Real-world examples of attacks on containers and CI/CD workflows 🔹 How to secure your artifact lifecycle from build to deploy 🔹 Why SBOMs, signing, and provenance matter more than ever Save your seat for May 27 👉 cloudsmith.com/webinars/stat… #Docker #Cloudsmith #CyberSecurity #DevSecOps #Containers #CI/CD #SBOM
2
99
Aiming to achieve SLSA Level 2? A cloud-native artifact management platform lets you enforce immutability, track artifact provenance, and control who can publish what. Read more: cloudsmith.com/blog/slsa-a-r… #SLSA #SoftwareSupplyChain #DevSecOps
1
76
Most enterprises have dozens of software development teams Best practice is to build policy checks directly into artifact management, so every package that enters your pipeline is secure, compliant, and production-ready by default. See how it works: cloudsmith.com/blog/streamli… #SoftwareSupplyChain #DevOps #ArtifactManagement #CICD
1
72
Meet the new team. We’re delighted to welcome three new leaders to scale and solidify our support for the enterprise market. Welcome to the team! #SoftwareSupplyChain #ArtifactManagement #DevOps
1
2
7
561
Because modern developers need modern UI. Introducing Cloudsmith Dark Mode. 🔗: changelog.cloudsmith.com/en/… #DevOps #SoftwareSupplyChain #UX #ArtifactManagement
1
4
299
“We’re all believers in what we’re doing… [which is] delivering true value to customers.” Our CEO, @GlennWeinstein, couldn’t have put it better. #SoftwareSupplyChain #ArtifactManagement #DevOps
1
6
133
🛠️ HANDS-ON at KubeCon! 📍 Booth S280 (South Hall) | #KubeCon #CloudNativeCon Bring Your Own Artifacts 🔧 What package formats power your cloud-native web app? Stop by and get hands-on with YOUR real-world software artifacts using Cloudsmith. Whether it's Docker, Python, Terraform, or more—we support them. Try it yourself and discover how artifact management should work. #DevOps #CloudNative #ArtifactManagement #KubeConEurope
1
2
184
The wait is almost over – KubeCon + CloudNativeCon Europe 2025 starts TOMORROW! 🎉 With so much happening, it’s time to lock in your schedule. Here’s what you CAN’T miss: ✅ Keynotes from industry leaders shaping the future of cloud-native ✅ Kubernetes security & software supply chain deep-dives 🔐 ✅ Hands-on demos at Booth S280 – See how Cloudsmith streamlines artifact management & software delivery ✅ The ultimate DevSecOps networking party – DevSecOnTheRocks 🎸🍻 ✅ The Passport Program – Win epic prizes! 🎮 Grab a “Passport to Security” at our booth & enter to win a Nintendo Switch, Meta Sunglasses, & more! 📍 Where to find us: Booth S280, South Hall – ExCeL London Save this post & get ready for an amazing week in London! What’s at the top of your agenda? Drop it in the comments! 👇 #KubeCon #CloudNative #Kubernetes #DevOps #ArtifactManagement #London2025
1
100
Software supply chain security needs to be easier. We help teams curate and secure their software supply chain because sourcing from a trusted internal registry is faster, safer, and easier than pulling from public upstream. #SoftwareSupplyChain #DevSecOps #ArtifactManagement
2
93
📢 ONE WEEK TO GO! The Kubernetes and cloud-native event of the year is almost here, and we’re getting everything ready for an incredible week in London. 🔹 Where? Booth S280, South Hall – ExCeL London 🔹 When? April 1-4, 2025 🌟 What’s happening? ✅ LIVE DEMOS – See Cloudsmith in action & learn how to secure, scale, and accelerate software delivery. ✅ The Passport Program – Collect stamps from us & our partners to win epic prizes (Nintendo Switch, Meta Sunglasses, PlayStation Portal & more!) 🎮 ✅ 1:1 Consultations – Have questions about artifact management? Book a personalized chat with our experts. ✅ DevSecOnTheRocks – The best DevSecOps networking event of KubeCon! 🔐🍻 ✅ House of Kube – The must-attend opening night party! 🚀 Haven’t locked in your plans yet? You can still book a meeting, request a discounted pass, or RSVP to our events! Sign up here ➡️ cloudsmith.com/campaigns/kce… See you in London! Who’s ready? Drop a 🔥 in the comments! #KubeCon #CloudNative #Kubernetes #DevOps #ArtifactManagement #London2025
2
82
KubeCon Europe 2025 is packed with game-changing keynotes, deep-dive sessions, and hallway track convos. From container security to supply chain resilience, there’s something for everyone. 👉 What topics are you most excited to learn about this year? Comment below! P.S. Don’t forget to swing by Booth S280 for live demos on artifact management and a chance to grab some exclusive Cloudsmith swag! 🎁🔥 Sign up here ➡️ cloudsmith.com/campaigns/kce… #KubeCon #CloudNative #Kubernetes #DevSecOps #london2025
1
2
157
⏳ The countdown continues – just 2 WEEKS until KubeCon Europe 2025! 🚀 We’re gearing up for an incredible week in London, April 1-4 at the ExCeL Center. Expect: 💡 Expert-led sessions on the future of cloud-native 🎯 Live demos at Booth S280 (come say hi!) 🍻 DevSecOnTheRocks – an unmissable networking event! We’ll be showing how Cloudsmith makes secure, cloud-native artifact management a breeze. Don’t miss out! 📅 Have you planned your KubeCon schedule yet? What sessions or booths are on your list? Let us know below! ⬇️ cloudsmith.com/campaigns/kce… #KubeCon #CloudNative #Kubernetes #DevSecOps #London2025
2
87
🚀 𝗛𝗲𝗮𝗱𝗲𝗱 𝘁𝗼 #𝗞𝘂𝗯𝗲𝗖𝗼𝗻 + #𝗖𝗹𝗼𝘂𝗱𝗡𝗮𝘁𝗶𝘃𝗲𝗖𝗼𝗻 𝗘𝘂𝗿𝗼𝗽𝗲 𝗶𝗻 𝗟𝗼𝗻𝗱𝗼𝗻 (𝗔𝗽𝗿𝗶𝗹 𝟭-𝟰)? 𝗦𝗼 𝗮𝗿𝗲 𝘄𝗲!📍 Booth S280 (South Hall) is where you’ll find Cloudsmith, your go-to partner for cloud-native, enterprise-grade artifact management. Stop by to: ✅ Chat with our experts about cutting costs, boosting productivity & securing your software supply chain ✅ See a live demo—anytime! ✅ Grab some awesome swag 🎁𝗥𝗲𝘀𝗲𝗿𝘃𝗲 𝗮 𝗱𝗲𝗺𝗼 𝗼𝗿 𝗿𝗲𝗾𝘂𝗲𝘀𝘁 𝗮 𝗱𝗶𝘀𝗰𝗼𝘂𝗻𝘁𝗲𝗱 𝗽𝗮𝘀𝘀 ➡️ cloudsmith.com/campaigns/kce… Let’s talk cloud-native, DevOps, and next-gen artifact management. See you there! 👋 #KubeCon #CloudNativeCon #SoftwareSupplyChain #DevOps #ArtifactManagement
1
109
Cloudsmith has raised $23M in Series B funding, led by @TCVTech with additional investment from @insightpartners. This fuels our mission to simplify, secure, and scale software delivery, giving teams full control over every package, every dependency, everywhere. More here: cloudsmith.com/company/press… #SeriesB #DevOps
1
3
221
You shouldn’t have to second-guess what’s in production. 90% of your code comes from external sources. Keeping track of it all shouldn’t be a battle. Cloudsmith helps teams manage complexity and track provenance, “so that when problems occur, you know how to fix them.” #DevOps #ArtifactManagement
108
No manual setup. No API keys. Just seamless integration. The new Cloudsmith CLI GitHub Action automates package management, authenticates with OIDC, and streamlines CI/CD. Get started: cloudsmith.com/blog/announci… #DevOps #GitHub #ArtifactManagement
2
112
Did you see the report on a compromised Go package that went undetected for three years? Join Cloudsmith’s Alison Sickelka & Paddy Carey to learn how data can protect your pipeline. 📅 Feb 25 | 1 PM ET Register: webinars.techstronglearning.… #SoftwareSupplyChain #DevOps #CyberSecurity
59
A customer downloads your software, but did they accept the license? @ProGlove faced the same issue—until it automated EULA tracking with Cloudsmith. Read more: cloudsmith.com/customers/clo… #SoftwareSupplyChain #DevOps #ArtifactManagement
63
“It’s crazy to allow developers to connect directly to a public, community-driven artifact repository.” Alan Carson explains how Cloudsmith acts as a buffer, keeping your pipeline secure. #SoftwareSupplyChain #DevSecOps #ArtifactManagement
182
What would you say if someone told you switching platforms wasn’t worth the risk? "There’s a better way. Change unlocks business potential—you shouldn’t be afraid of it." That’s Alison Sickelka, our VP of Product, on why the right partner makes all the difference. Hear her take. #SoftwareSupplyChain #DevOps #ArtifactManagement
1
86
Two days of collaboration, strategy, and problem-solving: all focused on making Cloudsmith work better for you. From refining our roadmap to scaling enterprise experiences, everyone deserves a faster, smarter way to manage their software supply chain. #Cloudsmith #DevOps #SoftwareSupplyChain
1
80
"If an open-source library has a vulnerability, you may struggle to know where the software is in production." Our CEO, Glenn Weinstein, explains how Cloudsmith provides a single source of truth to secure and manage dependencies with confidence. Watch below: #DevOps #CyberSecurity #SoftwareSupplyChain
59
Compliance is more than rules - it’s your reputation, resilience, and the foundation of trust in software. At Cloudsmith, we see it as proactive protection, not reactive patchwork. How does your team stay ahead? Automated checks? Real-time monitoring? Share your playbook below. ⬇️ Compliance isn’t the cost of doing business - it’s the cost of staying in business. @Sonatype — thoughts? #Compliance #DevSecOps #SoftwareSupplyChain
65
This past year taught us a lot about what fast, secure artifact distribution can unlock for teams. In 2024, Cloudsmith customers delivered 53% more packages than the year before. Learn more: cloudsmith.com/blog/cloudsmi… #ArtifactManagement #SoftwareSupplyChain #DevOps
57
Are you doing DevSecOps right? Forrester outlines the 4 phases where vulnerabilities lurk in your supply chain. More here: forrester.com/blogs/are-you-… Cloudsmith is here to help simplify and secure your artifact management every step of the way. 💡 What's your biggest DevSecOps challenge? #DevSecOps #Cloudsmith #Security #Developers
42
You’re managing a system that’s been moved to the cloud, but it still feels like a traditional setup. If you’re stuck fixing issues that shouldn’t exist, it might be time to explore the difference between “cloud-hosted” and “cloud-native.” Faster scaling, reduced maintenance, and fewer headaches await. Here’s where to start: cloudsmith.com/blog/cloud-na…
45
How often do your tools get in the way of your delivery process? With Broadcasts, you can: -Manage who gets what, with policies you control. -Deliver artifacts instantly, backed by a global network. -Gain insights from advanced analytics to improve every release. Learn more: cloudsmith.com/blog/elevatin… #SoftwareDistribution #DevTools #ArtifactManagement
65
Catching vulnerabilities is a great start towards controlling them. Datadog’s Supply-Chain Firewall scans public packages in real-time, flagging risks. Good, but reactive. It means vulnerabilities are caught after packages are pulled in. A curated repository flips that: policies enforced upfront, so you don't have to worry about surprises. Full analysis: cloudsmith.com/blog/thoughts… #Cloudsmith #SoftwareSupplyChain #DevSecOps
92
Migrating away from @jfrog Artifactory? We've got the roadmap to help you take control. ✅ Minimize downtime ✅ Strengthen security ✅ Simplify your workflows Our step-by-step guide breaks it all down. Start here: cloudsmith.com/blog/masterin… Managing artifacts shouldn’t slow you down—it should set you free to innovate. #Cloudsmith #SoftwareSupplyChain
89
If you couldn't make our #SoftwareSupplyChain 2025 predictions webinar, keep an eye out for: 1. Stricter security measures 2. Centralized management platforms. 3. Threat actors using AI 4. New, developer-first intelligent tooling Watch the recording: bigmarker.com/orbitalx-webin… #Cloudsmith
48
ICYMI: Cloudsmith’s Advanced Observability Suite launched just over a month ago. Here’s why it matters: 🔍 Full visibility: Track every artifact across geographies, pipelines, and workflows. ⚡ Proactive insights: Catch vulnerabilities before they catch you. 🤝 Effortless integrations: Works seamlessly with your existing tools. It’s all about helping developers and teams to simplify supply chains, focus on what they do best, and ship better, faster, safer software. #SoftwareSupplyChain #DevOps #Cloudsmith
60
What’s next for 2025? 🚀 At 9 years old, we’re stepping up—outgrowing our office and ready for bigger challenges. None of this would be possible without YOU—our incredible users and customers. Cloudsmith CEO Glenn Weinstein reflects on 2024’s wins, lessons, and how enterprises can take control of their software supply chains in 2025. 👉 Read & watch: cloudsmith.com/blog/a-year-t… #DevSecOps #Cloudsmith #SoftwareSupplyChain
65
🎄 December is for devs! Cloudsmith is sponsoring Advent of Code 2024—where creativity meets code. Sharpen your skills, solve puzzles, and join a global coding celebration. Day 24 is already underway: adventofcode.com/ #DevCommunity #CodingFun #AdventOfCode #SoftwareEngineering
2
83
The new Cloudsmith web app: Reimagined for you Streamline your artifact management with: ⚡ Fewer clicks, more coding. 🔍 Data-driven insights, always at your fingertips. 💨 Optimized for speed, because your time matters. Your software supply chain just got smarter and simpler. Discover how: cloudsmith.com/blog/launchin… #ArtifactManagement #DeveloperTools #SoftwareSupplyChain
1
59
Why did Kong trust Cloudsmith for artifact management? 🗨️ “Our engineers love Cloudsmith. Complaints about our distribution mechanisms have gone to zero.” – Saju Pillai, SVP of Engineering, Kong Discover how we help teams eliminate artifact chaos. cloudsmith.com/customers/clo… #DevSecOps #Cloudsmith
46
Is your organization ready for the software security challenges of 2025? As over 90% of software deployed is #opensource, it’s critical for platform and security teams to have the right policy management tools in place to safeguard the software supply chain—without impeding developer productivity. Here’s one of the highlights of our conversation. Register now to see it in full: shorturl.at/veUDj
82
With 90% of software today being #opensource, platform teams need to rethink how they mitigate risks while maintaining developer speed and agility. Watch as we explore how policy management can help you secure your software supply chain, reduce risks, and still empower your developers to move quickly. Watch the full session here: shorturl.at/Vns6X
102
We are ready to rock ⛰️ #kubecon in SLC! The weather might be cold outside, but we’ve got hats, scarfs, mugs, Lego, & cloud-native artifact management to keep you warm. Stop by & see us in the “Frozen Lakes Zone” of the sponsor showcase starting TODAY! #kubeconNA ❄️🌨️ #devops
1
131
📊Gain complete insights into your software supply chain artifacts with Cloudsmith’s detailed analytics. See consumption patterns, improve your security posture, and get more from every artifact.
1
90
In just a few days, Cloudsmith is unveiling a new web app that marks a major milestone in our commitment to modern artifact management. Get ready for advanced observability features that put you in control. Let’s take artifact management to the next level, shall we? 🚀
2
101