Ship trusted software, fast. Cloud-native artifact management for the AI era — security enforced before packages reach your build environment.

Joined October 2015
672 Photos and videos
Your artifact registry and your deployment tool shouldn't be strangers. Cloudsmith decides what's allowed. @OctopusDeploy controls how it ships. Governance baked in, not bolted on. cloudsmith.com/blog/from-tru…
33
Valid SLSA attestations. Legitimate OIDC tokens. 73 repos down. The Miasma worm shows why signed isn't the same as safe. cloudsmith.com/blog/miasma-w…
39
AI coding tools are pulling in dependencies faster than any senior engineer can review them. AI's speed, matched with automation, guardrails, and a strong artifact management layer, provides a secure development foundation. Here's how we think about it. ↓
1
22
Join @cloudsmith, @rootlyhq, Mend.io, @ClickHouseDB, and @Docker in NYC for an evening of cocktails, conversations, and connections. 📍 Diamante’s | 410 8th Ave, NYC 📅 Wed, June 17 | 5:30-8:30 PM 🍸 RSVP: luma.com/odgqf98e?utm_source…
1
57
24 Jun 2025
Are you at PlatformCon London? Join Spacelift and Cloudsmith TONIGHT at F1 Arcade London for an evening where competitive racing meets DevOps and platform engineering. Connect with peers, test your skills on full-spec racing simulators, and explore how to optimize your DevOps for both speed and control. 📅 Date: Wednesday, 25 June ⏰ Time: 7:00 PM - 10:00 PM BST 📍 Location: F1 Arcade London - 1 New Change, London EC4M 9AF, United Kingdom 🔥 Space is limited—reserve your spot now! 🔥 👉 events.spacelift.io/iac-gran… See you there!
1
4
1,049
23 Jun 2025
Is your Helm a risk? 🔍 If your business or open-source project relies on Helm charts, join Nigel Douglas, Head of Developer Relations at Cloudsmith, in a hands-on, virtual workshop during PlatformCon 2025: "What Supply Chain Risks Are Hidden in Your Helm Charts?" Join this hands-on workshop to explore real-world Helm vulnerabilities and learn practical strategies to automate and strengthen your Kubernetes security posture. Reserve your spot 👉 platformcon.com/sessions/wha… 🗓️ Friday, 27 June at 4:00 PM BST / 11:00 AM EST 📍 Virtual #PlatformEngineering #PlatformCon2025 #KubernetesSecurity #Helm
1
4
820
23 Jun 2025
We're thrilled to be part of PlatformCon 2025, the world’s largest platform engineering conference! This year, we're bringing two high-impact virtual talks to the stage 💥 More Than Code: How Culture Defines Platform Success Explore how team culture, not just tooling, shapes the true success of platform engineering 🌟 Artifact Management Unleashed: Powering Your Packages at Lightning Speed Discover how to optimize package delivery and streamline your artifact workflows for peak performance 🚀 This week only, PlatformCon attendees can enter to win a $250 gift card at the end of each talk! Watch now: cloudsmith.com/events/confer… #PlatformEngineering #PlatformCon25
3
400
19 Jun 2025
In April, Scattered Spider cracked M&S’s systems in a massive ransomware attack. It all started with the theft of an NTDS.dit file. See Nigel Douglas’s advice for practitioners securing their CI/CD pipelines against lateral movement: cloudsmith.com/blog/owasp-ci… Full guide: cloudsmith.com/campaigns/gui… #DevSecOps #OWASP #CI/CD
1
2
331
17 Jun 2025
🌍 Cloudsmith is proud to sponsor PlatformCon 2025 - the worlds biggest platform engineering event! Join us for a full week of all things platform engineering—including free virtual sessions packed with insights into cloud-native artifact management at scale 🚀 Here’s what we’re bringing to the table: 💡 23-27 June | 2 Virtual Talks • More Than Code: How Culture Defines Platform Success — Explore how platform strategy aligned with company goals enables empowered engineering teams. • Artifact Management Unleashed: Powering Your Packages at Lightning Speed — Discover how smart caching and optimized registry access can supercharge your package delivery. 🇬🇧 25 June | London Live Day - Booth 8 • Stop by Booth 8 to see why Cloudsmith is the world’s best cloud-native artifact management platform—fully managed, built for scale, and designed to secure and streamline everything in your software supply chain. • Get hands-on with the Cloudsmith platform, enter to win great prizes, and take home great swag! 🗓️ When: Wednesday, 25 June 📍 Where: Convene Sancroft, St. Paul's - London 🛠️ 27 June | Virtual Workshop • What Supply Chain Risks Are Hidden in Your Helm Charts? — A hands-on deep dive into vulnerabilities, attack scenarios, and best practices for securing Helm charts, ensuring supply chain security and compliance. 👉 Learn more & explore our sessions: cloudsmith.com/events/confer… #PlatformEngineering #PlatformCon25 #ArtifactManagement
2
241
16 Jun 2025
QA ≠ Admin Developer ≠ Release Manager Strong Pipeline-Based Access Controls (PBAC) rely on separating duties across the pipeline: cloudsmith.com/blog/owasp-ci… Download a full guide on OWASP’s CI/CD Top 10 risks: cloudsmith.com/campaigns/gui… #PBAC #OWASP #CI/CD
2
162
Cloudsmith retweeted
Happy to announce grlx is now being built and distributed with @GoReleaser ! In addition to our official alpine packages, we are now offering aur packages for archlinux as an official distribution channel. .deb and .rpm packages are coming soon on @cloudsmith
1
5
6
579
30 May 2025
Look familiar? If you’d like a refresher on best practices for tackling Poisoned Pipeline Execution, we’re running through OWASP’s CI/CD Top 10 risks with advice on how to deal with these types of unauthorised executions. Check out Part 4: cloudsmith.com/blog/owasp-ci… Download the free guide: cloudsmith.com/campaigns/gui…
1
146
29 May 2025
Is vibe coding more of a risk than a vibe? “Without security-aware tooling or policy enforcement, enterprises could end up unknowingly introducing vulnerabilities.” — said Nigel Douglas to The New Stack. Read more: thenewstack.io/vibing-danger…
123
27 May 2025
“We wanted a product that was easy to use and hard to misuse.” 🎥 Listen to our CTO Lee Skillen discuss the mindset behind building for critical use: simple, secure, and cloud-native from day zero.
2
106
19 May 2025
To help you combat the rise in seemingly harmless malicious packages, we’ve broken down some best practices in Part 3 of the Cloudsmith and OWASP CI/CD Top 10 series on Dependency Chain Abuse. Read the blog: cloudsmith.com/blog/owasp-ci… Download the free guide: cloudsmith.com/campaigns/gui…
2
109
15 May 2025
If you’re looking to reduce exposure from over-permissive roles, stale access, or shared credentials, reviewing identity and access management best practice could make all the difference. In Part 2 of our OWASP CI/CD Top 10 series, we’re looking at CICD-SEC-2: Inadequate Identity and Access Controls. Read the blog: cloudsmith.com/blog/owasp-ci… Download the free guide: cloudsmith.com/campaigns/gui…
1
104
14 May 2025
As software supply chain threats grow, securing your CI/CD pipeline is critical. Join Esteban Garcia (Principal Engineer, Cloudsmith), Liana Ertz (Product Manager, Cloudsmith), and Jason van Zyl (Senior Engineering Manager, Chainguard) for a 30-minute session covering: ➡️ Techniques for signing and verifying artifacts with open-source tools (SBOMs, provenance data) ➡️ Enforcing security policies to block unverified software from production ➡️ Managing and storing signed artifacts in CI/CD pipelines using Cloudsmith & Chainguard ➡️ Ensuring compliance with audit logs, tamper-proof metadata, and secure artifact lifecycle management 📅 June 3, 2PM EST — 30 minutes Live Q&A included | Recording sent to all registrants Register here ➡️   cloudsmith.com/webinars/unlo… #CICDSecurity #DevSecOps #Chainguard #Cloudsmith #OpenSourceSecurity #SoftwareDelivery #DevTools #Webinar #ArtifactSigning
108
2 May 2025
Use CodeQL to detect vulnerabilities? Until recently, there was a big one hiding in plain sight. Researcher John Stawinski discovered a vulnerability (now patched) in the GitHub Action used by CodeQL. Check out the full article from DevClass here: devclass.com/2025/04/02/the-… #SoftwareSupplyChain #DevSecOps #ArtifactManagement #GitHubActions
2
115