Log inSign up
Cloudsmith
1,346 posts
Cloudsmith profile banner
@cloudsmith

Cloudsmith

@cloudsmith
Ship trusted software, fast. Cloud-native artifact management for the AI era — security enforced before packages reach your build environment.
The Cloud (obviously)
cloudsmith.com
Joined October 2015
613
Following
1,106
Followers
RepliesRepliesRepostsRepostsMediaMedia

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
  • @cloudsmith
    Cloudsmith
    @cloudsmith
    Aug 24
    Axios. LiteLLM. Shai Hulud. All hit the same way. Here's how a control point at ingestion, policy-as-code, and continuous risk detection build a supply chain you can actually trust in 2026. Full breakdown ⬇️
    Image
    Trust your software supply chain from ingestion to production
    From cloudsmith.com
  • @cloudsmith
    Cloudsmith
    @cloudsmith
    Aug 19
    🚀 Now live: policy management and continuous risk detection, open to everyone on Cloudsmith. Write the rules once and enforce them at the repo level, across every pipeline and every developer and agent pulling code in. See it in action.
    cloudsmith.com
    Software Supply Chain Security with Cloudsmith
    Protect your software supply chain with automated policy enforcement, malicious package detection, continuous risk detection, and stronger dependency controls.
  • @cloudsmith
    Cloudsmith
    @cloudsmith
    Aug 12
    Most security tools find problems after they're already in your environment. A dependency firewall catches them at the door before a bad package ever reaches a build. Here's what that actually looks like.
    Image
    How to use Cloudsmith as a dependency firewall
    From cloudsmith.com
  • @cloudsmith
    Cloudsmith
    @cloudsmith
    Aug 10
    Kubernetes 1.37 drops August 26. Nigel from our team broke down everything worth knowing: new features, deprecations, and the DRA/AI stuff before it even ships.
    Image
    Kubernetes 1.37 – What you need to know
    From cloudsmith.com
  • @cloudsmith
    Cloudsmith
    @cloudsmith
    Aug 5
    Malicious versions of #keyv and #cacheable are spreading through npm on their own; the payload runs on install, steals credentials, then uses them to infect more packages. 444 packages have been hit so far.
    Image
    Keyv and Cacheable npm Packages Compromised in Active Supply-Chain Attack
    From cloudsmith.com
Advertisement
Advertisement