1. X
  2. Cloudsmith
Log inSign up
Cloudsmith
1,341 posts
Image
user avatar
Cloudsmith
@cloudsmith
Ship trusted software, fast. Cloud-native artifact management for the AI era — security enforced before packages reach your build environment.
The Cloud (obviously)
cloudsmith.com
Joined October 2015
612
Following
1,108
Followers
RepliesRepliesMediaMedia

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
  • user avatar
    Cloudsmith
    @cloudsmith
    Jul 14
    Attackers didn't need a fake package this time. They hijacked #AsyncAPI's own CI/CD pipeline and shipped the malware through the real one – 2.9 million weekly downloads before anyone caught it. Full attack breakdown:
    Image
    Inside the AsyncAPI npm supply chain attack
    From cloudsmith.com
    68
  • user avatar
    Cloudsmith
    @cloudsmith
    Jun 29
    Every container inherits its base image. If that image carries unpatched CVEs, your app does too, before you've written a line of code. Here's how to make @wiz_io WizOS hardened images the frictionless default across your org.
    Image
    Start secure, stay secure with WizOS and Cloudsmith
    From cloudsmith.com
    87
  • user avatar
    Cloudsmith
    @cloudsmith
    Jun 18
    Cloudsmith is now a @github secret scanning partner. If your API key ends up in a public repo, GitHub catches it and tells us. One more layer of control over your software supply chain 🛡️
    Image
    Secret scanning updates - June 2026 - GitHub Changelog
    From github.blog
    85
  • user avatar
    Cloudsmith
    @cloudsmith
    Jun 17
    The logic is rather simple: if you can compromise the framework itself, you have the ability to compromise highly sensitive infrastructure. Today, it's happened again - this time #Mastra was the target. Full attack breakdown:
    Image
    Inside the Mastra npm supply chain attack
    From cloudsmith.com
    67
  • user avatar
    Cloudsmith
    @cloudsmith
    Jun 16
    Automate now > explain to regulators later. 87 days until the CRA's 24-hour reporting rule kicks in. We broke down what engineering teams should be working towards for compliance.
    Image
    The EU Cyber Resilience Act: What Engineering Teams Need to Do to Be Compliant
    From cloudsmith.com
    58
  • See @cloudsmith's full profile

    Sign up
    Log in
Advertisement
Advertisement