Home / Companies / Cloudsmith / Blog / May 2021

May 2021 Summaries

5 posts from Cloudsmith

Filter
Month: Year:
Post Summaries Back to Blog
The US and UK governments are implementing regulations to secure the software supply chain in response to recent high-profile attacks, such as SolarWinds and CodeCov. The new regulations aim to increase cybersecurity defenses across the software industry by requiring companies to provide a Software Bill of Materials (SBOM), which is a record of all components and dependencies used in building software. This will enable end-users to perform vulnerability or license analysis, evaluating risk in products. The regulations also focus on secure software development environments, automation tools, and the use of trusted source code supply chains. Companies will need to update their CI/CD pipelines to increase visibility and automate security practices, and may be required to provide proof of secure software development and attest to conformity with secure practices.
May 28, 2021 646 words in the original blog post.
Cloudsmith can be easily integrated with Semaphore CI workflows to automate package management and deployment. By installing the Cloudsmith CLI and adding a secret containing the API key, users can push packages to a private Cloudsmith repository from their workflow. The integration involves creating a pipeline in Semaphore that includes two blocks: "Build Package" and "Push Package". The "Build Package" block builds and packages the source code, while the "Push Package" block pushes the package to the Cloudsmith repository using the API key. With this setup, users can automate their packaging process and take advantage of Continuous Packaging, a key component of modern DevOps workflows.
May 19, 2021 1,418 words in the original blog post.
A short demo of how you can set up a Semaphore CI workflow to push a package to a private Cloudsmith repository.` This is a demonstration of setting up a Continuous Integration workflow using Semaphore CI, which automates the process of building and deploying a package to a private Cloudsmith repository. The goal is to efficiently manage the release process for a software project. Semaphore CI provides a platform for defining workflows that can be easily executed on multiple platforms, including Linux and Windows environments. By integrating with Cloudsmith, users can automate the deployment of their package to the repository, streamlining the development-to-production pipeline.
May 18, 2021 52 words in the original blog post.
Today, almost every service now is offered in a “Cloud” variant, but not all cloud services are created equal. The major difference between Cloud Hosted and Cloud-Native lies in their design and architecture. Many established software vendors have added Cloud editions to take advantage of the trend, but this often means paying a premium for the same software running on a virtual machine. In contrast, Cloudsmith is designed from the ground up as a Cloud-Native application that takes full advantage of cloud provider platforms' technology, offering features like fully distributed workloads and scaling for global performance. This approach allows it to harness the power and flexibility of the Cloud and Edge computing, making it a smart CDN for software.
May 17, 2021 386 words in the original blog post.
At Cloudsmith, their mission is to make it easy for users to get packages into their system and manage them. They recently collaborated with Atlassian's Bitbucket team to build a pipe that simplifies the process of turning source code into distributable packages and deploying to Cloudsmith in just a few lines of YAML. This pipe builds on top of Bitbucket's Pipelines functionality, allowing users to automate their build and deploy processes. The Cloudsmith pipe is included in Bitbucket's collection of officially maintained pipes and can be used by default for any user who wants to include it in their pipeline. To use the pipe, users need to package their code using a Bitbucket pipeline and then add configuration to publish the package to Cloudsmith. Once configured, the pipe can be run by pushing a new tag to Bitbucket, and the resulting package is published to Cloudsmith's repository. The process allows for easy deployment of packages from source code to Cloudsmith with minimal configuration.
May 17, 2021 713 words in the original blog post.