Home / Companies / Cloudsmith / Blog / December 2021

December 2021 Summaries

8 posts from Cloudsmith

Filter
Month: Year:
Post Summaries Back to Blog
The story revolves around an infamous hacker, th3_GR1NCH, who attempts to breach Cloudsmith's API with malicious intent. However, the company's security measures, including password protections, timeouts, and a web app firewall, successfully rebuff his attempts. Despite initial success in other service companies, th3_GR1NCH finds it challenging to gain access to Cloudsmith due to its robust security, leading him to contact support without making any progress. Ultimately, the team at Cloudsmith discovers a potential vulnerability and adds an additional check to prevent similar incidents in the future.
Dec 21, 2021 380 words in the original blog post.
We're proud to announce that Cloudsmith has become ISO27001:2013 certified, a gold standard for managing information security, after nearly a year of effort in our "Year of Security" initiative, demonstrating our commitment to ensuring the integrity and privacy of customer data as a fully managed service in software supply chains.
Dec 20, 2021 283 words in the original blog post.
The log4j library is a widely used logging framework for Java applications, but it has been found to be vulnerable to a critical severity Remote Code Execution (RCE) exploit, known as Log4Shell, which can cause arbitrary code execution on servers. The vulnerability was disclosed in December 2021 and has a high CVSS rating of 10, making it one of the most impactful exploits in the last decade. Cloudsmith is not impacted by this vulnerability, but developers and users of affected software should take it seriously due to its high impact and widespread use. To mitigate the issue, updated guidance and resources are available on the Cloudsmith website, including a detailed blog article that provides background, identification, and remediation advice for log4j/Log4Shell.
Dec 14, 2021 398 words in the original blog post.
This was an amazing year for Cloudsmith, with significant growth and milestones achieved, including adding 17 new team members to become a team of 27 across three countries. The company raised $15 million in Series A funding and expanded its customer base globally, thanks to the incredible work of its talented team. Cloudsmith has gained several notable partnerships and certifications, including ISO:27001, and is looking forward to continued growth in the new year, encouraging others to join the team by checking out their careers page.
Dec 13, 2021 283 words in the original blog post.
Join Cloudsmith’s Ciara Carey and Buildkite’s Mel Kaulfuss as they explore how to combine continuous packaging with integration and delivery for a true continuous software pipeline in the cloud, apply shift-left security principles across the whole value stream, and leverage Buildkite Test Analytics to identify and fix problems in test suites.
Dec 08, 2021 94 words in the original blog post.
To get started with Helm and Cloudsmith, you can push a Helm chart to a private Cloudsmith repository, which allows for secure and controlled package management. This demo shows how to install the chart on a Kubernetes cluster, providing a hands-on introduction to these tools. The process involves creating a private repository, adding the Helm chart, and then pulling and installing it on a Kubernetes cluster. By following this demo, you can gain practical experience with using Helm and Cloudsmith for managing packages in your Kubernetes environment.
Dec 06, 2021 72 words in the original blog post.
A Content Delivery Network (CDN) can efficiently deliver software packages globally by caching them at multiple locations worldwide, reducing latency and improving performance. However, traditional CDNs may not be optimal for package management due to the complexity of managing different package formats, client tooling, APIs, and communication protocols. The Package Delivery Network (PDN), a highly customized CDN, addresses this issue by being context-aware and allowing users to define caching rules, TTLs, and cache metadata differently for various packages. It also enables authentication at the edge, reducing round-trip times for authentication requests and improving performance. By leveraging the latest developments in CDN technology, the PDN provides a modern solution for secure package management, enabling faster and more reliable delivery of software artifacts.
Dec 03, 2021 1,186 words in the original blog post.
Join Ciara Carey, DevRel at Cloudsmith, and Nick Rycar from Buildkite, as they explore what it means to combine Cloudsmith’s continuous packaging with Buildkite’s integration & delivery to truly have a continuous software pipeline in the cloud.` This discussion aims to examine the combination of Cloudsmith's continuous packaging capabilities with Buildkite's integration and delivery services to achieve a fully continuous software pipeline in the cloud. The conversation will delve into the benefits and potential outcomes of this integrated approach, allowing participants to share their expertise and insights on how to effectively implement such a strategy.
Dec 01, 2021 82 words in the original blog post.