Home / Companies / Cloudsmith / Blog / September 2022

September 2022 Summaries

4 posts from Cloudsmith

Filter
Month: Year:
Post Summaries Back to Blog
The use of Software Bill of Materials (SBOMs) is becoming increasingly important for organizations as they seek to improve the security of their software supply chain, with 78% of companies expecting to produce or consume SBOMs by 2022.
Sep 29, 2022 117 words in the original blog post.
Cloudsmith, a hosted package management service, is extending its support for vulnerability scanning to include Docker, Ruby, Python, Composer, Maven, NuGet, Golang, Cargo, and npm. This feature automatically scans supported package types for Common Vulnerabilities and Exposures (CVEs) when packages are pushed or fetched from public repositories. Cloudsmith also offers symbiotic features such as webhooks, quarantining, and upstreaming to create workflows and drive actions. These features enable teams to integrate vulnerability scanning with other tools in their build pipelines, block downloads of vulnerable packages, and trigger rescans on demand. Additionally, Cloudsmith is working to integrate its security scanner with emerging standards like the Vulnerability-Exploitability eXchange (VEX) and Software Bill of Materials (SBOMs).
Sep 21, 2022 1,344 words in the original blog post.
The Cloudsmith Team is attending KubeCon CloudNativeCon North America in Detroit where they will be at their booth in the expo hall to speak with universal artifact management experts and offer swag. Cloudsmith is a cloud-native package management platform that offers support for 28+ formats, integrates with various tools, and provides secure software delivery. The team includes several key individuals who will be present at the event, including Paul McKeever, Dan McKinney, Justin Eaton, Erkan Erdogan, and Hillary Foster. Attendees can register for the event or book a demo with Cloudsmith experts in advance to take advantage of exclusive discounts and offers.
Sep 19, 2022 224 words in the original blog post.
The Open Source Security Foundation (OpenSSF) is a cross-industry forum working to improve security in open source software (OSS). To address the security problems with OSS, OpenSSF aims to support maintainers, improve security policies for public repositories, remove or tag malicious projects, and adopt tooling and security practices. Cloudsmith, a company providing tools for securing software supply chains, has integrated with Sigstore's Cosign and is aligning with OpenSSF initiatives to help customers secure their OSS dependencies and supply chains. The Alpha-Omega Project, funded by Microsoft and Google, aims to improve software supply chain security through direct engagement of software security experts and automated security testing. Other projects include the Software Bill of Materials (SBOM) tooling, Scorecards for automated security checks, SLSA for hardening software supply chains, and the Great MFA Distribution Project providing hardware multi-factor authentication tokens to OSS developers.
Sep 16, 2022 2,628 words in the original blog post.