Home / Companies / Cloudsmith / Blog / December 2023

December 2023 Summaries

4 posts from Cloudsmith

Filter
Month: Year:
Post Summaries Back to Blog
As the CEO of Cloudsmith, I'm learning about how customers use us to protect their software supply chains. Most software organizations struggle with tracking and controlling what's coming into and going out of their builds, as public indexes like npm or Maven Central may introduce known vulnerabilities or outdated code. We're dedicated to helping DevOps teams manage this end-to-end flow with our flagship product Cloudsmith. In 2023, we made significant strides in providing a comprehensive solution, adding support for Helm, Python, and Terraform, improving our Container Registry, and enhancing security controls. This year saw a 48% increase in overall package download volumes, and we're committed to delivering more features and support to take control of software supply chains. We invite customers to provide feedback or try out Cloudsmith for personal or open-source projects, taking advantage of free storage and bandwidth limits.
Dec 21, 2023 510 words in the original blog post.
The EU's Cyber Resilience Act aims to improve digital security in the European Union by introducing mandatory cyber security requirements for hardware and software products, a CE marking to signify compliance, and enhanced transparency for consumers. The act applies to most digital products sold in the EU and requires manufacturers to provide security updates, report vulnerabilities, and minimize weaknesses throughout the product lifecycle. While the open-source community has raised concerns about the Act's impact on vulnerability reporting burdens, its final version extends exemptions to non-profit OSS organizations, addressing some of these criticisms.
Dec 08, 2023 386 words in the original blog post.
The EU Cyber Resilience Act will require software and hardware developers to comply with its regulations starting in 2024, unless they fall within one of the four product exemption categories. Failure to comply may result in penalties. Using a modern package management system as part of a CI/CD process can help meet these requirements, particularly by minimizing vulnerabilities and being transparent about cybersecurity aspects. Legacy systems often struggle with visibility, manual vulnerability scanning, tracking dependencies, and robust logging and reporting, making compliance more challenging. In contrast, cloud-native artifact management systems like Cloudsmith provide features such as secure authentication, access controls, audit logs, policy management, vulnerability scanning, and upstream proxying of public repositories to streamline CRA compliance efforts and support evolving requirements.
Dec 08, 2023 351 words in the original blog post.
The European Union has reached an agreement on the EU Cyber Resilience Act (CRA), a regulation akin to GDPR for cybersecurity, aiming to protect consumers from insecure digital products. The CRA introduces mandatory cybersecurity measures such as vulnerability disclosure, Software Bill of Materials, and security updates throughout the product life cycle, covering a wide range of digital products including operating systems, baby monitors, and firewalls. Companies have 36 months to comply with penalties of up to €15 million or 2.5% of global turnover for non-compliance. The regulation also includes exemptions for open-source software developed without commercial intent and products already regulated by specific laws. The CRA is set to be adopted in 2024, marking a significant stride in strengthening digital security across the EU.
Dec 08, 2023 959 words in the original blog post.