January 2024 Summaries
4 posts from Cloudsmith
Filter
Month:
Year:
Post Summaries
Back to Blog
Cloudsmith Navigator is a tool designed to help software engineering teams select high-quality open-source packages early in their development lifecycle. It analyzes data from 40,000 popular packages across NPM, PyPi, RubyGems, and Maven, assigning each one a unique quality score based on security standards, maintenance metrics, and documentation. The tool offers a simple heuristic to determine package quality and provides detailed information to cut through noise for engineering teams. Navigator's quality metric considers three essential factors: Package Quality, Maintenance, and Documentation. It also analyzes package dependencies to understand the trade-offs involved in consuming an OSS package. With its general availability, Cloudsmith Navigator aims to provide a quick assessment of package quality, making it easier for software engineering teams to find the right packages for their projects.
Jan 31, 2024
644 words in the original blog post.
Cloudsmith is a critical component of modern DevOps practices, providing observability tools for predicting, preventing, and addressing issues in distributed software systems. By aggregating logs from build tooling and visualizing the state of the entire system, Cloudsmith helps teams improve security, compliance, and operational efficiency. The quality of these logs is essential, as they provide granular visibility into the lifecycle of artifacts, user interactions, and system behavior. Cloudsmith offers various types of logs, including audit logs for cybersecurity and compliance, client logs to analyze package downloads, and package logs to understand resource utilization trends. These logs can be easily extracted and integrated with observability tools such as Datadog, Elasticsearch, Splunk, and Amazon Athena, providing actionable insights into the software supply chain.
Jan 26, 2024
940 words in the original blog post.
Cloudsmith aims to simplify software development by making artifact management more efficient and automating tasks, allowing teams to migrate from legacy tools like JFrog Artifactory or Sonatype Nexus to SaaS-based solutions. To achieve this, Cloudsmith has established a Customer Engineering team, which will develop migration and integration tools, including a Migration Toolkit that provides repository structure mappings, data migration, and ETL-style transfer of artifacts from legacy systems. The toolkit is now available for registration, allowing interested parties to try it out and contribute to its development through open-source contributions.
Jan 19, 2024
281 words in the original blog post.
Cloudsmith is an artifact management platform designed to put users in control of their intellectual property, providing a flexible and powerful permissions system that integrates with identity providers to manage authentication, team membership, and user lifecycle. The platform aims to be the go-to choice for enterprise customers, and it is expanding its capabilities by integrating with the System for Cross-domain Identity Management (SCIM) protocol. SCIM is an open standard designed to manage user identity information across multiple systems and applications, allowing for seamless access and up-to-date profiles and permissions. By integrating Cloudsmith with an identity provider via SCIM, users can automate provisioning and de-provisioning in the platform, leveraging their single point of control for managing user access. The company is offering early access to these capabilities to enterprises, inviting them to participate in shaping the final release through feedback.
Jan 16, 2024
406 words in the original blog post.