February 2024 Summaries
4 posts from Cloudsmith
Filter
Month:
Year:
Post Summaries
Back to Blog
Cloudsmith, as a SaaS artifact management platform, aims to provide an enterprise-scale multi-tenant solution that can serve large software development teams, unlike traditional "me-too" artifact managers that are more suited for small teams. The company focuses on integrating with innovative DevOps tools and vendors, rather than competing against them, to deliver a truly great artifact management platform built to work at web scale. Cloudsmith is well-positioned to address the growing need for artifact management as the use of open-source software increases, the threat environment in popular OSS registries grows, and containerization becomes more prevalent, with its developer-native software distribution capabilities and commitment to doing one thing incredibly well.
Feb 23, 2024
629 words in the original blog post.
A new artifact management platform is crucial for streamlining software production and improving the work-life balance of developers. A modern tool can store, manage, and secure all package formats, introducing consistent dependency management, increasing knowledge sharing, and simplifying toolchain integration. The importance of dependency management cannot be overstated, as external dependencies bring security and stability risks. A cloud-native solution offers higher reliability, faster software delivery, improved efficiency, and cost savings by leveraging today's cloud capabilities and future marvels. Fully managed solutions eliminate the need for self-managed package management, freeing up resources for strategic initiatives and providing lower total costs of ownership.
Feb 15, 2024
1,823 words in the original blog post.
Cloudsmith introduces support for private Hex package repositories, a significant milestone in supply chain security and package management for Erlang and Elixir teams. With Cloudsmith, developers can manage, develop, and distribute their own private Hex registry using familiar tooling, ensuring seamless integration into existing workflows. The platform provides global distribution with 410 points of presence worldwide, built-in security scanning for malware and CVEs, transparent pricing, and quality Engineer-led support. This marks a major development in the Hex ecosystem, enabling developers to host and distribute packages internally or externally securely and flexibly.
Feb 14, 2024
600 words in the original blog post.
Software supply chain security is critical to protect against digital threats, as recent attacks on organizations like Okta and JetBrains demonstrate. The financial impact of supply chain attacks is rising, with predicted costs reaching $138 billion by 2031. To mitigate risk, a thorough security audit is essential, involving mapping the entire software supply chain, assessing vulnerabilities, reducing and removing risks, and continuously monitoring for new threats. Cloudsmith provides a fully-managed platform to streamline this process, ensuring authenticity, origin, and security of artifacts, as well as automating surveillance and response to vulnerabilities. By maintaining a robust defence against evolving digital risks, organizations can safeguard their digital ecosystem.
Feb 09, 2024
1,002 words in the original blog post.