Home / Companies / Cloudsmith / Blog / November 2024

November 2024 Summaries

6 posts from Cloudsmith

Filter
Month: Year:
Post Summaries Back to Blog
As software complexity increases, observability becomes crucial for understanding and managing the entire software supply chain. Observability goes beyond data collection to provide insights that help teams troubleshoot, enhance complex systems, and maintain resilience and reliability. Limited observability can lead to longer downtime, unexpected costs, missed security risks, and compromised system reliability and customer trust. Cloudsmith has launched an advanced observability suite offering unparalleled insights into the software supply chain, including detailed usage analytics, security and compliance insights, and monitoring alerts. This new suite comes with a fully redesigned user experience tailored for large-scale enterprise operations, empowering organizations to navigate challenges confidently, drive smarter decision-making, and ensure their software supply chain remains both agile and secure.
Nov 13, 2024 533 words in the original blog post.
Cloudsmith's container registry now fully complies with the Open Container Initiative (OCI) distribution specification, allowing customers to store, secure, and distribute images and artifacts more efficiently. This update offers robust support for OCI storage protocol and API format, including early access for OCI images and artifacts, as well as a Referrers API for querying linked artifacts. Key benefits of Cloudsmith's OCI-compliant registry include interoperability, standardization, and future-proofing.
Nov 13, 2024 331 words in the original blog post.
Cloudsmith has introduced the Enterprise Policy Manager, a powerful policy engine designed to enhance security in modern software supply chains. The platform leverages Open Policy Agent (OPA) and Cloudsmith's search capabilities to enable organizations to define, enforce, and monitor policies across their artifact lifecycle. Key features include custom policy creation, pre-built policy templates, enhanced package data, and policy as code automation. By addressing supply chain security challenges such as compliance breaches, unmanaged access, and limited customization, Cloudsmith's Enterprise Policy Manager aims to provide a more resilient and secure software ecosystem for organizations across various sectors.
Nov 13, 2024 560 words in the original blog post.
Cloudsmith, a leader in cloud-native artifact management, has introduced Broadcasts to help organizations manage, brand, and personalize their software delivery. Broadcasts offers features such as intuitive setup, custom domain and branding, advanced usage analytics, developer-native experience, and global, lightning-fast distribution. It addresses key challenges in software distribution by providing tools for control, branding, and analysis. With Broadcasts, organizations can deliver a professional experience that fosters deeper relationships with their customers and gain insights into usage trends.
Nov 13, 2024 491 words in the original blog post.
KubeCon, a cloud-native technology conference, is set to take place in Salt Lake City next week. The event will bring together experts and enthusiasts from the industry for talks, workshops, networking opportunities, and an exhibition of the latest tools and solutions. Attendees are encouraged to plan their schedule ahead of time, engage in networking with fellow professionals, explore the Sponsor Showcase, visit the Cloudsmith booth for insights on artifact management and build workflows, and attend the exclusive AprèsKube afterparty. Tips for first-time attendees include wearing comfortable shoes, staying hydrated, and bringing a portable charger.
Nov 08, 2024 836 words in the original blog post.
OpenID Connect (OIDC) offers ephemeral tokens, reducing the risk of long-lived credentials being exposed. This guide explains how to configure GitHub Dependabot to authenticate with Cloudsmith using OIDC. The process involves creating a service account in Cloudsmith, configuring OIDC authentication for GitHub Actions in Cloudsmith, setting up access controls in Cloudsmith, adding a Fine-Grained Personal Access Token (PAT) in GitHub for Dependabot, creating DEP_CLOUDSMITH_API_KEY secret for Dependabot, configuring the dependabot.yml file, and setting up a GitHub Action workflow to overwrite the Dependabot API key with an ephemeral OIDC token. This setup enhances security by using short-lived Cloudsmith OIDC tokens and regularly updating the DEP_CLOUDSMITH_API_KEY secret.
Nov 05, 2024 928 words in the original blog post.