Home / Companies / Cloudsmith / Blog / March 2025

March 2025 Summaries

2 posts from Cloudsmith

Filter
Month: Year:
Post Summaries Back to Blog
The importance of software artifact integrity is highlighted as breaches can have severe consequences, including data breaches and system takeovers. Cryptographic signing is a highly effective defense against artifact poisoning, which verifies the authenticity and integrity of artifacts by using digital signatures unique to each software developer's private key. Two approaches are discussed: native signing, which integrates well with artifact workflows and ensures automatic verification, and non-native (third-party) signing, which requires additional manual steps for verification. Native signing plays a role in maintaining compliance with industry regulations by ensuring that software artifacts are verifiable, traceable, and tamper-proof. Cloudsmith supports non-native signing for all package formats, including Swift, NuGet, and Docker, and offers native signing support for these formats to improve workflows and reach compliance. Automated signing for Docker images uses Sigstore's Cosign, while native signing of NuGet packages uses an X.509 certificate, and Swift packages use ECDSA private key in combination with an X.509 certificate.
Mar 28, 2025 996 words in the original blog post.
Cloudsmith has officially become a Series B company after securing a $23 million fundraising round led by TCV, with participation from Insight Partners and existing investors. The company's CEO joined in 2023 with the goal of disrupting the software supply chain market dominated by JFrog and Sonatype. Over the past year, Cloudsmith has seen significant growth, including over 100% pipeline closure at the start of each quarter, a fivefold increase in average deal size, and numerous Fortune 500 and Global 2000 companies adopting its platform. The company is now poised to deliver on its promises to customers and investors, with plans to expand support for various formats, scale up the platform, and improve onboarding services, customer success, engineering, and global footprint. Cloudsmith aims to become a trusted partner in building software and implementing software usage policies, and thanks its customers, investors, and employees for their support as it moves forward.
Mar 03, 2025 477 words in the original blog post.