September 2026 Summaries
1 posts from Cloudsmith
Filter
Month:
Year:
Post Summaries
Back to Blog
Cloudsmith describes a registry-layer security control plane that uses Open Policy Agent and Rego-based policies to assess software artifacts against risk signals such as CVE severity, EPSS exploit likelihood, licenses, package age, metadata, and Docker SBOM contents. Its configurable cooldown policies delay access to newly published packages to reduce exposure to potential zero-day supply-chain attacks while threat information emerges. Continuous risk detection updates package assessments as OSV.dev receives new vulnerability, exploitability, or malicious-package data, allowing policies to automatically take actions such as quarantining affected artifacts. Each evaluation generates queryable decision logs documenting the inputs, actions, and rationale, supporting incident response and compliance evidence for standards including SOC 2, DORA, FedRAMP, PCI-DSS, and the CRA. Together, these capabilities are presented as a continuous alternative to point-in-time scans and CI pipeline gates for managing open-source dependency risk.
Sep 22, 2026
941 words in the original blog post.