Everything Cloudsmith shipped in Q3 2026
Blog post from Cloudsmith
Cloudsmith published 25 changelog updates in Q3 focused on expanding software supply-chain security, developer tooling, package-format support, and operational visibility. Policy management and continuous risk detection reached general availability, enabling Rego-based rules, automated package re-evaluation using OSV.dev threat intelligence, expanded cooldown policies across eight formats, policy-editor validation, and downloadable vulnerability findings. The platform added trusted upstream integrations for hardened container images and vendor-curated libraries, while Go upstreams now support any GOPROXY-compatible proxy. CLI releases introduced automatic OIDC and Docker credential discovery, standalone binaries without Python dependencies, and support for Nix, Cargo, pnpm, repository administration, Debian source packages, and improved headless authentication. New package and client logs provide more detailed audit trails and download-resolution data, while Broadcasts analytics now show consumption, entitlement-token usage, and geographic delivery patterns. Other additions include Nix binary-cache and upstream support, faster Python dependency resolution through PEP 658 metadata, GitHub secret-scanning detection for exposed API keys, more granular read-only workspace permissions, generally available SCIM group provisioning, and a dedicated bug bounty platform.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Platform Engineering | 3 | No monthly metrics for this publish month. | |||
| Secrets Management | 2 | No monthly metrics for this publish month. | |||
| Developer Experience | 1 | No monthly metrics for this publish month. | |||
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.