Real-time risk detection replaces stale package scans
Blog post from Cloudsmith
Traditional vulnerability scans provide only point-in-time results that can quickly become outdated as new CVEs emerge, with an average of 234 reported daily, while frequent full rescans are resource-intensive due to large repository sizes, accumulated advisories, and the complexity of container images. Continuous risk detection instead uses vulnerability-centric matching of package URLs in threat advisories against persistent package metadata, enabling near-real-time identification of newly disclosed vulnerabilities without repeating full package analyses. Running at the artifact registry layer can provide visibility across packages, dependencies, and builds throughout the software lifecycle, while Cloudsmith’s implementation uses OSV.dev threat data and can trigger security and policy-as-code controls when matches are found. Because both scanning and matching depend on known vulnerabilities, cooldown policies that delay use of newly released packages can supplement detection by allowing time for emerging threats, including potential zero-days, to be identified.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Real-time | 4 | 649 | 155 | 80 | -85% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.