Documentation

Supply chain security

Modern software delivery pipelines face a rising wave of sophisticated supply chain attacks. Artifact management has to go beyond traditional storage to keep up. According to the Cloudsmith 2026 Artifact Management Report, the compromise of upstream open-source ecosystems is one of the top concerns for teams today when it comes to risk in the software supply chain.

Cloudsmith is built to meet that challenge. The platform helps you operationalize your risk and security data, turning detection signals into consistent policies that automatically protect your organization from known and emerging threats.

In this section, you can learn about:

  • Package signing: Cryptographically sign the packages you publish so downstream consumers can verify their authenticity and integrity before use.
  • SBOMs: Generate Software Bills of Materials for the artifacts in your workspace to trace exactly what each package contains.
  • Risk detection: Automatic scanning that surfaces malware, malicious packages, vulnerabilities, and license exposure in artifacts entering your workspace.
  • Governance and controls: Policy-driven enforcement that blocks, quarantines, or tags packages based on detection results, with continuous re-evaluation as new threat data arrives.