Ensuring your packages and container images remain secure over time can be challenging, especially as new vulnerabilities surface daily and can emerge long after a package is first introduced. With Cloudsmith, you can now set up recurring security scans of your packages and images to check for new vulnerabilities and use that updated information in Cloudsmith’s policy manager to notify users or quarantine the package.
Security Scanning with Cloudsmith
- On Upload: We automatically scan supported package types for vulnerabilities as soon as they’re uploaded to a Cloudsmith repository from an external source - say, a public registry - or an internal source.
- Ad Hoc Scans: You can trigger subsequent scans manually via the Web UI or via the Cloudsmith API.
- New: Recurring Security Scans: This feature is in Early Access and allows you to set up security scans to run on a recurring basis.
See Security Scanning for more details on how Cloudsmith security scanning works.
Key Benefits of Recurring Security Scans
- Proactive threat detection: Quickly identify and respond to newly discovered vulnerabilities.
- Reduced operational overhead: Automate your security scanning instead of relying on manual triggers.
Security Scanning is available for Ultra plan customers. To set up recurring security scans for your workspace, contact us to be added to Early Access.