Catch new vulnerabilities in your packages and images with recurring security scans

Feb 10 2025

Ensuring your packages and container images remain secure over time can be challenging, especially as new vulnerabilities surface daily and can emerge long after a package is first introduced. With Cloudsmith, you can now set up recurring security scans of your packages and images to check for new vulnerabilities and use that updated information in Cloudsmith’s policy manager to notify users or quarantine the package.

Security Scanning with Cloudsmith

  • On Upload: We automatically scan supported package types for vulnerabilities as soon as they’re uploaded to a Cloudsmith repository from an external source - say, a public registry - or an internal source.
  • Ad Hoc Scans: You can trigger subsequent scans manually via the Web UI or via the Cloudsmith API.
  • New: Recurring Security Scans: This feature is in Early Access and allows you to set up security scans to run on a recurring basis.

See Security Scanning for more details on how Cloudsmith security scanning works.

Key Benefits of Recurring Security Scans

  • Proactive threat detection: Quickly identify and respond to newly discovered vulnerabilities.
  • Reduced operational overhead: Automate your security scanning instead of relying on manual triggers.

Security Scanning is available for Ultra plan customers. To set up recurring security scans for your workspace, contact us to be added to Early Access.

Keep up to date with our monthly product bulletin

By submitting this form, you agree to our privacy policy