Improved security with EPSS in Enterprise Policy Management

Apr 1 2025

Cloudsmith’s Enterprise Policy Management (EPM) now supports the Exploit Prediction Scoring System (EPSS), a data-driven metric designed to estimate the probability of a software vulnerability being exploited in the wild.

Using Enterprise Policy Management, you can now use a package’s EPSS score to inform your package workflows, including those around package quarantine and promotion.

Why EPSS Matters

  • Risk Assessment: Use EPSS scores to prioritize vulnerabilities most likely to be exploited, to strengthen your organization’s security posture and automate your response to vulnerabilities.
  • Enhanced Control: Leverage EPSS-based policies for more granular, data-informed decisions around vulnerability management.
  • Automated Responses: Remain protected in real time as Cloudsmith automatically re-checks and re-applies your policies when EPSS scores change.

Check out Enterprise Policy Management for more information, or contact us if you have any questions or feedback on this feature.

Keep up to date with our monthly product bulletin

By submitting this form, you agree to our privacy policy