TL;DR — Key Takeaways
- Cloudsmith expanded its software supply chain governance capabilities with policy templates, cooldown policies and broader evaluation triggers.
- New cooldown policies can block recently published packages from being indexed until they have had time to be validated.
- Rego-based policy templates give DevOps teams a way to apply consistent baseline controls across software delivery workflows.
Cloudsmith this week revealed it has expanded the policy management and continuous risk detection capabilities it makes available within its software artifact management platform to now include policy templates, cooldown policies, and expanded evaluation triggers.
Alison Sickelka, vice president of product for Cloudsmith, said these additions to the platform will make it simpler to prevent malicious packages from inadvertently being incorporated into the binaries that DevOps teams deploy in production environments.
For example, policy templates written in the Rego programming language can now be used to provide a set of baseline controls that are consistently implemented across a DevOps workflow.
Additionally, DevOps teams can now implement a set of cooldown policies that prevent any recently made available software package from being indexed. That capability ensures that only versions of a validated package are exposed to application developers, noted Sickelka. That’s crucial because many of those packages have been created by maintainers of open source software projects that are targeted by adversaries that have no shortage of time, patience and financial resources.
Finally, the expanded evaluation triggers now consider when a policy was created or updated as part of the metrics used alongside threat intelligence feeds to generate an alert. That capability helps ensure that policies are updated as the application development environment continues to evolve, said Sickelka.

Rather than trying to secure software supply chains by focusing mainly on the source code used to create binaries, Cloudsmith is making a case for applying policies to the binaries that cybercriminals are actually targeting. That approach ensures that application developers are not incorporating malicious packages spread, for example, through a compromised instance of the Axios Node Package Manager that resulted in malicious code being added to an application after it had been deployed, noted Sickelka.
In general, the way software supply chains are secured now clearly needs to evolve, added Sickelka. The days when DevSecOps teams could prioritize their efforts based on the severity ranking of a vulnerability are over. As business and IT leaders in the artificial intelligence (AI) era become more aware of threats to software supply chains, there is a lot more focus on preventing security incidents from occurring in the first place by ensuring malicious packages and other known vulnerabilities that can now be easily exploited don’t find their way into production environments, said Sickelka.
In fact, in many cases CISOs are now willing to fund the acquisition of the tools and platforms needed to secure software supply chains in the hopes of reducing the number of downstream incidents they might later need to respond to in the event of a cyberattack, she added.
Hopefully, the increased focus on software supply chains will result in more secure applications being deployed. In the short term, however, it’s probable there will be a significant amount of turmoil as cybercriminals leverage AI to exploit increasingly well-known weaknesses in software supply chains. The challenge and the opportunity now is to reduce as many of those potential incidents as possible by applying more rigorous policies and controls that, if properly implemented, should not slow down the pace at which modern software can be securely built and deployed.
Frequently Asked Questions
What new capabilities did Cloudsmith add?
Cloudsmith added policy templates, cooldown policies and expanded evaluation triggers to its software artifact management platform.
What are cooldown policies?
Cooldown policies prevent newly published software packages from being immediately indexed or exposed to developers, giving teams time to validate them first.
How do Cloudsmith’s policy templates work?
The templates use the Rego programming language to provide reusable baseline controls that can be consistently applied across DevOps workflows.

