Cloudsmith Brings Threat Intelligence to Software Artifacts to Strengthen Supply Chain Security
Cloudsmith has unveiled threat intelligence enrichment for software packages at KubeCon + CloudNativeCon Europe, enabling DevSecOps teams to automatically assess risk, block unsafe dependencies, and enforce compliance policies across their software supply chains.

Cloudsmith software artifact management platform with threat intelligence and DevSecOps policy enforcement
Cloudsmith has unveiled new threat intelligence capabilities for its managed software artifact platform at KubeCon + CloudNativeCon Europe 2026 in Amsterdam, giving DevSecOps teams the ability to automatically assess risk tied to the packages their developers download.
Nigel Douglas, head of developer relations at Cloudsmith, described the update as a significant extension to the company's managed service for software artifact management. The new capability allows organisations to attach known malware and vulnerability data — sourced from initiatives such as the Open Source Security Foundation (OpenSSF) — directly to software packages at the point of ingestion.
Automating Risk at the Dependency Level
Beyond threat enrichment, DevSecOps teams can now automatically evaluate a software bill of materials (SBOM) to identify and block unsafe transitive dependencies or non-compliant licences. The combined capability is designed to prevent developers from inadvertently downloading packages that have been compromised in a cyberattack or that contain vulnerabilities with a known high probability of exploitation.
The scale of the problem is significant. A Cloudsmith survey found that 44% of respondents work for organisations that have confirmed a security incident caused by a third-party dependency, with a further 39% reporting near misses.
Policy Enforcement Powered by Open Standards
The new enforcement layer is built on Open Policy Agent (OPA), an open source policy engine managed under the Cloud Native Computing Foundation (CNCF). Through OPA, DevSecOps teams can automatically quarantine newly published packages until they have been vetted, preventing them from reaching developer machines or production builds before review is complete.
Teams can also block packages that score highly on the Exploit Prediction Scoring System (EPSS) — a data-driven, machine-learning model that estimates the probability of a vulnerability being exploited in the wild within the next 30 days. When access to a package is restricted, developers receive customised remediation or exception request instructions directly in their command line interface (CLI), keeping workflows moving without bypassing controls.
Supply Chain Attacks Drive Urgency
The release comes in the wake of a sustained wave of software supply chain attacks that have pushed organisations to revisit their DevSecOps practices. The risk is expected to intensify as more organisations adopt AI coding agents to accelerate development, potentially increasing the volume of unvetted code being pulled from repositories such as GitHub.
Regulatory pressure is also mounting. EU mandates including the Cyber Resilience Act (CRA) and the Digital Operational Resilience Act (DORA) are making the adoption of robust DevSecOps practices a legal requirement for organisations operating in the European market, adding further urgency to supply chain security investment.
The Policy Paradox
The broader challenge facing DevSecOps teams is not just technical — it is organisational. Enforcing stricter policies inevitably creates friction with application developers who cite policy overhead as a factor in missed delivery timelines. What has shifted, however, is the level of awareness. There is now far broader recognition of the risk organisations face when policies are absent or ignored, which gives security teams a stronger basis for making the case that enforcement is non-negotiable.
As AI-generated code continues to grow exponentially, the ability to automate policy enforcement at the artifact level — rather than relying on manual review — may be the only practical way to keep pace. Cloudsmith's position is that the artifact repository itself is the right control point: by embedding intelligence and policy enforcement directly into the platform where packages enter the software supply chain, risk can be addressed before it ever reaches a developer's environment.
Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA RegionOmar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.