Cloudsmith Extends Policies and Controls to Secure Application Binaries
Cloudsmith this week revealed it has expanded the policy management and continuous risk detection capabilities it makes available within its software artifact management platform to now include policy templates, cooldown policies, and expanded evaluation triggers. Alison Sickelka, vice president of product for Cloudsmith, said these additions to the platform will make it simpler to prevent […]
Cloudsmith has recently expanded its software artifact management platform to enhance policy management and continuous risk detection. The company's vice president of product, Alison Sickelka, highlighted these additions as they aim to prevent malicious packages from being included in the production environment binaries.
The new features include policy templates written in Rego programming language, which provide consistent baseline controls across DevOps workflows. Additionally, DevOps teams can now implement cooldown policies that prevent recently available software packages from being indexed, ensuring only validated versions reach application developers.
Furthermore, expanded evaluation triggers now factor in when a policy was created or updated, alongside threat intelligence feeds, to generate alerts. This ensures policies are kept up-to-date with evolving application development environments.
Cloudsmith's strategy shifts focus from securing software supply chains primarily through source code to applying policies to the binaries that adversaries target. This approach aims to prevent malicious packages from being incorporated into binaries, as exemplified by an incident involving the Axios Node Package Manager.
Sickelka emphasized that traditional approaches to securing software supply chains, based on vulnerability severity ranking, are becoming outdated. As AI era threats to software supply chains grow, there's increased emphasis on preventing security incidents before they occur, by ensuring malicious packages and known vulnerabilities don't reach production environments.
CISOs are increasingly willing to fund tools and platforms for supply chain security, recognizing the need to reduce downstream incidents. However, in the short term, significant turmoil may arise as cybercriminals exploit AI to take advantage of known software supply chain weaknesses. The challenge lies in implementing rigorous policies and controls that won't hinder the secure, rapid development and deployment of modern software.
Written by urgent.news from DevOps.com's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.