Skip to content

Conversation

pabloopez
Copy link
Collaborator

No description provided.

Copy link

linear bot commented Jun 11, 2025

DOCS-145 Guide: how to set up your dependency firewall

write a KB article about how a customer should/could setup and configure a dependency firewall

useful explanation: https://docs.google.com/document/d/1qvPvH8krm0r8bWY2iMuRlGbvBFzH7itMfQ3mvjc_pa0/edit

  • what are the features that allow you to build the firewall
  • what are the (different) approaches you could use to implement the firewall & pros/cons
    • promotion workflow
    • strict dependency blocking

Purpose

Highlight key cloudsmith functionality. including; security scanning, deny policies, block-until-scanned, vulnerability policies

Format

  • explanation of what a dependency firewall is
  • why it's important to implement
  • step-by-step guide to configuring (2-3 pages max)

Steps

  1. Ensure your teams are only pulling from Cloudsmith - which means setting up your teams and pipelines to point at Cloudsmith
  2. Connect Cloudsmith to upstream registries
  3. Bonus step: Create a policy (Licence policy, vulnerability policy)
  4. Bonus step: Activate "block until scanned"

workflow on how block-until-scanned works:

ENG-3576_ PoC_ Implement _Hold the Line_ Download Delay Until Policies Evaluated.png

Copy link

vercel bot commented Jun 11, 2025

The latest updates on your projects. Learn more about Vercel for Git ↗︎

Name Status Preview Comments Updated (UTC)
cloudsmith-docs ❌ Failed (Inspect) Aug 7, 2025 0:05am

Base automatically changed from staging to main August 21, 2025 10:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

Successfully merging this pull request may close these issues.

1 participant