<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Cloudsmith on Open Source Security</title>
    <link>https://opensourcesecurity.io/tag/cloudsmith/</link>
    <description>Recent content in Cloudsmith on Open Source Security</description>
    <generator>Hugo -- 0.139.4</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://opensourcesecurity.io/tag/cloudsmith/feed.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Dependency attacks in 2026 with James Matchett</title>
      <link>https://opensourcesecurity.io/2026/2026-10-james-cloudsmith/</link>
      <pubDate>Mon, 05 Oct 2026 00:00:00 +0000</pubDate>
      <guid>https://opensourcesecurity.io/2026/2026-10-james-cloudsmith/</guid>
      <description>&lt;p&gt;Josh chats with Jeff Matchett from Cloudsmith about a new report they put out. It has some scary looking statistics in it about how organizations are using dependencies. There are some surprising numbers in there, but the story is really one of defense in depth. There&amp;rsquo;s no single thing we can do here, it&amp;rsquo;s all about knowing what you have every step of the way. It&amp;rsquo;s easy to say, but certainly a challenge to do right. James is a ton of fun to chat with and filled with energy and knowledge.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
