Signing Keys

Cloudsmith uses GPG or RSA signatures (where applicable) in addition to package checksums to detect tampering.

We calculate a signature for every file that is uploaded, but only some of the package formats make it available or use it. Only some of the formats also offer metadata signing.

For increased trust, you can also provide your own GPG key or RSA key for signing.

Key Support by Package Format

Package FormatKey TypeKey Use
AlpineRSAIndex
CargoNot Supported by Format
CocoaPodsNot Supported by Format
ComposerGPG
ConanNot Supported by Format
CRAN
DartNot Supported by Format
DebianGPGIndex
DockerRSAIndex
Go
GradleGPGIndex Packages
Helm ChartsGPG
LuaRocks
MavenGPGIndex Packages
npmGPG
NuGet
PythonGPG
RawGPG
RPMGPGIndex Packages
RubyGPG
sbtGPGIndex Packages
Terraform ModulesNot Supported by Format
Unity RegistryGPG
VagrantGPG

Cloudsmith is the new standard in Package / Artifact Management and Software Distribution

With support for all major package formats, you can trust us to manage your software supply chain.


Start My Free Trial Now
Cookie Declaration (Manage Cookies)