Company
Date Published
Author
Nigel Douglas
Word count
467
Language
English
Hacker News points
None

Summary

Cloudsmith's Enterprise Policy Management (EPM) now supports the Exploit Prediction Scoring System (EPSS), a data-driven metric estimating the probability of software vulnerabilities being exploited in the wild. Using EPM, users can inform package workflows with EPSS scores to prioritize vulnerabilities most likely to be exploited and strengthen their organization's security posture. Cloudsmith users can leverage EPSS-based logic in Open Policy Agent (OPA) policies for more granular decisions around vulnerability management. The system allows automated responses to vulnerabilities, protecting users in real-time as policies are re-checked and reapplied when EPSS scores change. A demonstration of the capabilities will be provided at Kubecon London, showcasing how EPSS can inform package workflows and enhance security posture.