Company
Date Published
Author
Maia Livingstone
Word count
737
Language
English
Hacker News points
None

Summary

Datadog's Supply-Chain Firewall (SCFW) is a real-time scanning feature that identifies vulnerabilities as developers pull packages from public registries like npmjs. This approach helps manage risk consistently and efficiently at scale, but it focuses on individual package decisions during development, which may not be sufficient for larger organizations. In contrast, Cloudsmith offers curated repositories, which provide centralized and persistent security control, policy-driven automation, scalability at enterprise levels, support for multiple package formats, reduced developer burden, and a more comprehensive solution for securing the software supply chain.