Package Search Help

You can use boolean logic (e.g. AND/OR/NOT) for complex search queries. For more help and examples, see the search documentation.

Search by package name:
my-package (implicit)
name:my-package (explicit)

Search by package filename:
filename:my-package.ext 

Search by package tag:
tag:latest 

Search by package version:
version:1.0.0  prerelease:true (prereleases)
prerelease:false (no prereleases)

Search by package architecture:
architecture:x86_64 

Search by package distribution:
distribution:el 

Search by package license:
license:MIT 

Search by package format:
format:deb 

Search by package status:
status:in_progress 

Search by package file checksum:
checksum:5afba 

Search by package security status:
severity:critical 

Search by package vulnerabilities:
vulnerabilities:>1 
vulnerabilities:<1000 

Search by # of package downloads:
downloads:>8 
downloads:<100 

Search by package type:
type:binary 
type:source 

Search by package size (bytes):
size:>50000 
size:<10000 

Search by dependency name/version:
dependency:log4j 
dependency:log4j=1.0.0 
dependency:log4j>1.0.0 

Search by uploaded date:
uploaded:>"1 day ago" 
uploaded:<"August 14, 2022 EST" 

Search by entitlement token (identifier):
entitlement:3lKPVJPosCsY 

Search by policy violation:
policy_violated:true
deny_policy_violated:true
license_policy_violated:true
vulnerability_policy_violated:true

Search by repository:
repository:repo-name

Search by last download date:
last_downloaded:<"30 days ago" 
last_downloaded:>"August 14, 2022 EST" 

Search queries for all Debian-specific (and related) package types

Search by component:
deb_component:unstable

Search queries for all Maven-specific (and related) package types

Search by group ID:
maven_group_id:org.apache

Search queries for all Docker-specific (and related) package types

Search by image digest:
docker_image_digest:sha256:7c5..6d4
(full hashref only)

Search by layer digest:
docker_layer_digest:sha256:4c4..ae4
(full hashref only)

Search queries for all Generic-specific package types

Search by file path:
generic_filepath:path/to/file.txt

Search by directory:
generic_directory:path/to

Field type modifiers (depending on the type, you can influence behaviour)

For all queries, you can use:
~foo for negation

For string queries, you can use:
^foo to anchor to start of term
foo$ to anchor to end of term
foo*bar for fuzzy matching

For number/date or version queries, you can use:
>foo for values greater than
>=foo for values greater / equal
<foo for values less than
<=foo for values less / equal

Need a secure and centralised artifact repository to deliver Alpine, Cargo, CocoaPods, Composer, Conan, Conda, CRAN, Dart, Debian, Docker, Generic, Go, Helm, Hex, HuggingFace, LuaRocks, Maven, MCP, Nix, npm, NuGet, P2, Python, RedHat, Ruby, Swift, Terraform, Vagrant, VSX, Raw & More packages?

Cloudsmith is the new standard in Package / Artifact Management and Software Distribution.

With support for all major package formats, you can trust us to manage your software supply chain.

Start My Free Trial
 Open-Source cloudsmith cloudsmith (Cloudsmith) / cli  GitHub Project
Official repository for the [Cloudsmith CLI](https://github.com/cloudsmith-io/cloudsmith-cli) —standalone binaries, install manifests, and Python packages for every release.


**Other official distribution channels:**
* [Docker Hub](https://hub.docker.com/r/cloudsmith/cloudsmith-cli)
* [PyPI](https://pypi.org/project/cloudsmith-cli)
* [Homebrew](https://github.com/cloudsmith-io/homebrew-cloudsmith-cli)


📖 [Documentation](https://docs.cloudsmith.com/developer-tools/cli) ·
🐛 [Issues](https://github.com/cloudsmith-io/cloudsmith-cli/issues)
Note: Packages in this repository are licensed as Apache License 2.0 (dependencies may be licensed differently).

Docker logo cloudsmith-cli  980efbd37b9b32b97543071a7c0…

One-liner (summary)

A certifiably-awesome package curated by cli-release, hosted by Cloudsmith.

Description

A certifiably-awesome package curated by cli-release, hosted by Cloudsmith.

License

Unknown

Size

49.1 MB

Downloads

2

Tags

image amd64 linux

Status  Completed
Checksum (MD5) d6d55a5d9f4163cdba6b4ad085c7e4a4
Checksum (SHA-1) 320a89ce70695eac3256fb1a4d911f1aa18d7ead
Checksum (SHA-256) 980efbd37b9b32b97543071a7c02529fec92a34bc3883f5404f4e065c1af7998
Checksum (SHA-512) 5176ad18bdd73e597884592c50b5c043ca207b3131c6e32d68e3bdb3befc58b8c7…
GPG Signature
GPG Fingerprint 8e80a1fff6df43fe906d00ff0e7b9fadd43eb554
Storage Region  Dublin, Ireland
Type  Binary (contains binaries and binary artifacts)
Uploaded At 1 month, 2 weeks ago
Uploaded By Uploaded by cli-release
Slug Id cloudsmith-cli-vvat
Unique Id 8i6qTYaeFVd7
Version (Raw) 980efbd37b9b32b97543071a7c02529fec92a34bc3883f5404f4e065c1af7998
Version (Parsed)
  • Type: Unknown
  docker-specific metadata
Image Digest sha256:980efbd37b9b32b97543071a7c02529fec92a34bc3883f5404f4e065c1af7998
Config Digest sha256:3381b4aeae67155372e6e3bec3f4189ec791ccbe632a2b0bef3d1f15bae7ee4a
V1 OCI Index Digest sha256:d955caf5536598c086a978c967867a7bb53045e23c4409b4ead074bf2b9493be
V1 Distribution (Signed) Digest sha256:a7b0ae21c15269457416d7e92b6ddaa924306ce10e517d2af0dc57f4e6d21c7d
V2 Distribution List Digest sha256:53d2828918a7f17656ddfe89e97ad3fa0944ec106f879a65c0b3719094b5bcfa
V2 Distribution Digest sha256:790a498bb613cef2415b72036234474cda681d59abb24520eda5b6729ffd721f
V1 Distribution Digest sha256:1d987099a5aca2aac3d1df3d1a6c71682c4be1f7f34006e663650c871fc1ee75
V1 OCI Digest sha256:980efbd37b9b32b97543071a7c02529fec92a34bc3883f5404f4e065c1af7998
  Cosign Manifests
SIG cloudsmith-cli (sha256:5af0deffaef495a2201c612b7e39413cee99cc2c48e776acce4b9a576950d7f4)
  extended metadata
Manifest Type V1 OCI
Architecture amd64
Config
Created 2026-08-03 14:37:42 UTC
Os linux

This package was uploaded with the following V1 OCI manifest:

{
  "schemaVersion": 2,
  "mediaType": "application/vnd.oci.image.manifest.v1+json",
  "config": {
    "mediaType": "application/vnd.oci.image.config.v1+json",
    "digest": "sha256:63f34865ef83bd066e72b56e418eed2cb9d8864535cb276ec5812fe5758567b0",
    "size": 3263
  },
  "layers": [
    {
      "mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
      "digest": "sha256:897d797d2723cf0e318402f4d6f37d51b011517e5cf09246b22155f0fa90dc81",
      "size": 3646875
    },
    {
      "mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
      "digest": "sha256:e7a1b9e23b2a0b3b40cd0a6e4f8a5d28151ff64169ff257c695e6b3ebe471ce3",
      "size": 47811313
    },
    {
      "mediaType": "application/vnd.oci.image.layer.v1.tar+gzip",
      "digest": "sha256:ea31cca3975641b377e36ccc7a9e83a26d75d1afc7b2e6d84ff2c354dcef5bde",
      "size": 944
    }
  ]
}
Digest: sha256:897d797d2723cf0e318402f4d6f37d51b011517e5cf09246b22155f0fa90dc81
Command: ADD alpine-minirootfs-3.21.7-x86_64.tar.gz / # buildkit
3.5 MB
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: CMD ["/bin/sh"]
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ARG CLOUDSMITH_CLI_VERSION=1.21.0
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ARG VCS_REF=1af8b0b33f9fea0f60b27f2c9369afa483d810f8
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: LABEL maintainer=support@cloudsmith.io org.opencontainers.image.title=Cloudsmith CLI org.opencontainers.image.description=Official Cloudsmith CLI org.opencontainers.image.vendor=Cloudsmith org.opencontainers.image.url=https://cloudsmith.com org.opencontainers.image.source=https://github.com/cloudsmith-io/cloudsmith-cli org.opencontainers.image.documentation=https://docs.cloudsmith.com/developer-tools/cli org.opencontainers.image.licenses=Apache-2.0 org.opencontainers.image.version=1.21.0 org.opencontainers.image.revision=1af8b0b33f9fea0f60b27f2c9369afa483d810f8
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ENV PATH=/opt/cloudsmith:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin
32 bytes
Digest: sha256:e7a1b9e23b2a0b3b40cd0a6e4f8a5d28151ff64169ff257c695e6b3ebe471ce3
Command: COPY /opt/cloudsmith /opt/cloudsmith # buildkit
45.6 MB
Digest: sha256:ea31cca3975641b377e36ccc7a9e83a26d75d1afc7b2e6d84ff2c354dcef5bde
Command: RUN |2 CLOUDSMITH_CLI_VERSION=1.21.0 VCS_REF=1af8b0b33f9fea0f60b27f2c9369afa483d810f8 /bin/sh -c adduser -D -u 1000 cloudsmith # buildkit
944 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: USER cloudsmith
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ENTRYPOINT ["cloudsmith"]
32 bytes
Docker logo
cloudsmith-cli
image amd64 linux
1 Uploaded by cli-release
Docker logo
cloudsmith-cli
image arm64 linux
3 Uploaded by cli-release
Docker logo
cloudsmith-cli
image amd64 linux
3 Uploaded by cli-release
Docker logo
cloudsmith-cli
image amd64 linux
51.0 MB 1 month ago
5 Uploaded by cli-release
Docker logo
cloudsmith-cli
image amd64 linux
51.0 MB 1 month ago
4 Uploaded by cli-release
Docker logo
cloudsmith-cli
image arm64 linux
51.3 MB 1 month ago
3 Uploaded by cli-release
Docker logo
cloudsmith-cli
image arm64 linux
2 Uploaded by cli-release
Docker logo
cloudsmith-cli
image amd64 linux
5 Uploaded by cli-release
Docker logo
cloudsmith-cli
image arm64 linux
5 Uploaded by cli-release
Docker logo
cloudsmith-cli
image amd64 linux
2 Uploaded by cli-release
Docker logo
cloudsmith-cli
image amd64 linux
4 Uploaded by cli-release
Docker logo
cloudsmith-cli
image amd64 linux
2 Uploaded by cli-release
Docker logo
cloudsmith-cli
image arm64 linux
1 Uploaded by cli-release
Docker logo
cloudsmith-cli
image arm64 linux
3 Uploaded by cli-release
Docker logo
cloudsmith-cli
image amd64 linux
2 Uploaded by cli-release
Docker logo
cloudsmith-cli
image arm64 linux
51.3 MB 1 month ago
4 Uploaded by cli-release
Docker logo
cloudsmith-cli
image arm64 linux
3 Uploaded by cli-release
Docker logo
cloudsmith-cli
image amd64 linux
6 Uploaded by cli-release
Docker logo
cloudsmith-cli
image arm64 linux
4 Uploaded by cli-release
Docker logo
cloudsmith-cli
image arm64 linux
4 Uploaded by cli-release

Last scanned

6 days, 23 hours ago

Scan result

Vulnerable

Vulnerability count

2

Max. severity

High
Target: Python
HIGH

CVE-2026-69247: python-cryptography: python-cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 until 50.0.0, pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime reported the outcome of decrypting a RecipientInfo's encryptedKey in several distinguishable ways, one of which disclosed the exact length recovered from the RSA operation. The same distinction was also observable by timing. An application that decrypts attacker-supplied EnvelopedData and reflects the outcome gives the attacker a Bleichenbacher oracle against the content-encryption key. Decryption ran as RSA PKCS#1 v1.5 decrypt of encryptedKey, build an AES cipher from the result, then AES-CBC decrypt and PKCS#7 unpad. Invalid RSA padding, a valid padding with a bad key length, a correct length with a wrong key, and the real key each failed or succeeded differently. Case 1 is reachable only where the linked library lacks implicit rejection: OpenSSL 3.0 and 3.1, LibreSSL, and BoringSSL. Exploitation requires a service that auto-decrypts untrusted EnvelopedData matching the victim certificate and answers adaptively at high volume, such as an S/MIME gateway or mail filter. This issue is fixed in 50.0.0.

Package Name: cryptography
Installed Version: 49.0.0
Fixed Version: 50.0.0

References: access.redhat.com github.com github.com github.com github.com nvd.nist.gov www.cve.org
HIGH

CVE-2026-59950: MCP Python SDK: WebSocket server transport does not support Host/Origin validation

The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.28.1, the deprecated mcp.server.websocket.websocket_server transport accepted WebSocket handshakes without applying Host or Origin header validation, leaving no SDK-level way to restrict which origins could connect to applications that exposed that transport. This issue is fixed in version 1.28.1.

Package Name: mcp
Installed Version: 1.27.2
Fixed Version: 1.28.1

References: github.com github.com github.com github.com github.com nvd.nist.gov

These instructions assume you have setup the repository first (or read it).

To pull cloudsmith-cli @ reference/tag sha256:980efbd37b9b32b97543071a7c02529fec92a34bc3883f5404f4e065c1af7998:

docker pull docker.cloudsmith.io/cloudsmith/cli/cloudsmith-cli@sha256:980efbd37b9b32b97543071a7c02529fec92a34bc3883f5404f4e065c1af7998

You can also pull the latest version of this image (if it exists):

docker pull docker.cloudsmith.io/cloudsmith/cli/cloudsmith-cli:latest

To refer to this image after pulling in a Dockerfile, specify the following:

FROM docker.cloudsmith.io/cloudsmith/cli/cloudsmith-cli@sha256:980efbd37b9b32b97543071a7c02529fec92a34bc3883f5404f4e065c1af7998
Top