Cloudsmith incident

OSV vulnerability data delays.

Cloudsmith is currently experiencing a major incident affecting Policy Management, which began 26 min ago. The vendor's full update timeline is below.

Started
Sep 08, 2026, 06:01 PM UTC
Resolved
Ongoing
Duration
● 25m
Detected by Pingoru
Sep 08, 2026, 06:01 PM UTC

Affected components

Policy Management

Update timeline

  1. investigating Sep 08, 2026, 02:14 PM UTC

    Status: Investigating We are experiencing delays in OSV vulnerability data. New advisories may take longer to appear against affected packages and trigger policy evaluation. Our engineers are investigating. Affected components Continuous Risk Detection(OSV) (Degraded performance) Policy Management (Degraded performance)

  2. investigating Sep 08, 2026, 02:53 PM UTC

    Status: Investigating We continue to experience delays in OSV vulnerability data. New advisories may take longer to appear against affected packages and trigger policy evaluation. Our engineers are investigating Affected components Continuous Risk Detection(OSV) (Degraded performance) Policy Management (Degraded performance)

  3. monitoring Sep 08, 2026, 03:58 PM UTC

    Status: Monitoring We've made some configuration changes to help process the backlog of OSV vulnerability data. New advisories may take longer to appear against affected packages and trigger policy evaluation. Our engineers are currently monitoring the backlog. Affected components Continuous Risk Detection(OSV) (Degraded performance) Policy Management (Degraded performance)

  4. monitoring Sep 08, 2026, 05:03 PM UTC

    Status: Monitoring Following the configuration changes, we're seeing improvement in processing the backlog of OSV vulnerability data. New advisories may still take longer than usual to appear against affected packages and trigger policy evaluation while the backlog clears. Our engineers are continuing to monitor progress. Affected components Continuous Risk Detection(OSV) (Degraded performance) Policy Management (Degraded performance)

  5. monitoring Sep 08, 2026, 06:01 PM UTC

    Status: Monitoring We're seeing improvement in processing the backlog of OSV vulnerability data. Please note that the new advisories may still take longer than usual to appear against affected packages and trigger policy evaluation while the backlog clears. Our engineers are continuing to monitor progress. Next update at 07:00 PM UTC. Affected components Continuous Risk Detection(OSV) (Degraded performance) Policy Management (Degraded performance)