Cloudsmith incident

OSV vulnerability data delays.

Minor Resolved View vendor source →

Cloudsmith experienced a minor incident on September 8, 2026 affecting Policy Management, lasting —. The incident has been resolved; the full update timeline is below.

Started
Sep 08, 2026, 07:03 PM UTC
Resolved
Sep 08, 2026, 07:03 PM UTC
Duration
Detected by Pingoru
Sep 08, 2026, 07:03 PM UTC

Affected components

Policy Management

Update timeline

  1. investigating Sep 08, 2026, 02:14 PM UTC

    Status: Investigating We are experiencing delays in OSV vulnerability data. New advisories may take longer to appear against affected packages and trigger policy evaluation. Our engineers are investigating. Affected components Continuous Risk Detection(OSV) (Degraded performance) Policy Management (Degraded performance)

  2. investigating Sep 08, 2026, 02:53 PM UTC

    Status: Investigating We continue to experience delays in OSV vulnerability data. New advisories may take longer to appear against affected packages and trigger policy evaluation. Our engineers are investigating Affected components Continuous Risk Detection(OSV) (Degraded performance) Policy Management (Degraded performance)

  3. monitoring Sep 08, 2026, 03:58 PM UTC

    Status: Monitoring We've made some configuration changes to help process the backlog of OSV vulnerability data. New advisories may take longer to appear against affected packages and trigger policy evaluation. Our engineers are currently monitoring the backlog. Affected components Continuous Risk Detection(OSV) (Degraded performance) Policy Management (Degraded performance)

  4. monitoring Sep 08, 2026, 05:03 PM UTC

    Status: Monitoring Following the configuration changes, we're seeing improvement in processing the backlog of OSV vulnerability data. New advisories may still take longer than usual to appear against affected packages and trigger policy evaluation while the backlog clears. Our engineers are continuing to monitor progress. Affected components Continuous Risk Detection(OSV) (Degraded performance) Policy Management (Degraded performance)

  5. monitoring Sep 08, 2026, 06:01 PM UTC

    Status: Monitoring We're seeing improvement in processing the backlog of OSV vulnerability data. Please note that the new advisories may still take longer than usual to appear against affected packages and trigger policy evaluation while the backlog clears. Our engineers are continuing to monitor progress. Next update at 07:00 PM UTC. Affected components Continuous Risk Detection(OSV) (Degraded performance) Policy Management (Degraded performance)

  6. resolved Sep 08, 2026, 07:03 PM UTC

    Status: Resolved OSV advisory backlog processing has completed, and returned to normal processing at 07:00 PM UTC. All systems are now operating normally. Affected components Continuous Risk Detection(OSV) (Operational) Policy Management (Operational)