{"id":43846946,"url":"https://github.com/cloudsmith-io/terraform-provider-cloudsmith","last_synced_at":"2026-02-06T06:06:11.737Z","repository":{"id":40234667,"uuid":"270727700","full_name":"cloudsmith-io/terraform-provider-cloudsmith","owner":"cloudsmith-io","description":"Terraform Provider for Cloudsmith","archived":false,"fork":false,"pushed_at":"2025-12-16T10:24:07.000Z","size":652,"stargazers_count":18,"open_issues_count":6,"forks_count":11,"subscribers_count":14,"default_branch":"master","last_synced_at":"2025-12-19T23:38:18.327Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"https://registry.terraform.io/providers/cloudsmith-io/cloudsmith","language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mpl-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/cloudsmith-io.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":".github/CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":null,"codeowners":"CODEOWNERS","security":null,"support":".github/SUPPORT.md","governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2020-06-08T15:49:36.000Z","updated_at":"2025-12-11T14:09:36.000Z","dependencies_parsed_at":"2023-11-30T11:31:28.868Z","dependency_job_id":"8500512e-2bff-48e6-ba4d-8eed4208c2e4","html_url":"https://github.com/cloudsmith-io/terraform-provider-cloudsmith","commit_stats":null,"previous_names":[],"tags_count":67,"template":false,"template_full_name":null,"purl":"pkg:github/cloudsmith-io/terraform-provider-cloudsmith","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/cloudsmith-io%2Fterraform-provider-cloudsmith","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/cloudsmith-io%2Fterraform-provider-cloudsmith/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/cloudsmith-io%2Fterraform-provider-cloudsmith/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/cloudsmith-io%2Fterraform-provider-cloudsmith/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/cloudsmith-io","download_url":"https://codeload.github.com/cloudsmith-io/terraform-provider-cloudsmith/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/cloudsmith-io%2Fterraform-provider-cloudsmith/sbom","scorecard":{"id":231,"data":{"date":"2025-08-11","repo":{"name":"github.com/cloudsmith-io/terraform-provider-cloudsmith","commit":"e253930ff4b6a237d1e477e54dbd58d2c999b7da"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":5.3,"checks":[{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Maintained","score":2,"reason":"2 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 2","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Warn: no topLevel permission defined: .github/workflows/acceptance-tests.yml:1","Info: topLevel 'contents' permission set to 'read': .github/workflows/golangci-lint.yml:10","Warn: no topLevel permission defined: .github/workflows/release.yml:1","Info: no jobLevel write permissions found"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Code-Review","score":10,"reason":"all changesets reviewed","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"Pinned-Dependencies","score":0,"reason":"dependency not pinned by hash detected -- score normalized to 0","details":["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/acceptance-tests.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudsmith-io/terraform-provider-cloudsmith/acceptance-tests.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/acceptance-tests.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudsmith-io/terraform-provider-cloudsmith/acceptance-tests.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/acceptance-tests.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudsmith-io/terraform-provider-cloudsmith/acceptance-tests.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/acceptance-tests.yml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudsmith-io/terraform-provider-cloudsmith/acceptance-tests.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/golangci-lint.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudsmith-io/terraform-provider-cloudsmith/golangci-lint.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/golangci-lint.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudsmith-io/terraform-provider-cloudsmith/golangci-lint.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/golangci-lint.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudsmith-io/terraform-provider-cloudsmith/golangci-lint.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudsmith-io/terraform-provider-cloudsmith/release.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudsmith-io/terraform-provider-cloudsmith/release.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudsmith-io/terraform-provider-cloudsmith/release.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:37: update your workflow using https://app.stepsecurity.io/secureworkflow/cloudsmith-io/terraform-provider-cloudsmith/release.yml/master?enable=pin","Info:   0 out of   6 GitHub-owned GitHubAction dependencies pinned","Info:   0 out of   5 third-party GitHubAction dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: Mozilla Public License 2.0: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Packaging","score":10,"reason":"packaging workflow detected","details":["Info: Project packages its releases by way of GitHub Actions.: .github/workflows/release.yml:10"],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Branch-Protection","score":5,"reason":"branch protection is not maximal on development and all release branches","details":["Info: 'allow deletion' disabled on branch 'master'","Info: 'force pushes' disabled on branch 'master'","Warn: 'branch protection settings apply to administrators' is disabled on branch 'master'","Warn: 'stale review dismissal' is disabled on branch 'master'","Warn: required approving review count is 1 on branch 'master'","Info: codeowner review is required on branch 'master'","Warn: 'last push approval' is disabled on branch 'master'","Info: status check found to merge onto on branch 'master'","Info: PRs are required in order to make changes on branch 'master'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"Signed-Releases","score":8,"reason":"5 out of the last 5 releases have a total of 5 signed artifacts.","details":["Info: signed release artifact: terraform-provider-cloudsmith_0.0.62_SHA256SUMS.sig: https://github.com/cloudsmith-io/terraform-provider-cloudsmith/releases/tag/v0.0.62","Info: signed release artifact: terraform-provider-cloudsmith_0.0.61_SHA256SUMS.sig: https://github.com/cloudsmith-io/terraform-provider-cloudsmith/releases/tag/v0.0.61","Info: signed release artifact: terraform-provider-cloudsmith_0.0.60_SHA256SUMS.sig: https://github.com/cloudsmith-io/terraform-provider-cloudsmith/releases/tag/v0.0.60","Info: signed release artifact: terraform-provider-cloudsmith_0.0.59_SHA256SUMS.sig: https://github.com/cloudsmith-io/terraform-provider-cloudsmith/releases/tag/v0.0.59","Info: signed release artifact: terraform-provider-cloudsmith_0.0.58_SHA256SUMS.sig: https://github.com/cloudsmith-io/terraform-provider-cloudsmith/releases/tag/v0.0.58","Warn: release artifact v0.0.62 does not have provenance: https://api.github.com/repos/cloudsmith-io/terraform-provider-cloudsmith/releases/232220005","Warn: release artifact v0.0.61 does not have provenance: https://api.github.com/repos/cloudsmith-io/terraform-provider-cloudsmith/releases/214804608","Warn: release artifact v0.0.60 does not have provenance: https://api.github.com/repos/cloudsmith-io/terraform-provider-cloudsmith/releases/200167857","Warn: release artifact v0.0.59 does not have provenance: https://api.github.com/repos/cloudsmith-io/terraform-provider-cloudsmith/releases/200080596","Warn: release artifact v0.0.58 does not have provenance: https://api.github.com/repos/cloudsmith-io/terraform-provider-cloudsmith/releases/194903697"],"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"SAST","score":10,"reason":"SAST tool is run on all commits","details":["Info: all commits (30) are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}},{"name":"Vulnerabilities","score":0,"reason":"17 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: GO-2024-2961","Warn: Project is vulnerable to: GO-2023-2402 / GHSA-45x7-px36-x8w8","Warn: Project is vulnerable to: GO-2024-3321 / GHSA-v778-237x-gjrc","Warn: Project is vulnerable to: GO-2025-3487 / GHSA-hcg3-q754-cr77","Warn: Project is vulnerable to: GO-2022-0288","Warn: Project is vulnerable to: GO-2022-0969 / GHSA-69cg-p879-7622","Warn: Project is vulnerable to: GO-2022-1144 / GHSA-xrjj-mj9h-534m","Warn: Project is vulnerable to: GO-2023-1571 / GHSA-vvpx-j8f3-3w6h","Warn: Project is vulnerable to: GO-2023-1988 / GHSA-2wrh-6pvc-2jm9","Warn: Project is vulnerable to: GO-2023-2102 / GHSA-4374-p667-p6c8","Warn: Project is vulnerable to: GO-2023-2153 / GHSA-m425-mq94-257g / GHSA-qppj-fm5r-hxr3","Warn: Project is vulnerable to: GO-2024-2687 / GHSA-4v7x-pqxf-cx7m","Warn: Project is vulnerable to: GO-2024-3333","Warn: Project is vulnerable to: GO-2025-3503 / GHSA-qxp5-gwg8-xv66","Warn: Project is vulnerable to: GO-2025-3595 / GHSA-vvgc-356p-c3xw","Warn: Project is vulnerable to: GO-2022-1059 / GHSA-69ch-w2m2-3vjp","Warn: Project is vulnerable to: GO-2024-2611 / GHSA-8r3f-844c-mc37"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2025-08-14T12:20:58.775Z","repository_id":40234667,"created_at":"2025-08-14T12:20:58.775Z","updated_at":"2025-08-14T12:20:58.775Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":29153203,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-02-06T02:39:25.012Z","status":"ssl_error","status_checked_at":"2026-02-06T02:37:22.784Z","response_time":59,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.5:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2026-02-06T06:06:10.257Z","updated_at":"2026-02-06T06:06:11.728Z","avatar_url":"https://github.com/cloudsmith-io.png","language":"Go","funding_links":[],"categories":[],"sub_categories":[],"readme":"Terraform Provider for Cloudsmith\n=================================\n\n![](https://cloudsmith.com/images/uploads/resources/cloudsmith-logo-master-color.svg)\n\nTerraform provider for managing your Cloudsmith resources.\n\nRequirements\n------------\n\n- [Terraform](https://www.terraform.io/downloads.html) \u003e= 0.12.x\n- [Go](https://golang.org/doc/install) \u003e= 1.13 (to build the provider plugin)\n\nBuilding The Provider\n---------------------\n\nClone repository:\n\n```sh\ngit clone git@github.com:cloudsmith-io/terraform-provider-cloudsmith\n```\n\nEnter the provider directory and build the provider:\n\n```sh\ncd terraform-provider-cloudsmith\ngo build\n```\n\nUsing the provider\n------------------\n\nTo use a released provider in your Terraform environment, run [`terraform init`](https://www.terraform.io/docs/commands/init.html) and Terraform will automatically install the provider. To specify a particular provider version when installing released providers, see the [Terraform documentation on provider versioning](https://www.terraform.io/docs/configuration/providers.html#version-provider-versions).\n\nTo instead use a custom-built provider in your Terraform environment (e.g. the provider binary from the build instructions above), follow the instructions to [install it as a plugin.](https://www.terraform.io/docs/plugins/basics.html#installing-plugins) After placing the custom-built provider into your plugins directory, run `terraform init` to initialize it.\n\n### Examples\n\nCreate a repository with a custom entitlement token\n\n```\nprovider \"cloudsmith\" {\n    api_key = \"my-api-key\"\n}\n\ndata \"cloudsmith_namespace\" \"my_namespace\" {\n    slug = \"my-namespace\"\n}\n\nresource \"cloudsmith_repository\" \"my_repository\" {\n    description = \"A certifiably-awesome private package repository\"\n    name        = \"My Repository\"\n    namespace   = data.cloudsmith_namespace.my_namespace.slug_perm\n    slug        = \"my-repository\"\n}\n\nresource \"cloudsmith_entitlement\" \"my_entitlement\" {\n    name       = \"Test Entitlement\"\n    namespace  = cloudsmith_repository.test.namespace\n    repository = cloudsmith_repository.test.slug_perm\n}\n```\n\nRetrieve a list of packages from a repository\n\n```\nprovider \"cloudsmith\" {\n    api_key = \"my-api-key\"\n}\n\ndata \"cloudsmith_namespace\" \"my_namespace\" {\n  slug = \"my-namespace\"\n}\n\ndata \"cloudsmith_repository\" \"my_repository\" {\n  namespace  = data.cloudsmith_namespace.my_namespace.slug\n  identifier = \"my-repository\"\n}\n\ndata \"cloudsmith_package_list\" \"my_packages\" {\n  namespace     = data.cloudsmith_repository.my_repository.namespace\n  repository    = data.cloudsmith_repository.my_repository.slug_perm\n  filters       = [\"format:docker\", \"name:^my-package\"]\n}\n\noutput \"packages\" {\n  value = formatlist(\"%s-%s\", data.cloudsmith_package_list.my_packages.packages.*.name, data.cloudsmith_package_list.my_packages.packages.*.version)\n}\n```\n\nTesting the Provider\n-----------------------\n\nIn order to test the provider, you can run `go test`.\n\n```sh\ngo test -v ./...\n```\n\nIn order to run the full suite of Acceptance tests, you'll need a paid Cloudsmith account.\n\nYou'll also need to set a few environment variables:\n\n- `TF_ACC=1`: Used to enable acceptance tests during `go test`.\n- `CLOUDSMITH_API_KEY`: API key used to manage resources during test runs.\n- `CLOUDSMITH_NAMESPACE`: Cloudsmith namespace in which to create and destroy resources under test.\n\n*Note:* Acceptance tests create real resources, and may cost money to run.\n\n```sh\nexport TF_ACC=1\nexport CLOUDSMITH_API_KEY=mykey\nexport CLOUDSMITH_NAMESPACE=mynamespace\ngo test -v ./...\n```\n\nIf needed, you can also run individual tests with the `-run` flag:\n\n```sh\ngo test -v -run=TestAccEntitlement_basic ./...\n```\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fcloudsmith-io%2Fterraform-provider-cloudsmith","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fcloudsmith-io%2Fterraform-provider-cloudsmith","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fcloudsmith-io%2Fterraform-provider-cloudsmith/lists"}