Forgely is a security graph visualization engine which works against Cloudsmith.
200
From artifact to blast radius.
A security graph visualisation engine for Cloudsmith artifact repositories. It covers two cloud-native security disciplines — SCA and CIEM — and renders them as interactive, colour-coded graphs, so DevOps and Security teams can see blast radii, transitive risk and access exposure at a glance.

docker run -d \
--name forgely \
-p 8000:8000 \
-v forgely-cache:/data \
fullstackspectrum/forgely:latest
Open http://localhost:8000 and add your Cloudsmith API key under Settings → Connection. The key is stored in your browser, not in the image.
-p 8000:8000is required. Without it the container starts and reports healthy, but nothing reaches it.
services:
forgely:
image: fullstackspectrum/forgely:latest
ports:
- "8000:8000"
volumes:
- forgely-cache:/data
restart: unless-stopped
volumes:
forgely-cache:
SCA — Software Composition Analysis
CIEM — Cloud Infrastructure Entitlement Management
Combining the two lets you cross-reference a vulnerable package with the identities that can write to or download from the repository hosting it — the step that turns a CVE into an assessment of actual exposure.
| Tag | Meaning |
|---|---|
latest | Most recent release |
1.0.0-beta.11 | A specific version. Pin this for anything reproducible |
Platforms: linux/amd64, linux/arm64.
Windows users are covered by linux/amd64 — Docker Desktop runs Linux
containers through WSL2, so no separate Windows image is needed.
Everything is optional. Forgely runs with no configuration at all and takes an API key through the UI.
| Variable | Description |
|---|---|
CLOUDSMITH_API_KEY | A server-side key, if you would rather every visitor to this instance share one instead of entering their own |
CLOUDSMITH_OWNER | Default workspace slug, pre-selected on load |
CLOUDSMITH_REPO | Default repository slug, pre-selected on load |
FORGELY_CACHE_PATH | Scan cache location (default /data/scans.db) |
CORS_ORIGINS | Only needed if you serve the frontend from another origin. Not required here — one container serves both |
Mount /data to keep the vulnerability scan cache between runs. It is keyed on
each package's scan completion time rather than a TTL, so entries never go
stale — and a warm cache turns a cold graph build of several thousand packages
into a local read instead of thousands of API calls.
docker exec … sh will not work — use
docker logs.trivy image fullstackspectrum/forgely reports no
vulnerabilities at any severity.An API key is never baked into the image.
Not affiliated with Cloudsmith. This is an independent, community-developed tool. It is not endorsed or supported by Cloudsmith Ltd, and is provided "as is", without warranty of any kind. Cloudsmith Ltd accepts no responsibility or liability for any loss, damage or issues arising from its use. Use at your own risk.
Built with AI assistance. A large share of this code was written by an AI assistant working from prompts, then reviewed and directed by a human. Treat it as you would any code you did not write line by line: read it before running it against anything you care about.
Source: https://github.com/fullstackspectrum/Forgely · Licence: Apache-2.0
Content type
Image
Digest
sha256:f19ed6804…
Size
38.1 MB
Last updated
about 1 month ago
docker pull fullstackspectrum/forgely