Search results for: security/


Security Profiles Operator v1: Stable APIs, Security Hardened, and Shaping Upstream Kubernetes

Posted on June 26, 2026 | Sascha Grunert (Red Hat)

Linux provides powerful kernel-level security mechanisms, seccomp, SELinux, and AppArmor, that restrict what containerized workloads can do. Each uses profiles that define permitted behavior, but writing, distributing, and maintaining those profiles by hand is tedious and…


Securing CI/CD for an open source project, part 3: Credentials, verification, and what’s next

Posted on June 26, 2026 | André Martins (Cilium maintainer and Software Engineer, Isovalent at Cisco) and Feroz Salam (Cilium Security Team and Security Engineer, Isovalent at Cisco)

This is the third and final post in a series on how Cilium hardens its CI/CD pipeline. Part 1 covered access control and Part 2 covered dependency hardening. This post covers the last layer: keeping CI…


Inspektor Gadget: Results from the first security audit

Posted on June 3, 2026 | Brian Benz, Francis Laniel, Maya Singh, Helen Woeste, and Pietro Tirenna - Inspektor Gadget

Inspektor Gadget, the open source eBPF-based toolkit for Kubernetes observability and Linux host inspection, has completed its first independent security audit. The audit was coordinated by the Open Source Technology Improvement Fund (OSTIF), funded by the…


Introducing Prempti: Policy and visibility for AI coding agents

Posted on May 20, 2026 | Leonardo Grasso, Falco Maintainer

AI coding agents have become a real part of the developer workflow. Tools like Claude Code sit in your terminal, read your files, run shell commands, make network requests, and write code, all on your behalf….


Announcing Kyverno release 1.18!

Posted on May 5, 2026 | Cortney Nickerson, Kyverno Contributor

We’re excited to announce the release of Kyverno 1.18, our first release since graduating within the Cloud Native Computing Foundation. This release builds on Kyverno’s growing role as a Kubernetes-native policy engine, with major investments in…


Securing GitHub Actions CI dependencies: Recipe card

Posted on May 4, 2026 | Marina Moore, Evan Anderson, and Sherine Khoury, CNCF Technical Advisory Group

Recipe GitHub Actions CI dependencies Target audience (the chef) Project maintainers and developers who need practical, concrete steps to efficiently secure CI dependencies within their GitHub Actions workflows Scope (ingredients) Dependencies within the GitHub Actions, Github…


CNCF Welcomes 21 New Silver Members As Global Demand Surges for Observability, AI, and Secure Cloud Native Infrastructure

Posted on March 25, 2026

New global members join CNCF reflecting the rise of enterprise demand for scalable, cost-efficient cloud native technologies KUBECON + CLOUDNATIVECON EUROPE, AMSTERDAM—25 MARCH, 2026—The Cloud Native Computing Foundation® (CNCF®), which builds sustainable ecosystems for cloud native…


Cloud Native Computing Foundation Announces Kyverno’s Graduation

Posted on March 24, 2026

Kyverno reaches graduation after demonstrating broad enterprise adoption as platform teams adopt declarative governance Key Highlights: KUBECON + CLOUDNATIVECON NORTH EUROPE, AMSTERDAM, The Netherlands – March 24, 2026 – The Cloud Native Computing Foundation® (CNCF®), which…


Cloud native agentic standards

Posted on March 23, 2026 | CNCF AI TCG

An application, composed of one or more containers as dictated by system architecture, that operates either independently or as part of a distributed collaboration—interacting with at least one other entity (container) or achieving quorum-based consensus. It…


Policy-as-Code: Flexible Kubernetes governance with Kyverno

Posted on March 19, 2026 | Dahu Kuang, Lei Hou, and Shuting Zhao, Kyverno Project Maintainers

Overview Kubernetes has fundamentally transformed how enterprises deploy and manage business workloads. As organizations build production applications at scale on Kubernetes, cluster size and complexity continue to grow—creating unprecedented challenges in ensuring cluster security, compliance, and…