Staff Post
2024 year in review of CNCF and top 30 open source project velocity
By Chris Aniszczyk By consistently tracking open source project velocity, we are able to see the trends and technologies resonating with developers and end users. We have been tracking these trends since 2017; all previous blogs...
January 29, 2025
Showing 12 of 2236 posts
Mentorship Post
Congratulations to 45 CNCF Term 2 2024 LFX Program mentees!
Mentorship blog by Nate Waddington, Head of Mentorship & Documentation at CNCF We are thrilled to share that 45 CNCF mentees with the LFX Program have successfully completed their mentorship. Numerous CNCF projects across Graduated, Incubating,...
September 27, 2024
Lessons from CrowdStrike’s buggy update: the critical importance of robust release processes
Community post by Andrés Vega, M42 and Technical Leader, CNCF TAG Security Recent events involving CrowdStrike’s Falcon security software have underscored a critical lesson across the industry: the importance of having a robust, secure release process....
July 19, 2024
Member Post
Mastering DevSecOps with Devtron: a strategic approach
Member post originally published on the Devtron blog by Nishant As the adoption of Kubernetes continues to grow, organizations encounter numerous challenges in securing their software development and deployment processes. Integrating security practices into DevOps, known...
June 20, 2024
Project Post
Unleashing in-toto: The API of DevSecOps
Guest post by Aditya Sirish, in-toto maintainer and Cole Kennedy, member of the in-toto steering committee The Integration Revolution Being part of the DevOps world, you’re likely no stranger to the DevSecOps buzz — the strategy...
August 17, 2023 | Aditya Sirish and Cole Kennedy
Member Post
Container Security: what it is and how to implement it
Guest post originally published on SparkFabrik’s blog Containerized applications are becoming increasingly more common, and with their deployment comes an increased need to ensure adequate container security and resilience of the software supply chain. In this article,...
November 14, 2022
Member Post
A MAP for Kubernetes supply chain security
Guest post originally published on the Nirmata blog by Jim Bugwadia The sharp increase in software supply chain attacks has made securing the build and delivery of software a critical topic. But what does this mean...
April 12, 2022 | Jim Bugwadia
Member Post
Trusting SBOMs in the software supply chain: Syft now creates attestations using Sigstore
Guest post originally published on the Anchore blog by Dan Luhring With the recent release of Syft v0.40.0, you can now create signed SBOM attestations directly in Syft. This is made possible by Project Sigstore, which makes signing...
March 30, 2022
Staff Post
Supply chain security project in-toto moves to the CNCF Incubator
The CNCF Technical Oversight Committee (TOC) has voted to accept in-toto as a CNCF incubating project. in-toto is a framework that protects the software supply chain by collecting and verifying relevant data. It does so by...
March 10, 2022
Staff Post
16 CNCF interns graduated from Google Summer of Code (GSoC) 2021!
In its fifth year participating in Google Summer of Code (GSoC), CNCF is excited to announce 16 interns have graduated from the program after working with the Foundation’s projects. Interns this year contributed to Graduated, Incubating...
November 1, 2021
Member Post
Secure software supply chains: good practices, at scale
Guest post originally published on Contino Engineering‘s blog by Dan Chernoff Supply chain attacks rose by 42% in the first quarter of 2021 [1] and are becoming even more prevalent [2]. In response to secure software...
October 27, 2021 | Dan Chernoff
Community Post
GSoC Spotlight: My Google Summer of Code experience at CNCF in 2020
Guest post from Christian Rebischke, Site Reliability Engineer at avency and CNCF GSoC Intern As every year the Cloud Native Computing Foundation (CNCF) has participated in the Google Summer of Code program, where students from all...
October 7, 2020 | Christian Rebischke
16 CNCF Interns Graduate from Summer of Code (GSoC) 2020!
Having participated in the Google Summer of Code (GSoC) since 2017, CNCF is thrilled to announce that this year, 16 interns working on the Foundation’s projects have graduated from the program. Interns this year got to...
September 17, 2020 | Chris Abraham