Blog


Building secure software supply chains in CNCF with SLSA assessments
Staff Post Building secure software supply chains in CNCF with SLSA assessments
To continue efforts to improve the security of our graduated and incubating projects, we recently worked with Chainguard to assess the software supply chain security practices of two of our graduated projects, Argo and Prometheus. These efforts build...
April 19, 2023

Introducing our Spring 2023 Cloud Native Ambassadors!
Ambassador Post Introducing our Spring 2023 Cloud Native Ambassadors!
Today we’re thrilled to announce 155 new Cloud Native Ambassadors for the Spring 2023 term! The new diverse group of Ambassadors represents 124 companies across 37 countries – meet all the new Ambassadors here. The new Cloud Native...
April 19, 2023

New Kubernetes security audit complete and open sourced
Community Post New Kubernetes security audit complete and open sourced
By Chris Aniszczyk (@cra) and Rey Lejano In 2018, the Cloud Native Computing Foundation (CNCF) started performing and open sourcing third-party security audits with the goal of improving the overall security practices of our ecosystem. Since then, Argo,...
April 19, 2023

Introducing the Buildpack Community organization
Project Post Introducing the Buildpack Community organization
Project post originally published on the Buildpack’s blog by Juan Bustamante Our adopters and contributors have grown substantially over the last several years, but until now the Cloud Native Buildpacks project has not had a structure that would...
April 18, 2023 | By Juan Bustamante

CNCF fuzzing open source projects for security and reliability
Community Post CNCF fuzzing open source projects for security and reliability
By Chris Aniszczyk, Adam Korczynski, David Korczynski Introduction In this blog post we will present an overview of the state of fuzzing CNCF projects. We published a blog post on this in June 2022 titled Improving Security by...
April 18, 2023

Java Operator SDK is joining Operator Framework!
Project Post Java Operator SDK is joining Operator Framework!
By Jonathan Berkhahn, Operator Framework Steering Committee We are pleased to announce Java Operator SDK (JOSDK) is joining Operator Framework as an official subproject. Java Operator SDK JOSDK consists of a high-level framework for implementing operators in Java,...
April 18, 2023

Announcing the Kyverno 1.10 Pre-Release
Announcing the Kyverno 1.10 Pre-Release
Project post also on the Nirmata blog by the Kyverno maintainers Kyverno is a policy engine built for Kubernetes that helps secure and automate Kubernetes configurations. In Kubernetes policies are configurations that govern the configuration and runtime behaviors...
April 18, 2023

Comprehensive network security at Splunk
Project Post Comprehensive network security at Splunk
Project post originally published on the Istio blog by Bernard Van De Walle, Splunk + Mitch Connors, Aviatrix With dozens of tools for securing your network available, it is easy to find tutorials and demonstrations illustrating how these...
April 17, 2023

Introducing Cloud Native Explorers: Amsterdam! 
Community Post Introducing Cloud Native Explorers: Amsterdam! 
By the Cloud Native Explorers Building on the success of “Bob and Jeefy’s Guide to Detroit”, we are pleased to announce Cloud Native Explorers! Cloud Native Explorers is a new blog series where we bring together community members...
April 17, 2023

Top 5 GitOps sessions you don’t want to miss at cdCon + GitOpsCon 2023 (May 8-9 in Vancouver)!
Staff Post Top 5 GitOps sessions you don’t want to miss at cdCon + GitOpsCon 2023 (May 8-9 in Vancouver)!
In modern tech stacks, CI/CD enables GitOps. With so many organizations using CD and GitOps practices and technologies to build new features quickly, reliably, and securely, it was a natural evolution for the CNCF and CD Foundation to...
April 14, 2023