Search results for: artifact hub


A MAP for Kubernetes supply chain security

Posted on April 12, 2022 | By Jim Bugwadia

Guest post originally published on the Nirmata blog by Jim Bugwadia The sharp increase in software supply chain attacks has made securing the build and delivery of software a critical topic. But what does this mean for Kubernetes…


Trusting SBOMs in the software supply chain: Syft now creates attestations using Sigstore

Posted on March 30, 2022

Guest post originally published on the Anchore blog by Dan Luhring With the recent release of Syft v0.40.0, you can now create signed SBOM attestations directly in Syft. This is made possible by Project Sigstore, which makes signing and verification…


The future of Kubernetes – and why developers should look beyond Kubernetes in 2022

Posted on March 4, 2022 | By Michael Vittrup Larsen

Guest post originally published on Eficode’s blog by Michael Vittrup Larsen Kubernetes is ubiquitous in container orchestration, and its popularity has yet to weaken. This does, however, not mean that evolution in the container orchestration space is at…


Flux Security: Image Provenance

Posted on February 24, 2022

Guest post originally published on Flux’s blog by Daniel Holbach Next up in our blog series about Flux Security is how and why we use signatures for the Flux CLI and all its controller images and what you…


Security: The value of SBOMs

Posted on February 22, 2022 | By Daniel Holbach

Project post originally published on Flux’s blog by Daniel Holbach Flux – built with security in mind You don’t get to re-architect a successful project very often, but we did about two years ago. The Flux project was…


KEDA at Zapier

Posted on January 21, 2022

End User guest post by Ratnadeep Debnath, Site Reliability Engineer at Zapier At Zapier, RabbitMQ is at the heart of Zap processing. We enqueue messages to RabbitMQ for each step in a Zap. These messages get consumed by…


Discover how GitLab uses Falco to detect abnormal behavior in code dependencies

Posted on December 10, 2021

Project post originally published on the Falco Blog by Nate Magee and Vicente J. Jiménez Miras GitLab leverages Falco to detect software supply chain attacks with Package Hunter GitLab covers the entire software development lifecycle in a single application:…


Flux December 2021 update

Posted on December 7, 2021 | By Daniel Holbach

Guest post originally published on Flux’s blog by Daniel Holbach As the Flux family of projects and its communities are growing, we strive to inform you each month about what has already landed, new possibilities which are available…


Kubernetes main attack vectors tree: an explainer guide

Posted on November 24, 2021 | By Andrew Zola

Guest post originally published on Magalix’s blog by Andrew Zola Kubernetes is a leader in container orchestration. According to Statista, as much as 46% of respondents in a recent survey stated that they used Kubernetes for automating computer application…


Containerization on the edge

Posted on November 11, 2021 | By Second State and FutureWei

Guest post by Second State and FutureWei This work is supported by Second State and FutureWei based on Open Source projects WasmEdge and seL4. Application containers, such as Docker, are a key driving force behind the growth of…