Search results for: in-toto


Our trip to KubeCon + CloudNativeCon Valencia 2022, day by day

Posted on June 14, 2022 | By Giulio Roggero

Guest post originally published on the Mia-Platform blog by Giulio Roggero, CTO, Mia-Platform We live in an ever‑changing world where technology plays a key role in evolution. The ultimate expression of this concept is KubeCon Valencia, the flagship event…


KubeVirt becomes a CNCF incubating project

Posted on April 19, 2022

The CNCF Technical Oversight Committee (TOC) has voted to accept KubeVirt as a CNCF incubating project.  KubeVirt enables users to run virtual machine workloads on top of Kubernetes in a Kubernetes-native way. It allows the migration of legacy…


A MAP for Kubernetes supply chain security

Posted on April 12, 2022 | By Jim Bugwadia

Guest post originally published on the Nirmata blog by Jim Bugwadia The sharp increase in software supply chain attacks has made securing the build and delivery of software a critical topic. But what does this mean for Kubernetes…


Cloud Native Batch System Volcano moves to the CNCF Incubator

Posted on April 7, 2022

The CNCF Technical Oversight Committee (TOC) has voted to accept Volcano as a CNCF incubating project.  Volcano is a cloud native batch system and CNCF’s first batch computing project. It is developed to extend cloud native from micro…


Trusting SBOMs in the software supply chain: Syft now creates attestations using Sigstore

Posted on March 30, 2022

Guest post originally published on the Anchore blog by Dan Luhring With the recent release of Syft v0.40.0, you can now create signed SBOM attestations directly in Syft. This is made possible by Project Sigstore, which makes signing and verification…


Backstage project joins the CNCF Incubator

Posted on March 15, 2022

The CNCF Technical Oversight Committee (TOC) has voted to accept Backstage as a CNCF incubating project.  Backstage is an open platform for building developer portals maintained by a global community. It unifies an organization’s tooling, services, apps, data,…


16 CNCF interns graduated from Google Summer of Code (GSoC) 2021!

Posted on November 1, 2021

In its fifth year participating in Google Summer of Code (GSoC), CNCF is excited to announce 16 interns have graduated from the program after working with the Foundation’s projects. Interns this year contributed to Graduated, Incubating and Sandbox…


Secure software supply chains: good practices, at scale

Posted on October 27, 2021 | By Dan Chernoff

Guest post originally published on Contino Engineering‘s blog by Dan Chernoff Supply chain attacks rose by 42% in the first quarter of 2021 [1] and are becoming even more prevalent [2]. In response to secure software supply chain…


Welcome to Pluto, the place to start with open source development

Posted on October 26, 2021 | By Robert Brennan

Guest post originally published on Fairwind’s blog by Robert Brennan, Fairwinds Hello from Pluto, the little planet with big open source value. Once considered a full-size sphere in the cosmos, Pluto was downgraded to a dwarf planet in…


CNCF paper defines best practices for supply chain security

Posted on May 14, 2021

New paper demonstrates an actionable approach to architecting a secure supply chain amidst an increase in cyber attacks SAN FRANCISCO, Calif. – May 14, 2021 – The Cloud Native Computing Foundation® (CNCF®), which builds sustainable ecosystems for cloud…