Enforcing image trust on Docker containers using Notary
Guest post originally posted on the Infracloud blog by Frederick Fernando Why worry about software supply chain security? In the past few years, we have seen attacks such as NotPetya and Sunburst, which has shifted the industry’s focus to…
SDxCentral: "CNCF’s latest projects TUF and Notary aimed at security"
The Cloud Native Computing Foundation (CNCF) filled in a missing security component with the inclusion of two new projects under its open source guidance. The CNCF Technical Oversight Committee voted in the security-focused Notary and The…
eWeek: "CNCF brings In Notary, The Update Framework to boost container security"
The Cloud Native Computing Foundation on Oct. 24 announced that it is expanding its project roster with the addition of the Notary container trust project and The Update Framework security effort.
The New Stack: "CNCF brings security to the cloud native stack with Notary, TUF adoption"
The Cloud Native Computing Foundation continues to vigorously build its portfolio of open source cloud-native technologies. CNCF’s Technical Oversight Committee voted to accept both the Docker-developed Notary trusted content framework and the specification Notary was built…
CNCF to host two security projects – Notary and TUF specification
Riyaz Faizullabhoy, Docker Security Engineer, today announced on stage at Open Source Summit Europe, that the Cloud Native Computing Foundation (CNCF) Technical Oversight Committee (TOC) has voted Notary in as our 13th hosted project and TUF…
Shadow AI in CI/CD: Threat-modeling the path from developer laptop to Kubernetes
Artificial intelligence is becoming part of daily software delivery, often before it becomes part of the security architecture. That gap has a name: Shadow AI. It is any AI tool, model, agent, extension, or integration used…
K8gb becomes a CNCF incubating project
The CNCF Technical Oversight Committee (TOC) has voted to accept Kubernetes Global Balancer (K8gb) as a CNCF incubating project. About K8gb K8gb is an open source, cloud native Global Server Load Balancing (GSLB) solution designed specifically…
Runtime Supply Chain Verification using the Node Resource Interface (NRI)
The widely used container supply chain verification tools today operate at the Kubernetes API layer as admission webhooks (such as Kyverno, OPA Gatekeeper, and Sigstore Policy Controller). They intercept pod creation, check signatures and attestations, and…
Confidential Containers becomes a CNCF incubating project
The CNCF Technical Oversight Committee (TOC) has voted to accept Confidential Containers as a CNCF incubating project. About Confidential Containers Confidential Containers addresses the need to protect data in use within cloud native environments. While data…
HAMi becomes a CNCF incubating project
The CNCF Technical Oversight Committee (TOC) has voted to accept HAMi as a CNCF incubating project. About HAMi Modern AI infrastructure teams run into the same problem over and over: expensive GPUs often sit fragmented and…