Search results for: security


The cost of ignoring security champions: a cautionary tale for application security culture

Posted on May 31, 2023

Community post by Rodrigo Maues Rocha, Tech Lead Consulting at Conviso Application Security Nowadays, where software development is more complex and dynamic than ever, ensuring application security is crucial. However, knowing where to begin can be…




Ant Group security technology’s Nydus and Dragonfly image acceleration practices

Posted on May 1, 2023

Guest post by Dragonfly maintainers Introduction ZOLOZ is a global security and risk management platform under Ant Group. Through biometric, big data analysis, and artificial intelligence technologies, ZOLOZ provides safe and convenient security and risk management…


CNCF On demand webinar: How to Secure your Services with Kalix Security

Posted on April 27, 2023

How to Secure your Services with Kalix Security


Argo CD end user threat model: security considerations for hardening declarative GitOps CD on Kubernetes

Posted on April 21, 2023 | Andres Vega + Michael Crenshaw

Community post by Andres Vega from ControlPlane and Michael Crenshaw from Argo CD Argo CD provides deployment flexibility, which enables operators to configure it to varying situations. The new report by ControlPlane provides a comprehensive threat…


SDxCentral: “How Ikea, The New York Times and Bloomberg use open source for cloud native networking and security”

Posted on April 20, 2023

There is no shortage of approaches to securely connecting different services in the cloud. For a growing number of organizations the best approach is to use the open source Cilium technology.


CNCF On-Demand Webinar: Containerization 102: Security, Optimization and Speed

Posted on April 20, 2023

Containers and Microservices are now the primary platform for many organizations, but complexity and adoptions continue to be a challenge. This month we are discussing security concerns through the lens of the platform and network because…


New Kubernetes security audit complete and open sourced

Posted on April 19, 2023

By Chris Aniszczyk (@cra) and Rey Lejano In 2018, the Cloud Native Computing Foundation (CNCF) started performing and open sourcing third-party security audits with the goal of improving the overall security practices of our ecosystem. Since…


CNCF fuzzing open source projects for security and reliability

Posted on April 18, 2023

By Chris Aniszczyk, Adam Korczynski, David Korczynski Introduction In this blog post we will present an overview of the state of fuzzing CNCF projects. We published a blog post on this in June 2022 titled Improving…