InfoQ: “Software Supply Chain Security Project in-toto Accepted into CNCF Incubator”
The CNCF Technical Oversight Committee (TOC) has accepted the in-toto project as a CNCF incubating project. The in-toto project aims to cryptographically protect the entire software build and delivery process – the “supply chain” – from…
Flux Security: More confidence through fuzzing
Project post originally published in the Flux blog by Daniel Holbach Next up in our blog series about Flux Security is how we implemented fuzzing in Flux and its controllers and how that makes things safer…
Supply chain security project in-toto moves to the CNCF Incubator
The CNCF Technical Oversight Committee (TOC) has voted to accept in-toto as a CNCF incubating project. in-toto is a framework that protects the software supply chain by collecting and verifying relevant data. It does so by…
CNCF Live Webinar: Desktop to Deployment K8s Security with Checkov
Shift left blah blah blah… Sounds like more work for developers and less for security right? Well, yeah it is but not that much. It is akin to the proverb of “many hands make light security…
Argo security automation with OSS-Fuzz
Project post originally published on the Argo blog by Yuan Tang (Akuity), Adam Korczynski and David Korczynski (Ada Logics), Jann Fischer (Red Hat), Henrik Blixt (Intuit) Security is a key priority for the Argo project. In an effort to improve security, the Argo…
Flux Security: Image Provenance
Guest post originally published on Flux’s blog by Daniel Holbach Next up in our blog series about Flux Security is how and why we use signatures for the Flux CLI and all its controller images and…
Project post originally published on Flux’s blog by Daniel Holbach Flux – built with security in mind You don’t get to re-architect a successful project very often, but we did about two years ago. The Flux…
Kubernetes security best practices: definitive guide
Guest post originally published on ARMO’s blog by Jonathan Kaftzan, VP Marketing & Business Development at ARMO Introduction Kubernetes, an open-source microservice orchestration engine, is well known for its ability to automate the deployment, management, and,…
CNCF End User Lounge: Salt Security
In 2020, Salt Security started to grow quickly and our platform needed to scale fast. That led to a few challenges including backward compatibility issues. To address that we moved to gRPC but, since load balancing…
Hunting API traffic anomalies with minimal downtime The Salt Security platform delivers the simplest, most comprehensive, and most effective API security by tapping AI and big data. The platform works by continuously monitoring and learning from…