Search results for: security


Enforcing Artifact Security with Trivy and OPA

Posted on May 1, 2025 | Nigel Douglas, Cloudsmith

In cloud-native development, ensuring the integrity and security of software artifacts (such as Docker images, Python wheels, and Helm charts) is a fundamental challenge. With the growing adoption of continuous integration and delivery pipelines, there’s a…


ITOps Times: “CNCF announces graduation of in-toto security framework for software supply chain integrity”

Posted on April 25, 2025

The Cloud Native Computing Foundation (CNCF) today announced the graduation of in-toto, a software supply chain security framework developed at the NYU Tandon School of Engineering.


The New Stack: “Kubernetes v1.33 Advances in AI, Security and the Enterprise”

Posted on April 24, 2025

Kubernetes 1.33 brought the maintainer wizardry, with fresh namespace support, native sidecars and dedicated resource allocation for GPUs and TPUs.


TFIR: “Kubernetes v1.33: Faster Networking, Better Security”

Posted on April 24, 2025

Named after the magical color from Terry Pratchett’s Discworld, v1.33 celebrates the open source spirit and collaboration that power Kubernetes.


CNCF Announces Graduation of in-toto Security Framework, Enhancing Software Supply Chain Integrity Across Industries

Posted on April 23, 2025

NYU Tandon-developed software security framework achieves highest CNCF maturity level, combating rising software supply chain attacks SAN FRANCISCO, CA, April 23, 2025 – The Cloud Native Computing Foundation® (CNCF®), which builds sustainable ecosystems for cloud native…


Istio publishes results of ztunnel security audit

Posted on April 23, 2025 | Craig Box - Solo.io, for the Istio Product Security Working Group

Passes with flying colors Istio’s ambient mode splits the service mesh into two distinct layers: Layer 7 processing (the “waypoint proxy”), which remains powered by the traditional Envoy proxy; and a secure overlay (the “zero-trust tunnel”…


SD Time: “Report: Security is no longer the top challenge in cloud native environments”

Posted on April 1, 2025

Security used to be the biggest challenge companies implementing cloud native technologies faced, but according to a new report from the Cloud Native Computing Foundation (CNCF), that is no longer the case.


Cloud Native Computing Foundation Announces Argo CD v3 Update to Enhance Scalability and Security for Kubernetes

Posted on April 1, 2025

Latest release boosts automation, performance, and security for Kubernetes-native GitOps KubeCon + CloudNativeCon Europe, London, UK – April 1, 2025 – The Cloud Native Computing Foundation® (CNCF®), which builds sustainable ecosystems for cloud native software, today…


Istio: The Highest-Performance Solution for Network Security

Posted on March 27, 2025 | John Howard, Solo.io

Ambient mode provides more encrypted throughput than any other project in the Kubernetes ecosystem. Encryption in transit is a baseline requirement for almost all Kubernetes environments today, and forms the foundation of a zero-trust security posture….


Cloud Native Live: Optimizing cost, performance, and security in Kubernetes with policy-as-code

Posted on March 25, 2025

Kubernetes gives teams flexibility, but without the proper guardrails, costs soar, performance suffers, and security risks increase. In this webinar, Anusha & Sachin will explore how teams can enforce cost-efficient, high-performance, and secure Kubernetes operations with…