Search results for: security audit


Cloud Native Computing Foundation Announces Cilium Graduation

Posted on October 11, 2023

eBPF-powered tool has been adopted by well over 100 organizations SAN FRANCISCO, Calif. – October 11, 2023 – The Cloud Native Computing Foundation® (CNCF®), which builds sustainable ecosystems for cloud native software, today announced the graduation of Cilium….


Trip.com Group

Posted on September 13, 2023

Switching To Cilium For Scalable and Cloud Native Networking Trip.com Group Limited, a multinational travel service conglomerate, serves customers in over 40 languages and 200 countries. Their operations are supported by a vast IT infrastructure, with Kubernetes clusters…


Notary Project announces a major release!

Posted on August 28, 2023 | By Notary Project Release Team

Project post originally published on the Notary Project blog by the Notary Project Release Team The Notary Project maintainers are proud to announce a major release, including Notary Project specifications v1.0.0, notation v1.0.0, notation-go v1.0.0, and notation-core-go v1.0.0 which are ready for production…


Cloud Native Computing Foundation Announces Graduation of Kubernetes Autoscaler KEDA

Posted on August 22, 2023

The event-driven autoscaler is now used in production by more than 45 organizations, including FedEx, Grafana Labs, KPMG, Reddit, and Xbox SAN FRANCISCO, Calif. – August 22, 2023 – The Cloud Native Computing Foundation® (CNCF®), which builds sustainable…


Cloud Native Computing Foundation Announces Graduation of CRI-O

Posted on July 19, 2023

The Kubernetes Container Runtime provides users with a simple, clear, and performant container manager for cloud native workloads  SAN FRANCISCO, Calif. – July 19, 2023 – The Cloud Native Computing Foundation® (CNCF®), which builds sustainable ecosystems for cloud…


Building secure software supply chains in CNCF with SLSA assessments

Posted on April 19, 2023

To continue efforts to improve the security of our graduated and incubating projects, we recently worked with Chainguard to assess the software supply chain security practices of two of our graduated projects, Argo and Prometheus. These efforts build…


Flux: March 2023 Update

Posted on April 14, 2023

Project post originally published on the Flux blog by Daniel Holbach As the Flux family of projects and its communities are growing, we strive to inform you each month about what has already landed, new possibilities which are…


An overview of the CNCF and OSTIF impact report for the second half of 2022 and early 2023

Posted on March 13, 2023 | By Chris Aniszczyk + Amir Montazery 

By Chris Aniszczyk and Amir Montazery  CNCF and Open Source Technology Improvement Fund (OSTIF) have been working together for the last several years to conduct security audits for CNCF’s Graduated and Incubating projects. As a result of CNCF’s…


KubeEdge! CNCF’s First SLSA 3 Project

Posted on February 27, 2023 | By KubeEdge SIG-Security

Community post by KubeEdge SIG-Security (Reprinted from the KubeEdge blog) In July 2022, the KubeEdge community completed a third-party security audit of KubeEdge[2] and released a paper on cloud native edge computing security threat analysis and protection. Based…


Cloud DevSecOps: what it is, benefits and tools

Posted on February 27, 2023 | By SparkFabrik

Guest post originally published on the SparkFabrik blog If you are familiar with the DevOps philosophy, you will certainly have heard of DevSecOps. It is an approach to security that is gaining momentum in line with the growing…