Search results for: security audit


Ada Logics: CRI-O holistic security audit engagement

Posted on June 6, 2022 | By David Korczynski + Adam Korczynski

Community post originally on the Ada Logics blog by David Korczynski, Security Research & Security Engineering and Adam Korczynski, Security Engineering & Security Automation, Ada Logics Ada Logics Ltd. recently performed a holistic security audit of CRI-O. CRI-O is…


Flux Security Audit has concluded

Posted on November 11, 2021

Project post cross-posted from the Flux blog As Flux is an Incubation project within the Cloud Native Computing Foundation, we were graciously granted a sponsored audit. The primary aim was to assess Flux’s fundamental security posture and to…


Open sourcing the SPIFFE/SPIRE security audit

Posted on August 17, 2021

A few years back, CNCF began performing and open sourcing third-party security audits for projects to improve the overall security of our ecosystem. These audits have helped identify security issues, from general weaknesses to critical vulnerabilities, and given…


ContainerJournal: "The CNCF etcd project reaches a significant milestone with completion of security audit"

Posted on August 5, 2020

This week, a third-party security audit was published on etcd, the open source distributed key-value store that plays a crucial role in scaling Kubernetes in the cloud. For etcd, this audit was important in multiple ways. The audit…


Open sourcing the etcd Security Audit

Posted on August 5, 2020

Guest post from Sahdev Zala and Xiang Li, maintainers for etcd We are proud to announce that the etcd team has successfully completed a 3rd party security audit for the etcd latest major release 3.4. The third party…


Kubernetes security controls and enforcement: applying lessons from the K8s security audit

Posted on October 17, 2019

The recent Kubernetes security audit and the issues it identified got lots of publicity. But did you know that the audit reports also include many recommendations you can apply today to improve your security posture? On this webinar,…


Security Boulevard: "CNCF-led open source Kubernetes security audit reveals 37 flaws in Kubernetes cluster; recommendations proposed"

Posted on August 9, 2019

Last year, the Cloud Native Computing Foundation (CNCF) initiated a process of conducting third-party security audits for its own projects. The aim of these security audits was to improve the overall security of the CNCF ecosystem.


EnterpriseAI: "Kubernetes gets a security audit"

Posted on August 9, 2019

An open source group is expanding its third-party security audits to include the popular but vulnerable Kubernetes cluster orchestrator.


ZDNet: "Kubernetes reports the results of its open-source security audit"

Posted on August 8, 2019

All programs need security audits, but the Cloud Native Computing Foundation (CNCF) took a new open-source approach and revealed all to its users.


The New Stack: "CNCF open sources security audit of core Kubernetes components"

Posted on August 6, 2019

This week, the Cloud Native Computing Foundation (CNCF) has released the final results of a two-month-long, third-party security audit of eight core Kubernetes components, uncovering a variety of vulnerabilities.