Project post originally published on the Knative blog by Adam Korczynski, Ada Logics Knative is happy to announce the completion of its fuzzing security audit. The audit was carried out by Ada Logics and is part of…
PodSecurityPolicy migration with Kyverno
Project post originally published on the Kyverno blog As you’ve probably heard, PodSecurityPolicy (PSP) in Kubernetes is no more. After a deprecation beginning in v1.21, they were finally removed in v1.25. Many organizations out there are still relying…
Community post by Adam Korczynski, ADA Logics The Dapr project is happy to announce the completion of their fuzzing audit which added 39 fuzzers covering Dapr Runtime, Kit, and Components-Contrib. The audit is part of an…
Service account 101: the power of M2M with security in mind
Guest post originally published on Mia-Platform’s blog by Giovanna Monti, Full Stack Developer Specialist at Mia‑Platform Service accounts are an essential component of many IT environments, allowing applications and services to access various resources without requiring…
CNCF fuzzing open source projects for security and reliability
By Chris Aniszczyk, Adam Korczynski, David Korczynski Introduction In this blog post we will present an overview of the state of fuzzing CNCF projects. We published a blog post on this in June 2022 titled Improving…
containerd completes fuzzing audit
Community post by Adam Korczynski and Phil Estes The containerd project is happy to announce the completion of a comprehensive fuzzing audit which added 28 fuzzers covering a wide range of container runtime functionality. During this…
Notes from CloudNativeSecurityCon 2023
Guest post originally published on the Nirmata blog by Jim Bugwadia The Cloud Native Computing Foundation (CNCF) held the first ever standalone Cloud Native Security Conference in Seattle on February 1st and 2nd. Here are some…
Results of the KEDA security engagement
Community post by Amir Montazery, OSTIF, cross-posted from OSTIF’s blog KEDA, or the Kubernetes-based Event Driven Autoscaling project, was reviewed by Trail of Bits at the end of 2022. KEDA joins a growing list of CNCF…
CloudNativeSecurityCon 2023: 3 key areas to watch
If the past couple of years taught us anything, it’s the importance of security in cloud native and open source environments. The fallout of vulnerabilities like Log4j even reached the U.S. Federal Government with the Executive…
The Cutting Edge Schedule for CloudNativeSecurityCon 2023 is Now Available
First-time standalone conference will highlight cloud native security projects and best practices for handling the security challenges organizations are facing today SAN FRANCISCO, Calif. – December 14, 2022 – The Cloud Native Computing Foundation® (CNCF®), which…