2022-07-06 11:32:00 【programmer_ada】
"CNCF TOC成员和项目发起人Justin Cormack说:"供应链安全是当今软件生态系统面临的最大挑战之一。"一个典型的软件供应链是由多个步骤 "串联 "而成的,包括编写、测试、打包和分发软件。更多的步骤意味着一个组织可能会有更多的漏洞。in-toto通过提供安全和可信的方式来代表和证明云原生管道中的所有操作来解决这个问题。我们看到了社区对此的强烈支持。"
在过去的三年里,in-toto团队一直专注于通过增加或修改功能来实现稳定性,包括支持SPIFFE、更具表现力的证据收集和不同语言的实现,如Rust。该项目还被整合到重要的安全应用中,如Reproducible Builds和Sigstore。
in-toto已经被包括Datadog、Google Grafeas、Kubesec.io、rebuilderd、SolarWinds、Sigstore的Cosign等组织在生产中采用。Datadog用它来保护他们的管道,SolarWinds用它来避免未来出现与2019年SUNBURST黑客事件同样规模的泄露。此外,像rebuilderd这样的项目产生了in-toto attestations,以便进行可加密验证的构建-重现性检查。最后,Sigstore的一部分cosign等项目使用in-toto作为底层技术来证明各种供应链行为。事实上,in-toto是sigstore上第二大使用机制。
- 500多个GitHub星级
- 700个拉动请求
- 194个问题
- 45个贡献者
- 32个发布
"云原生计算基金会首席技术官Chris Aniszczyk说:"在过去的几年里,我们看到整个软件供应链的攻击频率和严重程度都在增加,甚至白宫最近也发布了一项行政命令。"我们很高兴有一个项目在供应链安全领域提供创新,我们期待着看到社区之间的合作,继续使云原生生态系统更加安全。"
自2020年发布1.0以来,in-toto一直专注于为现有的集成提供稳定性。在未来的一年里,该团队计划增加令人振奋的新功能,包括在证据收集期间支持表达式类型跟踪,对SLSA证明处理提供更好的本地支持,以及更简单的政策语言,以及 "最佳供应链实践 "政策的集合,以方便希望确保其供应链的项目采用。请阅读项目路线图中的更多内容。
作为一个CNCF托管的项目,in-toto是一个与它的技术利益相一致的中立基金会的一部分,也是更大的Linux基金会的一部分,后者提供管理、营销支持和社区推广。in-toto加入了孵化技术Argo, Buildpacks, Chaos Mesh, CIlium, CloudEvents, CNI, Contour, Cortex, CRI-O, Crossplane, Dapr, Dragonfly, emissary-ingress, Falco, Flagger, Flux, gRPC, KEDA, Knative, KubeEdge, Litmus, Longhorn, NATS, Notary, OpenMetrics, OpenTelemetry, Operator Framework, SPIFFE, SPIRE, and Thanos。关于每个级别的成熟度要求的更多信息,请访问CNCF的毕业标准。
- map的使用(列表的数据赋值到表单,json逗号隔开显示赋值)
- tensorflow和torch代码验证cuda是否安装成功
- Elastic search indexes are often deleted [closed] - elastic search indexes gets deleted frequently [closed]
- How to type multiple spaces when editing CSDN articles
- spark基础-scala
- R语言使用dt函数生成t分布密度函数数据、使用plot函数可视化t分布密度函数数据(t Distribution)
- Based on butterfly species recognition
- 受益匪浅,安卓面试问题
- ModuleNotFoundError: No module named ‘PIL‘解决方法
- [pytorch] yolov5 train your own data set
Actf 2022 came to a successful conclusion, and 0ops team won the second consecutive championship!!
It's super detailed in history. It's too late for you to read this information if you want to find a job
Sanmian ant financial successfully got the offer, and has experience in Android development agency recruitment and interview
Reflection and illegalaccessexception exception during application
Solution of intelligent management platform for suppliers in hardware and electromechanical industry: optimize supply chain management and drive enterprise performance growth
Druid database connection pool details
Based on butterfly species recognition
Airiot IOT platform enables the container industry to build [welding station information monitoring system]
USB host driver - UVC swap
ZABBIX proxy server and ZABBIX SNMP monitoring
JDBC details
Abstract classes and abstract methods
short i =1; I=i+1 and short i=1; Difference of i+=1
Druid database connection pool details
Fast power template for inverse element, the role of inverse element and example [the 20th summer competition of Shanghai University Programming League] permutation counting
10 schemes to ensure interface data security
Don't miss this underestimated movie because of controversy!
Problems encountered in using RT thread component fish
swagger2报错Illegal DefaultValue null for parameter type integer
【pytorch】yolov5 训练自己的数据集
A full set of teaching materials, real questions of Android interview of 7 major manufacturers including Alibaba Kwai pinduoduo
Reflection and illegalaccessexception exception during application
About static type, dynamic type, ID, instancetype
Synchronous development of business and application: strategic suggestions for application modernization
In depth analysis, Android interview real problem analysis is popular all over the network