当前位置:网站首页>[translation] supply chain security project in toto moved to CNCF incubator
[translation] supply chain security project in toto moved to CNCF incubator
2022-07-06 19:29:00 【programmer_ ada】
CNCF Technical Supervision Committee (TOC) Have voted to accept in-toto As CNCF The incubation program of .
in-toto It is a framework to protect the software supply chain by collecting and verifying relevant data . It enables libraries to collect information about software supply chain behavior , And allow software consumers and project managers to publish information about software supply chain practices policy , To verify before deploying or installing the software . In short , It helps capture What happens in the software supply chain , And ensure It happens according to defined policies .
in-toto The project was carried out by the Safety Systems Laboratory of the tanton School of engineering, New York University in 2015 Created in . From then on , It has been developing , To better adapt to the practices of different software ecosystems , And better integrate with other cloud technologies , Such as SPIFFE and SPIRE. Because a chain is only strong in its weakest link , The project still has enough plasticity , To protect every aspect of the software supply chain -- From source code to Kubernetes Admission in clusters and other aspects .
"CNCF TOC Members and project sponsors Justin Cormack say :" Supply chain security is one of the biggest challenges facing today's software ecosystem ." A typical software supply chain consists of many steps " Series connection " Formed , Including writing 、 test 、 Package and distribute software . More steps mean that an organization may have more vulnerabilities .in-toto Solve this problem by providing a safe and trusted way to represent and prove all operations in the cloud native pipeline . We see strong support from the community ."
since 2019 To join in CNCF Since sandbox ,in-toto already , Attracted from 16 Add more than... From different organizations 132 Name contributor , Now there are from 5 Organized 8 Maintainers and approvers .
In the past three years ,in-toto The team has been focusing on achieving stability by adding or modifying functions , Including support SPIFFE、 More expressive evidence collection and implementation in different languages , Such as Rust. The project is also integrated into important security applications , Such as Reproducible Builds and Sigstore.
in-toto Has been included Datadog、Google Grafeas、Kubesec.io、rebuilderd、SolarWinds、Sigstore Of Cosign And other organizations adopt .Datadog Use it to protect their The Conduit ,SolarWinds Use it to avoid future emergence and 2019 year SUNBURST The same scale of the hacker incident . Besides , image rebuilderd Such projects have produced in-toto attestations, In order to build encrypted authentication - Reproducibility check . Last ,Sigstore Part of cosign Wait for the project to use in-toto As the underlying technology to prove various supply chain behaviors . in fact ,in-toto yes sigstore On The second use mechanism .
in-toto And the first to pass CNCF Of TAG Safety assessment items .
Significant milestones .
- 500 Multiple GitHub The star
- 700 Pull request
- 194 A question
- 45 Contributors
- 32 Releases
" Chief technology officer of cloud native Computing Foundation Chris Aniszczyk say :" In the past few years , We see that the attack frequency and severity of the entire software supply chain are increasing , Even the White House recently issued an executive order ." We are pleased to have a project that provides innovation in the field of supply chain security , We look forward to seeing cooperation between communities , Continue to make the cloud native ecosystem more secure ."
since 2020 Released in 1.0 since ,in-toto Has been focused on providing stability for existing integrations . In the coming year , The team plans to add exciting new features , Including support for expression type tracking during evidence collection , Yes SLSA Proof processing provides better local support , And simpler policy language , as well as " Best supply chain practices " A collection of policies , In order to facilitate the project that wants to ensure its supply chain to adopt . Please read the item The roadmap More in .
As a CNCF Managed projects ,in-toto It is part of a neutral foundation consistent with its technical interests , It's also bigger Linux Part of the foundation , The latter provides management 、 Marketing support and community promotion .in-toto Added incubation Technology Argo, Buildpacks, Chaos Mesh, CIlium, CloudEvents, CNI, Contour, Cortex, CRI-O, Crossplane, Dapr, Dragonfly, emissary-ingress, Falco, Flagger, Flux, gRPC, KEDA, Knative, KubeEdge, Litmus, Longhorn, NATS, Notary, OpenMetrics, OpenTelemetry, Operator Framework, SPIFFE, SPIRE, and Thanos. More information about maturity requirements at each level , Please visit CNCF Graduation criteria .
边栏推荐
- Simple understanding of MySQL database
- Php+redis realizes the function of canceling orders over time
- JDBC details
- 谷粒商城--分布式高级篇P129~P339(完结)
- MRO工业品企业采购系统:如何精细化采购协同管理?想要升级的工业品企业必看!
- Based on butterfly species recognition
- Mysql Information Schema 学习(一)--通用表
- Documents to be used in IC design process
- Mind map + source code + Notes + project, ByteDance + JD +360+ Netease interview question sorting
- C # - realize serialization with Marshall class
猜你喜欢
Xingnuochi technology's IPO was terminated: it was planned to raise 350million yuan, with an annual revenue of 367million yuan
Mathematical knowledge -- code implementation of Gaussian elimination (elementary line transformation to solve equations)
利用 clip-path 绘制不规则的图形
Simple understanding of MySQL database
史上超级详细,想找工作的你还不看这份资料就晚了
Reflection and illegalaccessexception exception during application
Mysql Information Schema 学习(一)--通用表
打家劫舍III[后序遍历与回溯+动态规划]
Problems encountered in using RT thread component fish
ROS custom message publishing subscription example
随机推荐
Application of clock wheel in RPC
PMP每日一练 | 考试不迷路-7.6
Mind map + source code + Notes + project, ByteDance + JD +360+ Netease interview question sorting
关于图像的读取及处理等
short i =1; I=i+1 and short i=1; Difference of i+=1
Yutai micro rushes to the scientific innovation board: Huawei and Xiaomi fund are shareholders to raise 1.3 billion
Tensorflow2.0 自定义训练的方式求解函数系数
It's super detailed in history. It's too late for you to read this information if you want to find a job
驼峰式与下划线命名规则(Camel case With hungarian notation)
Mysql Information Schema 学习(一)--通用表
[pytorch] yolov5 train your own data set
R language ggplot2 visual time series histogram: visual time series histogram through two-color gradient color matching color theme
黑马--Redis篇
【翻译】供应链安全项目in-toto移至CNCF孵化器
USB host driver - UVC swap
Low CPU load and high loadavg processing method
map的使用(列表的数据赋值到表单,json逗号隔开显示赋值)
包装行业商业供应链管理平台解决方案:布局智慧供应体系,数字化整合包装行业供应链
Simple application of VBA script in Excel
Yyds dry goods inventory leetcode question set 751 - 760