当前位置:网站首页>[translation] supply chain security project in toto moved to CNCF incubator
[translation] supply chain security project in toto moved to CNCF incubator
2022-07-06 19:29:00 【programmer_ ada】
CNCF Technical Supervision Committee (TOC) Have voted to accept in-toto As CNCF The incubation program of .
in-toto It is a framework to protect the software supply chain by collecting and verifying relevant data . It enables libraries to collect information about software supply chain behavior , And allow software consumers and project managers to publish information about software supply chain practices policy , To verify before deploying or installing the software . In short , It helps capture What happens in the software supply chain , And ensure It happens according to defined policies .
in-toto The project was carried out by the Safety Systems Laboratory of the tanton School of engineering, New York University in 2015 Created in . From then on , It has been developing , To better adapt to the practices of different software ecosystems , And better integrate with other cloud technologies , Such as SPIFFE and SPIRE. Because a chain is only strong in its weakest link , The project still has enough plasticity , To protect every aspect of the software supply chain -- From source code to Kubernetes Admission in clusters and other aspects .
"CNCF TOC Members and project sponsors Justin Cormack say :" Supply chain security is one of the biggest challenges facing today's software ecosystem ." A typical software supply chain consists of many steps " Series connection " Formed , Including writing 、 test 、 Package and distribute software . More steps mean that an organization may have more vulnerabilities .in-toto Solve this problem by providing a safe and trusted way to represent and prove all operations in the cloud native pipeline . We see strong support from the community ."
since 2019 To join in CNCF Since sandbox ,in-toto already , Attracted from 16 Add more than... From different organizations 132 Name contributor , Now there are from 5 Organized 8 Maintainers and approvers .
In the past three years ,in-toto The team has been focusing on achieving stability by adding or modifying functions , Including support SPIFFE、 More expressive evidence collection and implementation in different languages , Such as Rust. The project is also integrated into important security applications , Such as Reproducible Builds and Sigstore.
in-toto Has been included Datadog、Google Grafeas、Kubesec.io、rebuilderd、SolarWinds、Sigstore Of Cosign And other organizations adopt .Datadog Use it to protect their The Conduit ,SolarWinds Use it to avoid future emergence and 2019 year SUNBURST The same scale of the hacker incident . Besides , image rebuilderd Such projects have produced in-toto attestations, In order to build encrypted authentication - Reproducibility check . Last ,Sigstore Part of cosign Wait for the project to use in-toto As the underlying technology to prove various supply chain behaviors . in fact ,in-toto yes sigstore On The second use mechanism .
in-toto And the first to pass CNCF Of TAG Safety assessment items .
Significant milestones .
- 500 Multiple GitHub The star
- 700 Pull request
- 194 A question
- 45 Contributors
- 32 Releases
" Chief technology officer of cloud native Computing Foundation Chris Aniszczyk say :" In the past few years , We see that the attack frequency and severity of the entire software supply chain are increasing , Even the White House recently issued an executive order ." We are pleased to have a project that provides innovation in the field of supply chain security , We look forward to seeing cooperation between communities , Continue to make the cloud native ecosystem more secure ."
since 2020 Released in 1.0 since ,in-toto Has been focused on providing stability for existing integrations . In the coming year , The team plans to add exciting new features , Including support for expression type tracking during evidence collection , Yes SLSA Proof processing provides better local support , And simpler policy language , as well as " Best supply chain practices " A collection of policies , In order to facilitate the project that wants to ensure its supply chain to adopt . Please read the item The roadmap More in .
As a CNCF Managed projects ,in-toto It is part of a neutral foundation consistent with its technical interests , It's also bigger Linux Part of the foundation , The latter provides management 、 Marketing support and community promotion .in-toto Added incubation Technology Argo, Buildpacks, Chaos Mesh, CIlium, CloudEvents, CNI, Contour, Cortex, CRI-O, Crossplane, Dapr, Dragonfly, emissary-ingress, Falco, Flagger, Flux, gRPC, KEDA, Knative, KubeEdge, Litmus, Longhorn, NATS, Notary, OpenMetrics, OpenTelemetry, Operator Framework, SPIFFE, SPIRE, and Thanos. More information about maturity requirements at each level , Please visit CNCF Graduation criteria .
边栏推荐
- Actf 2022 came to a successful conclusion, and 0ops team won the second consecutive championship!!
- Lick the dog until the last one has nothing (simple DP)
- Benefit a lot, Android interview questions
- R language uses DT function to generate t-distribution density function data and plot function to visualize t-distribution density function data
- 学习探索-无缝轮播图
- 五金机电行业供应商智慧管理平台解决方案:优化供应链管理,带动企业业绩增长
- Reflection and illegalaccessexception exception during application
- Problems encountered in using RT thread component fish
- How can my Haskell program or library find its version number- How can my Haskell program or library find its version number?
- Lucun smart sprint technology innovation board: annual revenue of 400million, proposed to raise 700million
猜你喜欢
Black Horse - - Redis Chapter
Tongyu Xincai rushes to Shenzhen Stock Exchange: the annual revenue is 947million Zhang Chi and Su Shiguo are the actual controllers
JDBC details
Application of clock wheel in RPC
php+redis实现超时取消订单功能
通俗的讲解,带你入门协程
In depth analysis, Android interview real problem analysis is popular all over the network
【翻译】云原生观察能力微调查。普罗米修斯引领潮流,但要了解系统的健康状况仍有障碍...
Spark foundation -scala
谷粒商城--分布式高级篇P129~P339(完结)
随机推荐
How to access localhost:8000 by mobile phone
思维导图+源代码+笔记+项目,字节跳动+京东+360+网易面试题整理
冒烟测试怎么做
主从搭建报错:The slave I/O thread stops because master and slave have equal MySQL serv
ACTF 2022圆满落幕,0ops战队二连冠!!
spark基础-scala
【翻译】数字内幕。KubeCon + CloudNativeCon在2022年欧洲的选择过程
助力安全人才专业素养提升 | 个人能力认证考核第一阶段圆满结束!
Pytorch common loss function
Detailed idea and code implementation of infix expression to suffix expression
黑马--Redis篇
The nearest library of Qinglong panel
Benefit a lot, Android interview questions
R language ggplot2 visualization: use ggviolin function of ggpubr package to visualize violin diagram
ROS custom message publishing subscription example
Pychrm Community Edition calls matplotlib pyplot. Solution of imshow() function image not popping up
LeetCode_格雷编码_中等_89.格雷编码
Carte de réflexion + code source + notes + projet, saut d'octets + jd + 360 + tri des questions d'entrevue Netease
The second day of rhcsa study
GCC【7】- 编译检查的是函数的声明,链接检查的是函数的定义bug