Beth Pariseau · @BPariseau
318 followers · 143 posts · Server hachyderm.io

It absolutely blows me away how much smaller the surface area is for versus the mainstream container images for popular opensource projects:

python: 647 vulns
cgr.dev/chainguard/python: 0

nginx: 78 vulns
cgr.dev/chainguard/nginx: 0

Now, granted many of these CVEs are worthless, but who wants to track and manage that kind of noise? Not me!

I'd also complain about the lack of in the upstream opensource projects, but the tooling still sucks there.

#SBOMs #images #chainguard #cve

Last updated 1 year ago

data://disrupted®️ · @DataDisrupted
15 followers · 60 posts · Server mastodontech.de

Neue Episode vom Release.Patch.Repeat. An der Schwachstellenfront war es auffallend ruhig. Bekannte werden aktiv mit Malware beschossen. Außerdem gibt's Interessantes zu Open Source und die Forderung nach SBOMs. Forschende haben Manager gefunden, die zur Ausbeutung loyaler Fachkräfte neigen. Im Strategie-Teil geht es um . Außerdem gibt’s Reports und ein ITSiG 3.0 hat kurz reingeschaut.

release-patch-repeat.letscast.

#vulnerabilities #zerotrust #kritis #opensource #SBOMs #cybersicherheit #itsicherheit

Last updated 2 years ago

devguy :verified: · @developerguy
332 followers · 434 posts · Server hachyderm.io

Every new CD release includes a bunch of amazing features. @fluxcd is one of the communities that take software S3C seriously and provide features to mitigate the risks of them such as providing and attestations using @docker !

cncf.io/blog/2023/03/06/flux-f

#Flux #SBOMs #SLSA #buildx

Last updated 2 years ago

Ben Stroz6i · @stroz
154 followers · 1270 posts · Server infosec.exchange

are not as simple as they seem.

#SBOMs

Last updated 2 years ago

Dennis Irsigler · @dirsigler
151 followers · 367 posts · Server infosec.exchange

I saw now several talks about companies using to restrict deployments made to production.
They only allow deployments where or other scanners report a certain low amount of vulnerabilities. Also are checked for existence. Sometimes even more restrictions apply.

How do these companies handle then third party images needed ? For example some official Python images?
Having some kind of automatic mirror of requested applications to fetch them and build the needed things on their own systems ?
Just blocking and tell them “yeah please wait few days until we work on that ticket”

It seems I am confusing or missing something…

#Kyverno #trivy #SBOMs #docker

Last updated 2 years ago

Andres Almiray · @aalmiray
637 followers · 307 posts · Server mastodon.social

Well this happened. is now capable of producing thanks to an integration with . You don't need Syft pre-installed on your environment, JReleaser takes care of that

jreleaser.org/guide/early-acce

#jreleaser #SBOMs #syft

Last updated 2 years ago

tgkarounos · @tgkarounos
9 followers · 187 posts · Server mastodon.green

: a system to capture detailed information

An issue that is currently plaguing a number of people working in is that, given a generated binary artifact of a project, it is not easy (or even possible) to point back to the exact files that were used for creating it.
...
This work has been the result of a 2022 Google Summer of Code project for the GFOSS organization.
fosdem.org/2023/schedule/event

@eellak

#build #recorder #SBOMs #fosdem

Last updated 2 years ago

· @twitter
1 followers · 35894 posts · Server mstdn.skullb0x.io

Referenced link: hubs.la/Q01yx4Th0
Originally posted by The Linux Foundation / @linuxfoundation@twitter.com: twitter.com/ZephyrIoT/status/1

RT by @linuxfoundation: .@linuxfoundation's @_kate_stewart discussed & @SPDXTeam w/ @securityweekly. Watch it here: hubs.la/Q01yx4Th0 @SCMagazine @ZephyrIoT @ProjectELISA

#opensource #SBOMs #ZephyrRTOS #ELISAProject #security #linux

Last updated 2 years ago

Ben Stroz6i · @stroz
131 followers · 674 posts · Server infosec.exchange

If you're looking for an SCA and/or DAST tool that doesn't break the bank, check out SOOS, it's pretty rad and has super simple pricing: soos.io/

#sca #SBOM #SBOMs #dast #cyclonedx

Last updated 2 years ago

LMG Security · @LMGsecurity
28 followers · 6 posts · Server infosec.exchange

SBOMs are emerging as a requirement in some Federal and private contracts, & Gartner is predicting a sharp rise among organizations. Learn more about and how they can reduce risk: ow.ly/CjVM50MjihY

#criticalinfrastructure #SBOMs #infosec #cybersecurity #ciso #riskmanagement

Last updated 2 years ago

mcdwayne · @mcdwayne
139 followers · 192 posts · Server mastodon.social

RT @GitGuardian
Check out our recap of 2022 from our Developer Advocate @mcdwayne. Recap of presentations from @Cybercoopss, @jossefharush , Jason Manar @KaseyaCorp.

, Securing the , Security, and more..

blog.gitguardian.com/cybertech

#cybertechnyc #SBOMs #supplychain #data

Last updated 2 years ago

Christie Dudley · @longobord
209 followers · 374 posts · Server infosec.exchange

@foone And THIS is why exist.

#SBOMs

Last updated 2 years ago

devguy :verified: · @developerguy
163 followers · 149 posts · Server hachyderm.io

GUAC provides a central source for information about the security and provenance of an application by collecting materials like , vulnerability scan results, and signed attestations. The great talk by @mlieberman85 and @mihaimaruseac about it👇
youtube.com/watch?v=xFRNgIEzbk

#SBOMs

Last updated 2 years ago

devguy :verified: · @developerguy
158 followers · 136 posts · Server hachyderm.io

One of the most incredible talks by @puerco about his experience in the Kubernetes Release Engineering Team about making Kubernetes SLSA Level 3 compliant, how they use @projectsigstore to sign and verify releases, how they generate etc. 👇

youtube.com/watch?v=rGHIu_AWAz

#Cosign #SBOMs

Last updated 2 years ago

@cloudnativeboy · @saim
26 followers · 41 posts · Server k8s.social

Highly informative talk by
@puerco about his experience in the K8s Release Engineering Team about making K8s SLSA Level 3 compliant, how they use @projectsigstore to sign and verify releases, how they generate etc.

Watch the recording
youtube.com/watch?v=rGHIu_AWAz

#Cosign #SBOMs

Last updated 2 years ago

Saim Safdar · @cloudnativeboy
2 followers · 8 posts · Server hachyderm.io

Highly informative talk by
@puerco about his experience in the K8s Release Engineering Team about making K8s SLSA Level 3 compliant, how they use @projectsigstore to sign and verify releases, how they generate etc.

Watch the recording
youtube.com/watch?v=rGHIu_AWAz

#Cosign #SBOMs

Last updated 2 years ago

puerco · @puerco
355 followers · 96 posts · Server hachyderm.io

RT @developerguyba@twitter.com

One of the most incredible talks by @puerco@twitter.com about his experience in the Kubernetes Release Engineering Team about making Kubernetes SLSA Level 3 compliant, how they use @projectsigstore@twitter.com to sign and verify releases, how they generate etc. 👇

youtube.com/watch?v=rGHIu_AWAz

🐦🔗: twitter.com/developerguyba/sta

#Cosign #SBOMs

Last updated 2 years ago

devguy :verified: · @developerguy
139 followers · 130 posts · Server hachyderm.io

A long-waited talk just has been shared by @orasproject. In that talk, you will discover all the recent updates in the @oci_org@birdsite.wilde.cloudto manage the relationships between the objects, such as , , , and OCI images 🏅
youtube.com/watch?v=VZckJNkJ0n

#SBOMs #provenance #signatures

Last updated 2 years ago

devguy :verified: · @developerguy
139 followers · 130 posts · Server hachyderm.io

Let's learn more about how we can combine these two excellent projects @AquaSecTeam's and @projectsigstore tools, to generate and sign 👇 Thanks to @itaysk for sharing such great details with us 🥳

≫ 📸 youtu.be/i_9bV08CTao
≫ 🧵 twitter.com/itaysk/status/1588

#trivy #SBOMs

Last updated 2 years ago