As organizations break down large systems into container-based microservices, it becomes harder to track all the pieces.To handle this,Google, JFrog, Red Hat, IBM, Black Duck, Twistlock, Aqua Security and CoreOS recently announced Grafeas , a new joint open-source project that provides users with a standardized way for auditing and governing for computing components & their software supply chain.
Grafeas offers a central, structured knowledge-base of the critical metadata organizations need to successfully manage their software supply chains.
Grafeas defines metadata API spec for computing components (e.g., VM images, container images, jar files, scripts) that can assist with aggregations over your metadata. This means keeping a record of authorship and code provenance, recording the deployment of each piece of code, marking whether code passed a security scan, which components it uses and whether Q&A signed off on it.
So before a new piece of code is deployed, the system can check all of the info about it through the Grafeas API and if it’s certified and free of vulnerabilities, then it can get pushed into production.
To learn more about Grafeas,visit GitHub
In today's digital-first world, businesses must adopt effective strategies to stay competitive. Social media marketing…
62% of UX designers now use AI to enhance their workflows. Artificial intelligence (AI) rapidly…
The integration of artificial intelligence into graphic design through tools like Adobe Photoshop can save…
The cryptocurrency trading world has grown significantly in recent years, with automation playing a key…
The non-fungible token (NFT) market has witnessed explosive growth over the past few years, transforming…
There are few things as valuable to a business as well-designed software. Organizations today rely…
This website uses cookies.