Kubernetes finishes kpromo rewrite for secure image promotion

The Linux Foundation announced that Kubernetes has completed a rewrite of its kpromo system, modernizing the image promotion supply chain. The update removes the legacy pipeline and enables provenance features by default for all images.

Kubernetes, the popular open-source container orchestration platform, has modernized its image promotion supply chain through a complete rewrite of kpromo, the system responsible for moving images into the registry at github.com/kubernetes/registry.k8s.io. The Linux Foundation shared this update, noting that the legacy pipeline has been fully removed. Newer provenance features are now enabled by default, including SLSA attestation, cosign validation, and keyless signing for all Kubernetes images. The Linux Foundation described this as a critical step for building trust in the supply chain. kpromo plays a key role in ensuring that container images used in Kubernetes deployments meet security standards before entering the official registry. This change aims to enhance security practices across the ecosystem by making advanced verification methods standard. The announcement highlights ongoing efforts to strengthen software supply chain integrity amid rising concerns over vulnerabilities in container images.

ተያያዥ ጽሁፎች

Tech leaders announcing Linux Foundation's AI-powered cybersecurity initiative for open source software with major partners.
በ AI የተሰራ ምስል

Linux Foundation announces AI security initiative with tech partners

በAI የተዘገበ በ AI የተሰራ ምስል

The Linux Foundation has launched a new initiative using Anthropic's Claude Mythos preview for defensive cybersecurity in open source software. Partners include AWS, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorgan, Microsoft, NVIDIA, and Palo Alto Networks. The effort aims to secure critical software amid the rise of AI for open source maintainers.

The Linux kernel project has begun using Sashiko, an AI-powered system, to automatically review patches. This agentic, LLM-driven tool is identifying bugs that human reviewers overlooked. The initiative aims to enhance code quality and maintainability.

በAI የተዘገበ

Google and Meta have signed on as Diamond sponsors for the Linux Storage, Filesystem, Memory Management & BPF Summit. The event, organized by the Linux Foundation, brings together experts to shape future Linux kernel developments. Organizers highlighted the companies' support in recent announcements.

ይህ ድረ-ገጽ ኩኪዎችን ይጠቀማል

የእኛን ጣቢያ ለማሻሻል ለትንታኔ ኩኪዎችን እንጠቀማለን። የእኛን የሚስጥር ፖሊሲ አንብቡ የሚስጥር ፖሊሲ ለተጨማሪ መረጃ።
ውድቅ አድርግ