Kubernetes finishes kpromo rewrite for secure image promotion

The Linux Foundation announced that Kubernetes has completed a rewrite of its kpromo system, modernizing the image promotion supply chain. The update removes the legacy pipeline and enables provenance features by default for all images.

Kubernetes, the popular open-source container orchestration platform, has modernized its image promotion supply chain through a complete rewrite of kpromo, the system responsible for moving images into the registry at github.com/kubernetes/registry.k8s.io. The Linux Foundation shared this update, noting that the legacy pipeline has been fully removed. Newer provenance features are now enabled by default, including SLSA attestation, cosign validation, and keyless signing for all Kubernetes images. The Linux Foundation described this as a critical step for building trust in the supply chain. kpromo plays a key role in ensuring that container images used in Kubernetes deployments meet security standards before entering the official registry. This change aims to enhance security practices across the ecosystem by making advanced verification methods standard. The announcement highlights ongoing efforts to strengthen software supply chain integrity amid rising concerns over vulnerabilities in container images.

Liittyvät artikkelit

Tech leaders announcing Linux Foundation's AI-powered cybersecurity initiative for open source software with major partners.
AI:n luoma kuva

Linux Foundation announces AI security initiative with tech partners

Raportoinut AI AI:n luoma kuva

The Linux Foundation has launched a new initiative using Anthropic's Claude Mythos preview for defensive cybersecurity in open source software. Partners include AWS, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorgan, Microsoft, NVIDIA, and Palo Alto Networks. The effort aims to secure critical software amid the rise of AI for open source maintainers.

SUSE has announced the availability of its Multi-Linux Manager MCP Server v0.5.1 tech preview on the SUSE registry. This release introduces secure, AI-assisted operations for mixed Linux environments. Key features include signed images, CVE scanning, and OAuth 2.0 support.

Raportoinut AI

Red Hat has released the general availability version of its build of Podman Desktop, aimed at streamlining development to production workflows. The tool offers native Kubernetes support and other features to enhance consistency across environments. The announcement was made on February 17, 2026.

Following its February call for proposals, the Linux Foundation has detailed its Linux kernel track at Open Source Summit India in Mumbai on June 16-17. Aimed at developers and maintainers, the track features deep technical dives into the kernel. Registration is now open.

Raportoinut AI

The Linux Foundation has secured $12.5 million in grants from AI companies to bolster open source software security. The funding addresses maintainers overwhelmed by AI-generated vulnerability reports. It will be managed by Alpha-Omega and the Open Source Security Foundation.

Tämä verkkosivusto käyttää evästeitä

Käytämme evästeitä analyysiä varten parantaaksemme sivustoamme. Lue tietosuojakäytäntömme tietosuojakäytäntö lisätietoja varten.
Hylkää