![Launching SBOM Capabilities with Codenotary for Enhanced Kubernetes Security - Insights on ZDNet](https://www.zdnet.com/a/img/resize/df9613a0c2aaec5985230e010833ea4d58145c5a/2017/07/12/0e12b766-4bc9-4d43-b610-e80b107ac54e/kubernetes-class.jpg?width=278&height=156&fit=crop&auto=webp)
Launching SBOM Capabilities with Codenotary for Enhanced Kubernetes Security - Insights on ZDNet
![](/images/site-logo.png)
Launching SBOM Capabilities with Codenotary for Enhanced Kubernetes Security - Insights on ZDNet
Software Bill of Materials (SBOM)s aren’t optional anymore. If we really want the applications we’re running in containers to be secure, we must know what’s what within them. To make that easier, Codenotary , a leading software supply chain security company, is launching its new SBOM Operator for Kubernetes in both its open-source Community Attestation Service and its flagship service, Codenotary’s Trustcenter .
Open Source
- 5 Linux commands you must know to keep your device running smoothly
- The best Linux laptops you can buy: Expert tested
- The best Linux distros for beginners
- My 5 favorite Linux text editors (and why you should be using one)
An SBOM (pronounced S-Bomb) is a record containing the details and supply chain relationships of the components used in building software. Since most programs today are made by assembling existing open-source and commercial software components, it’s essential to know the name and specific versions of all these elements. For instance, a program using Apache Log4j2 versions 2.17.0 is vulnerable to Log4Shell attacks . One using Log4j2 2.17.1 or newer is as safe as houses .
Now, you could check for that and thousands of other potential vulnerabilities by hand, or you could turn to a service like Codenotary’s new offering. I know which one I’d pick.
The SBOM Operator for Kubernetes mitigates the risk of software supply chain attacks by tracking all software and software dependencies running in Kubernetes. It does this by generating SBOMs of your running container images and maintaining up-to-date records of all builds, and dependencies. SBOM Operator builds its SBOMs using its own SBOM generator. When a new vulnerability shows up – and trust me, one will – this lets you know that it’s time to make a fix when dangerous or vulnerable artifacts are detected.
To make this keep working properly, Codenotary continuously updates its SBOM records, This data is kept in its open-source speedy, immutable database, Immudb . This is a zero-trust tamper-proof, auditable database. The container image files are kept in a Git repository.
Codenotary claims this information is instantly available for search. With it, you can locate the software artifacts in your code in seconds. The program also keeps a history of verified image content changes.
“By itself, the SBOM is not very useful without continuously being updated and maintained as the information is deprecated with every new deployment or update,” said Dennis Zimmer, Codenotary’s co-founder and CTO. “Now, users know exactly what is running in containers, with the most recent information, so they have the ability to immediately remediate something if necessary.”
SBOM Operator’s chief programmer, Christian Kotzbauer, said, “I am pleased to contribute to the wider adoption and use of SBOMs with the Codenotary integration in my Kubernetes operator, especially the additional security, timestamp, and search capabilities across the infrastructure were key to developing the extension.
This is another step forward in Codenotary’s efforts to provide comprehensive tools for cataloging and securing the software development lifecycle. Its programs and services, both free and paid, deserve Kubernetes developers’ attention.
Related Stories:
- The Alpha and Omega of software supply chain security
- Securing the open-source ecosystem: SBOMs are no longer optional
- Codenotary: Notarize and verify your software bill of materials
Also read:
- [New] 2024 Approved Insta-Tips for Enthusiasts on Uploading Podcasts
- [New] Elite Unmanned Aerial Vehicles Up for Grabs
- [Updated] How to Make Macbook Pro Video Tutorials Easy for 2024
- 2024 Approved Revolutionize Replies Enhancing Interaction on Telegram Platforms
- 2024 Approved Subscriber Threshold Raised for Profits
- Don't Miss Out! Get Your Hands on the Affordable Colsen Tabletop Fire Pit for Just $50 Today!
- EcoFlow River 3 - A Leading Choice for Beginners in Portable Power Solutions
- Effective Solo Marketing in 2008: Boosting Ad Performance Through MassMail Solutions
- Enhance Your Green Thumb with Our Plant Care Software at an Extra Discounted Price This Labor Day | Exclusive Deal Alert!
- Experience Endless Entertainment with This Ultimate Remote-Controlled Lawn Mowing System: A Review - Unleash Your Green Thumb in a Whole New Way!
- Expert Tips on Picking Your Ideal Lawn Mower According to ZDNet Standards
- Exploring the Elite Quad of 2022 Walkie-Talkies - In Depth Review | ZDNET
- Exploring the Most Efficient Traveling Solar Panels for 2#: Unveiling Our Picks on ZDNET
- First Look at the DJI Mini 3 Pro – The Ultimate Tiny Drone for Stealthy Aerial Photography with Integrated Battery Charger | GadgetHub ZDNet
- Gear Up for Adventure with the Ultimate Guide to Best Outdoor TVs - Expert Ratings | ZDNET
- In 2024, Enhance Your Experience with Mi 11 Screen Capture Guide
- In 2024, Mastering Voice-Over Recording for Videos
- Top 5 High Definition Media Players for PC and Mac: Detailed Comparison, Downloads & User Reviews - 4K Edition
- Windows 用の失われたファイルを復元する Stellar データリカバリ -無料版でも利用可能
- Title: Launching SBOM Capabilities with Codenotary for Enhanced Kubernetes Security - Insights on ZDNet
- Author: Donald
- Created at : 2025-01-11 16:50:43
- Updated at : 2025-01-12 17:17:07
- Link: https://some-tips.techidaily.com/launching-sbom-capabilities-with-codenotary-for-enhanced-kubernetes-security-insights-on-zdnet/
- License: This work is licensed under CC BY-NC-SA 4.0.