Automatic SBOMs with ko
Generate automatic SBOMs with ko to enhance software supply chain security for Go applications.

4276 articles
4276 ARTICLES
Generate automatic SBOMs with ko to enhance software supply chain security for Go applications.


Use the Snyk Vulnerability database to help you find an opportunity to make an open source contribution to The Big Fix!

Snyk has partnered with Sysdig to build a combined solution that addresses security across the DevOps process, from code to Kubernetes cluster.

Build and run Sigstore locally to easily sign and verify container images without external dependencies.

I conducted research based upon existing Python vulnerabilities and identified a common software pattern between them. This led to the discovery of a stored command injection vulnerability in Celery.

A look at Kubernetes operators and their implications for security, outlining potential security risks, discussing how to use operators with security in mind ,and examining how the right operators can lead to a more secure environment.
![Automating Terraform security in Scalr deployments with Regula [Tutorial]](https://stithello.blob.core.windows.net/ithello-online-images/1a7e39b4-bae9-427d-bc13-b8b49ff007ea.webp)
Regula enables cloud teams to evaluate Terraform, CloudFormation, Azure Resource Manager, and Kubernetes Infrastructure-as-Code (IaC) for security and compliance violations prior to deployment. Regula is an open source implementation of Rego, the query language used by the Open Policy Agent (OPA) project.

SAST and SCA are better when you use them together. Secure your code and dependencies at the same time with Snyk.

Learn about the Argo CD vulnerability (CVE-2022-24348), as well as the larger implications regarding securing yourself against the kind of supply chain attack this vulnerability could have caused.

Learn more about the unique requirements for microservices security architecture to keep your systems and applications secure.

For each CVE, the Wiz Research team maintains data from multiple threat intelligence sources and our own independent research. Now that we’ve added support for the new CISA KEV catalog, learn how you can use it in your cloud environment.

Keyless signing with Tekton on Amazon EKS simplifies software signing and enhances security in your Kubernetes pipelines.
Cookies
We use analytics cookies (Google Analytics) to improve this site. Accept to allow them. Privacy Policy