Breaking News

BellSoft Announces Hardened Builder for Paketo Buildpacks for Zero-CVE Containers

https://ift.tt/Paev4ot

The BellSoft Hardened Images builder improves security and compliance for users of the open-source Paketo Buildpacks project in the Cloud Native Computing Foundation.

These hardened images, which automatically turn container images into production-ready container images without a Docker file, offer continuous vulnerability management. According to BellSoft, “A buildpack inspects application code, determines what it needs, downloads dependencies, compiles where necessary and produces a runnable OCI image, all in a single command.”

BellSoft’s hardened builder builds off a builder that bundles a build environment, the buildpacks and a runtime, providing a largely CVE-free base for every container image produced. The base of every container that uses it is made up of the open source packages, libraries and runtime binaries. The hardened build replaces the build environment and runtime with Hardened Images, which means every container automatically produced has BellSoft’s security and compliance posture built in.

According to a recent BellSoft survey, over 60% of developers are unaware that a poorly written Dockerfile can become a vulnerability. At scale,  Dockerfile sprawl becomes a compliance and maintenance liability. Base image updates must be propagated manually across every repository. Security patches are only as fast as the slowest team. Using buildpacks, developers “push code, and the buildpack tooling auto-detects the language, resolves dependencies, and produces a minimal, reproducible OCI image with a built-in Software Bill of Materials,” the company said in a statement.

With BellSoft’s hardened builder, that advantage compounds. When a vulnerability is patched in BellSoft Hardened Images, built on BellSoft’s Alpaquita OS, every application built on the builder picks up the fix on the next build, across every service and team simultaneously.

“Vulnerability management is a business problem, not an engineering one,” said Alex Belokrylov, CEO of BellSoft. “It deserves a business answer, not the silent accumulation of toil on already-stretched internal teams. Scanner fatigue is real, and so is the cost of ignoring it. Rather than tracking CVE feeds, triaging which vulnerabilities affect which base images, and coordinating patches across teams, security and platform engineering teams can rely on BellSoft to maintain a clean image baseline. Each published image comes with a full Software Bill of Materials and a verifiable provenance record, making compliance audits straightforward and transparent, and providing the documented evidence that regulators and enterprise procurement teams increasingly demand.”

Read more here.

The post BellSoft Announces Hardened Builder for Paketo Buildpacks for Zero-CVE Containers appeared first on SD Times.



Tech Developers

No comments