4 ms·
In this case, supply chain security mostly means compliance. Alpine and other distros already do a great job at most aspects of supply chain security, but we ma
by dlor 3y ago
In this case, supply chain security mostly means compliance. Alpine and other distros already do a great job at most aspects of supply chain security, but we make package/image signatures and SBOMs very easy to get in Wolfi.
We're also more flexible on packaging extra software in Wolfi than other distros are, which has an effect on your overall supply chain security posture. We're aiming to package the entire Cloud Native landscape (to start!), so you can simply "apk add" anything you need, without having to drop back to "curl | bash" in your Dockerfile.
By making it easier for devs to get the software they need "the right way", they'll have a reduced need to work around the already existing secure distribution mechanisms built into their distros.
If you're already on Alpine and like it, that's great! If there are some packages you can't find in Alpine, or musl vs. glibc ever causes you issues, or you need SBOMs for some reason, give Wolfi a try!
- SamuelAdams 3y agoI’ve worked in a few industries that were crazy about compliance. Do you have any certifications for different compliances? Ie FedRamp, IL4/5/6, HIIPA, etc. I don’t think any other container images are strictly compliant with these standards - they’re not certified, but the technology stack (ECS, EKS, etc) is certified. Either way, if you can get this certified with different compliance platforms that would be a big selling point for B2B customers.
- dlor 3y agoWe're working on FIPS builds and will self-attest to the NIST SSDF stuff later this fall, but there aren't too many other requirements that directly apply to our images. The images are very useful for other organizations working on FedRAMP or HIPAA though, even though we don't need to have those ourselves. We wrote a bit more about that here: https://www.chainguard.dev/unchained/fortify-comply-and-conquer-fedramp-with-chainguard-images https://www.chainguard.dev/unchained/fortify-comply-and-conq...
- cookiengineer 3y agoDo you provide an OVAL feed? Alpine is out of the picture for us because the guy that works on their security tracker just doesn't care, and responds half a year after filing an issue. The tracker itself is broken for over a year and the response was to basically rebuild our own package index and host our own security tracker. So I would not say that Alpine has security as a high priority, even though in theory there are the secfixesdb. Redhat Enterprise, Debian and Ubuntu are used because they provide an OVAL feed that are easily integrated with zero development overhead. So if compliance is your focus, I'd heavily recommend generating an OVAL feed when you're regenerating the secfixes json files. Source: Am building a cross-linux-distro vulnerability database and I am scraping _all_ linux security trackers. [1] [1] https://github.com/tholian-network/vulnerabilities https://github.com/tholian-network/vulnerabilities
- dlor 3y agoThanks for the pointer! We update the JSON feed now but should be able to generate an OVAL feed too.
- killjoywashere 3y agoOVAL: https://oval.mitre.org/ https://oval.mitre.org/
- panekj 3y agoProbably because "the guy" is not a guy, but who cares, it's easier to just be salty on HN and spread lies about the project.
- cookiengineer 3y ago> it's easier to just be salty on HN and spread lies about the project. https://gitlab.alpinelinux.org/ariadne/secfixes-tracker/-/issues https://gitlab.alpinelinux.org/ariadne/secfixes-tracker/-/is... Check response time (in months or years) and also closed issues. What specifically was a lie in my comment?