Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
dlor
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
31.
▲
by
dlor
3y ago
We're rapidly approaching 10k packages, here's today's count: / # apk update fetch https://packages.wolfi.dev/os/aarch64/APKINDEX.tar.gz [ https://packages.wolfi.dev/os ] OK: 94
32.
▲
by
dlor
3y ago
Wolfi is for running inside the container instead of on a VM or bare metal host. They're complementary - you'd run something like Clear Linux to boot up into a container host, then run this inside the containers.
33.
▲
by
dlor
3y ago
Roughly yes! I think we have a few advantages - mainly that we're focused on container workloads - that simplify the problem. But otherwise, yes! I'm betting that with enough automation we can get there :)
34.
▲
by
dlor
3y ago
And the fun part there is that this image is effectively a workaround - node.js 20 is installed via curl | bash. That means CVE scanners and SCA tools can miss node itself in that image. As silly as it sounds, try running "snyk contain
35.
▲
by
dlor
3y ago
Thanks for the pointer! We update the JSON feed now but should be able to generate an OVAL feed too.
36.
▲
by
dlor
3y ago
We're working on FIPS builds and will self-attest to the NIST SSDF stuff later this fall, but there aren't too many other requirements that directly apply to our images. The images are very useful for other organizations working o
37.
▲
by
dlor
3y ago
In this case, supply chain security mostly means compliance. Alpine and other distros already do a great job at most aspects of supply chain security, but we make package/image signatures and SBOMs very easy to get in Wolfi. We're
38.
▲
by
dlor
3y ago
Yep, but workarounds come with a cost. We're trying to package basically everything, so you don't need to pick between "up to date software" and "software from a trusted distro". It's going to be hard to s
39.
▲
by
dlor
3y ago
Debian does a great job! But here's one example where their packaging system makes container workloads hard. Debian, like many other distros has a strict "one version of every package" rule, meaning that Debian only ships one
40.
▲
by
dlor
3y ago
The fun part of HN is that you don't get to pick your turn on the front page. This was a surprise to me too, but I'm guessing it's up here for the same reasons you are.
41.
▲
by
dlor
3y ago
For static, not really just because there's so little in it. For apps that need CGO there's a benefit as more dependencies are required. CGO apps are broken right now IIUC in distroless/glibc-dynamic because of the Debian gli
42.
▲
by
dlor
3y ago
Totally understand the concern. We've tried to draw a very clear line between Wolfi (the project), and Chainguard Images (our product). They're in different GitHub organizations, have different maintainers, and are documented diff
43.
▲
by
dlor
3y ago
Thanks! By building the SBOMs as part of the build process we can ensure full coverage, vs. the other approaches that rely on "guessing" the contents after. We wrote a bit more about this approach here: https://www.chai
44.
▲
by
dlor
3y ago
You don't really have a choice - containers always use the host kernel. So packaging the full kernel itself is a waste of space at best, confusing to CVE scanners, and something you just don't need to bother with if you work with
45.
▲
by
dlor
3y ago
I was (one of) the original creators of the Google Distroless project. The main difference is that Original Distroless uses Debian as the upstream. This is great in many ways, but makes it so stuff outside of Debian is hard to package in. W
46.
▲
by
dlor
3y ago
It was meant to be a tongue-in-cheek way of pointing out that a it's a Linux distro without the Linux kernel, so it's really an "unLinux distro", or an (un)distro for short.
47.
▲
Supply chain security for Go, Part 2: Compromised dependencies
(security.googleblog.com)
2 points
by
dlor
3y ago
|
0 comments
48.
▲
The Principle of Minimalism
(chainguard.dev)
9 points
by
dlor
3y ago
|
0 comments
49.
▲
by
dlor
3y ago
In Wolfi's packaging system (melange) we setup a hermetic build environment. See here: http://github.com/wolfi-dev/os https://github.com/chainguard-dev/melange We use this to build APK packag
50.
▲
Fully bootstrapping Java from source in Wolfi
(chainguard.dev)
8 points
by
dlor
3y ago
|
0 comments
51.
▲
by
dlor
3y ago
I'd love to make this happen, but there aren't really any IDPs that meet this criteria yet. Happy to help get one going though!
52.
▲
Removing PGP from PyPI
(blog.pypi.org)
187 points
by
dlor
3y ago
|
187 comments
53.
▲
by
dlor
3y ago
I know folks hate the centralization of identity management to the big identity providers, but as AI gets better and better at defeating captcha it's going to get harder and harder for the small, independent ones to operate reliably an
54.
▲
Sigstore: Roots of Trust for Software Artifacts
(infoworld.com)
1 points
by
dlor
3y ago
|
0 comments
55.
▲
He Untold Story of the Boldest Supply-Chain Hack Ever
(wired.com)
8 points
by
dlor
3y ago
|
1 comments
56.
▲
by
dlor
3y ago
They have similarities in that they both can be used to sign things, but the architecture is completely different and sigstore is designed for different tradeoff - namely to be much easier to get started with and use.
57.
▲
Feeling VEXed by software supply chain security? Us, too
(theregister.com)
2 points
by
dlor
4y ago
|
0 comments
58.
▲
87% of Container Images in Prod Have Critical or High-Severity Vulnerabilities
(darkreading.com)
3 points
by
dlor
4y ago
|
1 comments
59.
▲
Towards Easier, More Secure Signature Tech for the Java Ecosystem with Sigstore
(blog.sigstore.dev)
1 points
by
dlor
4y ago
|
0 comments
60.
▲
GitHub says hackers cloned code-signing certificates in breached repository
(arstechnica.com)
2 points
by
dlor
4y ago
|
0 comments
More ›