❌

Normal view

CNCF and Kusari Partner to Strengthen Software Supply Chain Security across Cloud-Native Projects

10 April 2026 at 20:00

The Cloud Native Computing Foundation (CNCF) and Kusari have announced a new collaboration aimed at strengthening software supply chain security across cloud-native projects, providing free access to Kusari's AI-powered security tooling for CNCF-hosted projects.

By Craig Risi

Open Source Security Tool Trivy Hit by Supply Chain Attack, Prompting Urgent Industry Response

3 April 2026 at 20:00

A major security incident affecting the widely used open source vulnerability scanner Trivy has exposed critical weaknesses in software supply chain security, after maintainers confirmed that a malicious release was briefly distributed to users.

By Craig Risi
❌