Vitess security auditProject Summary 4 Audit Scope 4 Threat model formalisation 5 Fuzzing 14 Issues found 16 SLSA review 38 Conclusions 40 ## Executive summary In March and April 2023, Ada Logics carried out a audit the remaining Vitess code base. 4. Assess and improve Vitess’s fuzzing suite. 5. Carry out a SLSA compliance review. These five goals are fairly different. While they allowed the auditors to evaluate The issue has been assigned CVE-2023-29195. ## SLSA review In this section we present our findings from our SLSA compliance review of Vitess. SLSA is a framework for assessing artifact integrity and0 码力 | 41 页 | 1.10 MB | 2 年前3
Istio audit report - ADA Logics - 2023-01-30 - v1.09 Threat model 11 Issues found 17 Review of fixes for issues from previous audit 50 Istio SLSA compliance 52 ## Executive summary In September and October 2022 Ada Logics carried out a security issues found in an audit from 2020. 4. Review and improve Istio's fuzzing suite. 5. Perform a SLSA review of Istio. The audit was started with a kickoff meeting, and following that, Ada Logics had potential issues that they may be affected by. ## I stio SLSA compliance Ada Logics follows the specifications of SLSA v0.1 that are outlined here: https://slsa.dev/spec/v0.1/requirements. This version of compliance0 码力 | 55 页 | 703.94 KB | 2 年前3
Dapr september 2023 security audit reportExecutive summary 2 Project Summary 3 Audit Scope 4 Threat model 5 Fuzzing 15 Issues found 17 SLSA 43 Supply-chain mitigations 45 ## Executive summary In May and June 2023, Ada Logics carried out assets in scope. 3. Evaluate Daprs fuzzing suite against the formalised threat model. 4. Perform a SLSA review of Dapr. Our overall assessment of Dapr is highly positive. Dapr follows security best practices of the audit. An area for future work on Daprs security posture is its software supply-chain. The SLSA review showed that Dapr is lacking a compliant provenance attestation alongside release artifacts0 码力 | 47 页 | 1.05 MB | 2 年前3
第29 期| 2023 年9 月- 技术雷达队在为组织设计安全策略或选择安全分析工具时考虑这项技术。 ### 5. 自动合并依赖项更新 PR 试验 软件供应链的复杂性是一个重大风险,我们已经在一些文章中进行过讨论,例如 SBOM 与 SLSA。对于大多数团队来说,致命弱点仍然是依赖项中存在漏洞,通常是来自于多层的间接依赖项。Dependabot 等工具可以通过创建拉取请求(PR)来更新依赖项。不过,团队仍然需要制定工程纪律,以确保及时处理这些0 码力 | 43 页 | 2.76 MB | 2 年前3
2023 中国开源开发者报告的总量也翻番,许多老用户纷纷回归。 展望 2024 年,PikiwiDB 将重点发力于云原生方向,继续在“极大容量、极高性能、极致弹性”方向上进行探索。 ## CNCF 社区首个,KubeEdge 达到软件供应链 SLSA L3 等级 KubeEdge 社区已于 2022 年 7 月份完成整个 KubeEdge 项目的第三方安全审计,并已发布云原生边缘计算安全威胁分析和防护白皮书。 之后,围绕 SLSA 这一套标准陆续发布了很多有助于我们分析的数据服务和产品,比如准 SCA 产品 Open Source Insight,漏洞风险库 OSV(Open Google stakes new Secure Open Source rewards program for developers with $1M seed money • Introducing SLSA, an End-to-End Framework for Supply Chain Integrity - Binary Authorization for Borg: how Google verifies CycloneDX Specification • 4 Key Sigstore Takeaways: Recap of Twitter Space with Kelsey Hightower • SLSA vs. Software Supply Chain Attacks • The State of Open Source Vulnerabilities 2021 • GitHub 20200 码力 | 1356 页 | 45.90 MB | 2 年前3
共 6 条
- 1













