I would like to share Minimal - Its a open source collection of hardened container images build using Apko, Melange and Wolfi packages. The images are build daily, checked for updates and resolved as soon as fix is available in upstream source and Wolfi package. It utilizes the power of available open source solutions and contains commercially available images for free. Minimal demonstrates that it is possible to build and maintain hardened container images by ourselves.
Minimal will add more images support, and goal is to be community driven to add images as required and fully customizable.
shyim|29 days ago
adriand|29 days ago
ritvikarya98|29 days ago
debarshri|29 days ago
I think the problem in general is hardened image market is keeping up with CVEs and making sure the catalog is vast so that it covers all the images and nuances.
Responding and patchibg CVEs with an SLA is the KPI of the vendors. As much as I would like cheer for you, doing it as an opensource initiate with a guaranteed SLA is going to be painful for you as maintainer without profit as a motive.
ritvikarya98|29 days ago
unknown|29 days ago
[deleted]
lmeyerov|29 days ago
clawsyndicate|29 days ago
[deleted]
euph0ria|29 days ago
How can we learn the identity of the contributors? How are the contributors vetted? How are we notified if a significant change in leadership happens?
It's just a general problem when relying on GitHub accounts for important code.
For some reason I trust the big vendors to have better safe-guards against things like the questions above. Such as aws linux containers etc..
Would love to hear how other people think around this.
dgrove|29 days ago
theoo21|29 days ago
Dayshine|29 days ago
I don't understand why one would go halfway and leave packages which are unneeded for services. The only executable in a hardened container image should be your application.
ritvikarya98|29 days ago
Sytten|29 days ago
The syntax is hard without a functional background but I strongly believe this is the next logical step to harden containers and have reproducible builds.
anukritisingh|29 days ago
Joel_Mckay|29 days ago
In general, a public security policy is pointless. It is the one layer you want people to trip over when breaking a system. =3
theodore-1|27 days ago
indigodaddy|29 days ago
humayuuun|29 days ago
0xcrypto|29 days ago
unknown|29 days ago
[deleted]