#policyascode

2025-12-31

Giới thiệu dự án mã nguồn mở Endpoint State Policy (ESP), một giải pháp "Policy as Code" giúp quản lý và thực thi chính sách endpoint một cách tự động.

#opensource #policyascode #DevOps #security #mãnguồnmở #bảomật

reddit.com/r/opensource/commen

All Things Openallthingsopen
2025-12-01

🚀 NEW on We ❤️ Open Source 🚀

Electric sheep need defenders. 🐑🔐 Brett Smith explores how SLSA helps secure the software supply chain, translating EO 14028 into a roadmap for resilient pipelines.

Read the article: allthingsopen.org/articles/sup

Left side says We Love Open Source. #WeLoveOpenSource. ATO. A community education resource from All Things Open. Right side has a sheep with a wolf's head.
2025-11-06

Zero CVEs ≠ Zero Risk.

Misconfigurations & leaked secrets can take down an image faster than any exploit.

Anchore helps teams catch both.

By @JoshSopuru → anchore.com/blog/beyond-the-cv

#SBOM #ContainerSecurity #PolicyAsCode #SoftwareSupplyChain

2025-10-31

Policy failure—not zero-days—is the real weak link.

Anchore enforces what "secure" means before bad configs & secrets ever ship.

Read @JoshSopuru's Beyond the CVE: anchore.com/blog/beyond-the-cv

#SBOM #ContainerSecurity #PolicyAsCode #SoftwareSupplyChain

2025-10-29

Relying on CVE scans alone is like putting a padlock on a vault with the back door open.

Anchore goes beyond the CVE to secure configs, secrets & policies.

By @JoshSopuru 👉 anchore.com/blog/beyond-the-cv

#SBOM #ContainerSecurity #PolicyAsCode #SoftwareSupplyChain

OctoLaunchoctolauch
2025-10-14

Policy-as-code makes governance reproducible & automatable. Enforce image signing, vulnerability scanning, & validate resource quotas starting small & scaling with warnings & blocks

OctoLaunchoctolauch
2025-10-07

Guardrails guide behavior, gates stop unsafe actions. Use guardrails for daily autonomy & gates for production-critical ops

Valdemarheyvaldemar
2025-05-26

🚨 Security doesn't start in prod — it starts at terraform plan.

With Policy as Code tools like , , Snyk, and by HashiCorp, you can catch misconfigs before they deploy. 🛡️

🎥 youtube.com/shorts/C-2OJMFVz8c

Open Policy Agent (OPA)openpolicyagent@infosec.exchange
2025-05-13

Nicholaos Mouzourakis at Gusto has been a long-time contributor to #OPA, and has written some of the best blogs on #Rego we've read. Turns out he is just as great talking about it on video! Just published on YouTube, "Super-Scaling Open Policy Agent with Batch Queries" is a deep-dive into an advanced OPA topic, explained well enough to be interesting to most. Hosted by the ever excellent Bart Farrell. Recommended!

youtube.com/watch?v=b6aTh2Qn4tA

#CloudNative #CNCF #DevOps #DevSevOps #PolicyAsCode

2025-04-22

A new #Regal release is out! Featuring 4 new linter rules, and a bunch of performance improvements along with the usual fixes. I'm particularly happy about the new "narrow-argument" rule, as I don't know many tools do that type of analysis for any language. It's an optional rule though, so make sure to enable it if you want to try it out!

github.com/StyraInc/regal/rele

#OPA #Rego #CloudNative #CodeQuality #PolicyAsCode

Open Policy Agent (OPA)openpolicyagent@infosec.exchange
2025-04-15

The #KubeCon recordings are now on YouTube! We'll be posting links to all the #OpenPolicyAgent related ones as we watch them. First out is the #OPA maintainer track session, where @charlieegan3 and @anderseknert give a short introduction to OPA and Rego, followed by a deep-dive into recent performance improvements, and a sneak peek at the project roadmap. Check it out!

youtube.com/watch?v=XtA-NKoJDaI

#CloudNative #CNCF #DevOps #DevSecOps #PolicyAsCode

2025-04-15

CIS ✅ STIG ✅ FedRAMP ✅ NIST ✅

Anchore Enforce comes with pre-built policy packs for major compliance standards. No translation needed.

Learn more: anchore.com/blog/automate-your

#SoftwareSupplyChain #Compliance #ContainerSecurity #PolicyAsCode

2025-04-11

Developers: Stop getting surprised by compliance issues at the end of your build. Anchore Enforce gives you immediate policy feedback right in your CI/CD pipeline.

See how: anchore.com/blog/automate-your

#SoftwareSupplyChain #Compliance #ContainerSecurity #PolicyAsCode

2025-04-09

Software supply chain attacks ⬆️ 540% since 2019. Your solution? Automated policy enforcement.

See how Anchore Enforce helps dev and security teams automate compliance at scale: anchore.com/blog/automate-your

#SoftwareSupplyChain #Compliance #ContainerSecurity #PolicyAsCode

2025-03-31

Before Policy-as-Code: Arcane compliance docs, 11th-hour shipping delays 😩

After Policy-as-Code: Automated and immediate feedback without leaving your terminal ✨

See how: anchore.com/blog/sbom-and-poli

#DevSecOps #SBOM #PolicyAsCode #SoftwareSupplyChain

2025-03-28

Today I was in the mood and packaged #regal and #opa for @opensuse

Packages still need more testing, but the first steps are done. Found a glitch in the OPA ldflags handling and reported it upstream.

Should arrive in #Tumbleweed soon-ish.

#packagerslife #policyascode #OpenPolicyAgent #opensuse

2025-03-28

Every context switch costs you productivity.

Learn how SBOMs & Policy-as-Code eliminate friction between development velocity and compliance requirements.

Read our developer guide: anchore.com/blog/sbom-and-poli

#DevSecOps #SBOM #PolicyAsCode #SoftwareSupplyChain

2025-03-26

🚀 The wait is over—Kubewarden 1.23 is here! Packed with security enhancements, smoother workflows, and key updates to elevate your Kubernetes experience. Dive into what's new: kubewarden.io/blog/2025/03/kub 🌟 #Kubernetes #DevSecOps #Security #PolicyAsCode

2025-03-26

Regal v0.32.0 just dropped! After having worked mostly on language server features recently, it was time for the linter to get some love. This release includes 3 new linter rules as well as much faster linting. Check it out!

github.com/StyraInc/regal/rele

#OPA #Rego #Regal #PolicyAsCode #CloudNative #DevOps #DevSecOps

2025-03-26

Tired of switching from coding to compliance?

Learn how SBOMs & Policy-as-Code automate policy checks in your workflow so you can spend less time in meetings and more time in your terminal.

Read our new developer guide: anchore.com/blog/sbom-and-poli

#DevSecOps #SBOM #PolicyAsCode

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst