-

Codenotary First to Provide Continuously Updated and Fully Searchable Tamper-Proof Information about Software Components in Container Images

SBOM Operator for Kubernetes allows users to continuously be aware of all software and software dependencies running in Kubernetes

HOUSTON--(BUSINESS WIRE)--Codenotary, leaders in software supply chain security, today launched SBOM Operator for Kubernetes in both its open source Community Attestation Service, as well as Codenotary’s Trustcenter, the company’s flagship product, that mitigates the risk of software supply chain attacks by tracking all software and software dependencies running in Kubernetes. Codenotary provides the easiest way to generate SBOMs (Software Bill of Materials) of running container images and maintaining up-to-date records of all builds, and dependencies. This allows for immediate risk mitigation in the event that unwanted, dangerous or vulnerable artifacts are detected.

All SBOM information is continuously updated and versioned to include any changes in deployments, then stored in a tamper-proof, auditable database. That information is instantly available for search so that the location of software artifacts can be pinpointed in seconds, and the history of image content changes verified, which is essential to maintaining a secure software supply chain.

The new SBOM Operator for Kubernetes helps enterprises comply with the U.S. Executive Order on Improving the Nation’s Cybersecurity, which includes maintaining a Software Bill of Materials (SBOM), as well as the SLSA security framework to ensure trust in the software supply chain.

“By itself, the SBOM is not very useful without continuously being updated and maintained as the information is deprecated with every new deployment or update,” said Dennis Zimmer, co-founder and chief technology officer, Codenotary. “Now, users know exactly what is running in containers, with the most recent information so they have the ability to immediately remediate something if necessary.”

SBOM Operator is an open source community project – supported by Codenotary – to store SBOM information about container images as files in a Git repository and has been extended to support both Community Attestation Service, as well as Trustcenter, which are tamper-proof, versioned and fully searchable.

“I am pleased to contribute to the wider adoption and use of SBOMs with the Codenotary integration in my Kubernetes operator, especially the additional security, timestamp and search capabilities across the infrastructure were key to developing the extension,” said Christian Kotzbauer.

Codenotary provides tools for cataloging and trusting components of the software development lifecycle which help attest to the origin and safety of the code. The company further enhances this core functionality by providing an additional tamper-proof layer which processes and stores millions of transactions per second, on-premises or as a cloud service, and with cryptographic verification. It gives developers and DevOps engineers a way to attach a Software Bill of Materials (SBOM) for development artifacts that include source code, builds, repositories, and more, plus Docker and Kubernetes container images for their software.

For more information, go to Codenotary Trustcenter.

About Codenotary

With over 100 customers that includes top three banks in the U.S. and Europe, Codenotary brings easy to use trust and integrity into the software lifecycle by providing end-to-end cryptographically verifiable tracking and provenance for all artifacts, actions, and dependencies. Codenotary can be set up in minutes and can be fully integrated with modern CI/CD platforms. It is the only immutable and client-verifiable solution available that is capable of processing millions of transactions a second. With the Codenotary tamper-proof bill of materials, users can instantly identify untrusted components in their software builds. For more information, go to https://www.codenotary.com.

Contacts

Joe Eckert for Codenotary
Eckert Communications
jeckert@eckertcomms.com

Codenotary


Release Summary
Codenotary launched SBOM Operator for Kubernetes in both its open source Community Attestation Service, as well as Codenotary’s Trustcenter.
Release Versions

Contacts

Joe Eckert for Codenotary
Eckert Communications
jeckert@eckertcomms.com

Social Media Profiles
More News From Codenotary

Codenotary Extends Free SBOM.sh Service to Examine AI Software Supply Chain

SAN FRANCISCO--(BUSINESS WIRE)--Codenotary, leaders in software supply chain protection, today announced new capabilities for its free SBOM.sh service – supporting AI applications by treating datasets as software supply chain artifacts. The update represents a necessary evolution of SBOMs that reflects how modern systems are actually built, deployed, and operated, helping to close a critical gap in security and compliance. “Traditional SBOM tools were built for an earlier era – focusing primari...

Codenotary Granted U.S. Patent for Breakthrough Cryptographic Proof Technology

HOUSTON--(BUSINESS WIRE)--Codenotary, leaders in software supply chain protection, today announced that it has been granted a patent for how data integrity can be verified at large scale, which is the foundation of the company’s software supply chain protection products. The novel approach to cryptographic verification dramatically improves the speed and efficiency of validating data integrity at enterprise scale. Organizations need to verify that their software, build artifacts, and sensitive...

Codenotary Inc. Raises $16.5M to Accelerate Global Expansion of Its Intelligent Cybersecurity & Trust Automation Platform

HOUSTON--(BUSINESS WIRE)--Codenotary Inc., a global leader in AI cybersecurity and software supply chain trust, today announced that it has raised $16.5 million in new financing from both new and existing investors. This latest round will accelerate development and market expansion for the company’s rapidly growing platform, which delivers next-generation capabilities in automated software integrity and overall systems security. As enterprises face unprecedented pressure to secure their digital...
Back to Newsroom