Kubescape Enhancing Kubernetes Scanning Abilities
CIO Review Europe | Friday, September 16, 2022
An end-to-end open source security platform for kubernetes, Kuberscape had added vulnerability scanning for code repositories and container image registries
FREMONT, CA: Kubescape, an open-source security platform for Kubernetes, has added two new vulnerability scanning features to the platform. Code repository and container image registry scanning are the first outcomes of an effort to cover more aspects of Kubernetes security. This also includes integrating third-party development and operations and Kubernetes tools such as lenses, Prometheus, plural, civo, GitHub Actions, GitLab, and Visual Studio.
Code repository scanning is the capability of scanning Helm charts and YAML files at the beginning stages of the software development life cycle. Users can view the outcomes on Kubescape's cloud UI even before any Kubernetes clusters are set up. They can view history, trends, and drifts, place exclusions, and do assisted remediation, which allows users to identify where control has failed and how to fix it.
On the other hand, container image registry scanning enables clients to scan container images directly from their registries, such as elastic container registry, quay, and Google container registry. Before administering or sending to run in the cluster, this scanning technique can be used.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
These two functions detect attacks earlier in the development process or third-party registries, preventing such threats from reaching production sites. Furthermore, Kubescape constantly monitors and tracks for new vulnerabilities in the CI/CD pipeline that might arise after a container image is developed, or a container cluster has been deployed. Kubescape will assist the Open API framework through swagger and enable Kubescape users to leverage services through available APIs.
The developers of Kubescape platforms are also open-sourcing a vital component of the Kubescape platform, its in-cluster Helm component, which is likely to create more features like image scanning, making it truly open source. The next development step will be to open source the whole back-end code base and services, allowing users to create their cloud solution and UI, above Kubescape, and build it as a DevOps-native system.
Furthermore, they will include collaboration features amalgamated with external ticket management systems and internal communication channels. This helps users to create Jira tickets, post to slack channels, and select the right team member when they identify new security issues in their environment with Kubescape. It will also help them to tackle the issues and fix them all from within the Kubescape platform.
Due to its easy-to-use CLI interface, flexible output formats, and automated scanning capabilities, Kubescape has emerged as one of the fastest-growing Kubernetes security compliance tools among developers. It also saves Kubernetes users' and admins' time, effort, and resources, which has made it a more effective platform, enhancing Kubernetes to scan vulnerabilities.
More in News