CNCFとKusariがクラウドネイティブプロジェクトのソフトウェアサプライチェーンセキュリティ強化で提携
本文の状態
日本語全文を表示中
詳細モードで約7分の本文を読めます。
同じ出来事の情報源
この情報源を基点に整理
InfoQ
クラウドネイティブコンピューティング財団(CNCF)とKusariは、CNCFがホストするプロジェクト向けにKusariのAI駆動セキュリティツールへの無料アクセスを提供し、ソフトウェアサプライチェーンセキュリティを強化する新たな連携を発表した。
Source Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。
クラウドネイティブコンピューティング財団(CNCF)とKusariは、クラウドネイティブプロジェクト全体におけるソフトウェアサプライチェーンのセキュリティを強化する新たな協力関係を発表しました。これにより、CNCFがホストするプロジェクトに対して、KusariのAI搭載セキュリティツールの無償アクセスが提供されます。この取り組みは、深いセキュリティ専門知識を必要とせず、メンテナーやコントリビューターがますます複雑化する依存関係エコシステムをより良く理解し、管理、そして保護することを支援するために設計されています。
このパートナーシップの中心は、Kusari InspectorへのアクセスをCNCFプロジェクトに提供することにあります。このツールは、AI支援コードレビューと依存関係分析を組み合わせ、直接の依存関係だけでなく間接的な(トランジティブな)依存関係全体にわたるリスクを特定します。現代のアプリケーションはますます数百、数千もの相互接続されたコンポーネントに依存しており、AI生成コードの普及が進むにつれて、完全なソフトウェアサプライチェーンへの可視性は、より困難かつより重要になっています。
この発表は、クラウドネイティブエコシステムが直面する拡大する課題を浮き彫りにしています。ソフトウェアサプライチェーンは規模と複雑さの両方で拡大しており、新たな攻撃面や運用リスクをもたらしています。多くの依存関係はトランジティブな関係を通じて自動的に取得されるため、メンテナーがソフトウェアに何が含まれているかを完全に理解することは困難です。同時に、攻撃者は依存関係の混乱(dependency confusion)、悪意のあるパッケージのインジェクション、脆弱なプロヴェナンス管理の悪用などの手法を通じて、これらのサプライチェーンを標的にするようになっています。
リソースが限られた小規模チームによって維持されることが多いオープンソースプロジェクトにおいて、この複雑さは断片化されたツールと限られた可視性によってさらに悪化しています。複数のセキュリティツールが使用されている場合でも、チームはサプライチェーン全体におけるリスクの統一された文脈付きのビューを欠いていることが多く、脆弱性の優先順位付けと効果的な修正が困難になっています。
Kusari-CNCFイニシアチブの重要な焦点は、セキュリティを開発者ワークフローに直接組み込むことで、「左側」へのシフトを実現することです。Kusari Inspectorは、プルリクエストに対してインラインフィードバックを提供し、依存関係をマッピングし、プロヴェナンス(出所)とアテスタション(証明)のギャップを特定し、開発ライフサイクルの初期段階でリスクを可視化します。
このアプローチは、リアクティブなセキュリティプロセスからプロアクティブでワークフローに統合されたセキュリティプラクティスへの、より広範な業界の移行を反映しています。問題を早期に検出し、文脈に応じた洞察を提供することで、このプラットフォームはメンテナーの負担を軽減し、手動調査を最小限に抑え、より迅速で安全なソフトウェア配信を可能にすることを目指しています。また、実行可能なインテリジェンスを開発プロセスに直接組み込むことで、開発者とセキュリティチームの間のギャップを埋めることにも役立ちます。
この取り組みは、Supply-chain Levels for Software Artifacts (SLSA) や GUAC、in-toto、OpenVEX といったプロジェクトやツールに基づいており、これらはすでに Kusari Inspector を採用しています。これらのプロジェクトは、現代のセキュリティ戦略における重要な柱である、ソフトウェアサプライチェーン全体の出自情報の改善、透明性の向上、そして信頼性の確保に焦点を当てています。
これらの既存の取り組みと統合することで、このコラボレーションはサプライチェーンセキュリティに対するより一貫性がありアクセスしやすいアプローチを提供することを目指しており、プロジェクトが断片化されたツール群から、連携したエコシステム全体の可視性とガバナンスへと移行できるよう支援します。
より広範な業界動向において、このコラボレーションはソフトウェアサプライチェーンセキュリティの向上に注力する他の組織による類似した取り組みと整合していますが、アプローチや統合のレベルは異なります。例えば、Snyk と GitHub(GitHub Advanced Security を通じて)は、開発者ファーストのセキュリティツールリングを強調し、脆弱性スキャン、依存関係の洞察、コード分析を直接開発者のワークフローに組み込んでいます。これらのプラットフォームは広く採用されており既知の脆弱性に関する強力な可視性を提供しますが、Kusari などの取り組みが対象とする出自情報、アテスタンス(証明)、信頼保証の全ライフサイクルというよりは、検出と修正に重点を置いている傾向があります。
エコシステムレベルでは、OpenSSFや前述のSLSAのような取り組みは、より標準主導のアプローチを採用し、ビルドの整合性、出所(プロヴェナンス)、およびアーティファクト検証に関するベストプラクティスを定義しています。同様に、Sigstoreのようなツールは、アーティファクトの信頼性を確保するために暗号署名と検証に焦点を当てています。これらと比較すると、CNCF-Kusariのイニシアチブは、AI支援による洞察とサプライチェーンの可視性を組み合わせ、開発者のワークフローに直接組み込むことで、より統合されアクセスしやすいレイヤーとして位置づけています。これは業界における顕著なトレンドを反映しています:断片化された定点のセキュリティツールから、強力なガバナンスと信頼性を保証しつつ、使いやすさとバランスを取った統一された継続的なサプライチェーンセキュリティプラットフォームへの移行です。
著者について
Craig Risi
Craig Risiは多才な人物ですが、その才能の使い方がわかりません。世界を変えに行くことも可能ですが、ソフトウェアを作ることを好みます。彼はソフトウェアデザインへの情熱を持っていますが、それ以上に技術的に多様で絶えず進化していくテクノロジーの世界において、ソフトウェアの品質とシステムの設計に情熱を注いでいます。
クレイグはまた、『Quality By Design: Designing Quality Software Systems(品質による設計:高品質なソフトウェアシステムの設計)』という書籍の著者であり、自身のブログサイトや世界中のさまざまなテックサイトにて定期的に記事を投稿しています。
ソフトウェアいじっていないときは、文章を書くこと、ボードゲームをデザインすること、あるいは何の理由もなく長距離走をしている姿をよく見かけます。
Show moreShow less
原文を表示
The Cloud Native Computing Foundation (CNCF) and Kusari have announced a new collaboration aimed at strengthening software supply chain security across cloud-native projects, providing free access to Kusari's AI-powered security tooling for CNCF-hosted projects. The initiative is designed to help maintainers and contributors better understand, manage, and secure increasingly complex dependency ecosystems without requiring deep security expertise.
The partnership centers on providing CNCF projects with access to Kusari Inspector, a tool that combines AI-assisted code review with dependency analysis to identify risks across both direct and transitive dependencies. As modern applications increasingly rely on hundreds or thousands of interconnected components, and as AI-generated code becomes more prevalent, visibility into the full software supply chain has become both more difficult and more critical.
The announcement highlights a growing challenge facing the cloud-native ecosystem: software supply chains are expanding in both scale and complexity, introducing new attack surfaces and operational risks. Many dependencies are pulled in automatically through transitive relationships, making it difficult for maintainers to fully understand what is included in their software. At the same time, attackers are increasingly targeting these supply chains through techniques such as dependency confusion, malicious package injection, and exploitation of weak provenance controls.
For open source projects, often maintained by small, resource-constrained teams, this complexity is compounded by fragmented tooling and limited visibility. Even when multiple security tools are used, teams frequently lack a unified, contextual view of risk across their supply chain, making it harder to prioritise and remediate vulnerabilities effectively.
A key focus of the Kusari-CNCF initiative is shifting security "left" by embedding it directly into developer workflows. Kusari Inspector provides inline feedback on pull requests, maps dependencies, identifies gaps in provenance and attestations, and surfaces risks early in the development lifecycle.
This approach reflects a broader industry move away from reactive security processes toward proactive, workflow-integrated security practices. By catching issues earlier and providing context-aware insights, the platform aims to reduce the burden on maintainers, minimise manual investigation, and enable faster, more secure software delivery. It also helps bridge the gap between developers and security teams by embedding actionable intelligence directly into the development process.
The initiative builds on existing efforts within the cloud-native and open source security ecosystem, including projects such as Supply-chain Levels for Software Artifacts (SLSA) and tools like GUAC, in-toto, and OpenVEX, which are already adopting Kusari Inspector. These projects focus on improving provenance, transparency, and trust across software supply chains, key pillars in modern security strategies.
By integrating with these efforts, the collaboration aims to provide a more cohesive and accessible approach to supply chain security, enabling projects to move from fragmented tooling toward connected, ecosystem-wide visibility and governance.
In the broader landscape, this collaboration aligns with similar efforts from other organizations focused on improving software supply chain security, though with varying approaches and levels of integration. For example, Snyk and GitHub (through GitHub Advanced Security) emphasize developer-first security tooling, embedding vulnerability scanning, dependency insights, and code analysis directly into developer workflows. These platforms are widely adopted and provide strong visibility into known vulnerabilities, but they often focus more on detection and remediation rather than the full lifecycle of provenance, attestations, and trust guarantees that initiatives like Kusari are targeting.
At the ecosystem level, efforts such as OpenSSF and the aforementioned SLSA take a more standards-driven approach, defining best practices for build integrity, provenance, and artifact verification. Similarly, tools like Sigstore focus on cryptographic signing and verification to ensure artifact trust. Compared to these, the CNCF-Kusari initiative positions itself as a more integrated and accessible layer, combining AI-assisted insights with supply chain visibility and embedding them directly into developer workflows. This reflects an emerging trend in the industry: moving from fragmented, point-in-time security tools toward unified, continuously enforced supply chain security platforms that balance usability with strong governance and trust guarantees.
About the Author
Craig Risi
Craig Risi is a man of many talents but has no sense of how to use them. He could be out changing the world but prefers to make software instead. He possesses a passion for software design, but more importantly software quality and designing systems in a technically diverse and constantly evolving tech world.
Craig is also the writer of the book, Quality By Design: Designing Quality Software Systems, and writes regular articles on his blog sites and various other tech sites around the world.
When not playing with software, he can often be found writing, designing board games, or running long distances for no apparent reason.
Show moreShow less
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み