Thanks for the write-up
What languages would you say are viable options in practice today to match rego(language and engine) functionality?
HN user
Giving your software supply chain superpowers at chainloop.dev
miguel at chainloop.dev
Thanks for the write-up
What languages would you say are viable options in practice today to match rego(language and engine) functionality?
I found this OSS tool interesting since it abstracts pretty much all the plumbing required to set up a computer vision pipeline.
For some reason, the act of choosing a plugin mechanism for our new project has been presented in my head a dilemma. Not a clear winner between the built-in stuff (plugin stdlib), the boring but battle tested option (Hashicorp go-plugin [1]) and the new exciting shiny ("future proof?") object web assembly plugins [2]
I ended up choosing the "traditional" Hashicorp library but any feedback, or comments on why you might think I am making a terrible mistake would be appreciated :)
[1] https://github.com/hashicorp/go-plugin [2] https://github.com/WebAssembly/WASI/blob/snapshot-01/phases/...
One step at the time. First, let's make something people love :)
Thanks!
I am afraid I don't have a formed opinion on the sigsum project yet.
Thanks for the pointer though, it indeed looks interesting, it might come handy once we start the effort of adding a transparent log (i.e rekor) to Chainloop.
Chainloop is not designed nor implemented with that centralization concept in mind.
It is meant to run as any other OSS infrastructure piece in your Software Supply Chain. The source of truth that we describe, it's about providing organizations with a single mechanism to define, ingest and route metadata and artifacts to their final destination (i.e artifactory, OCI registry, ...)
hi, Chainloop developer here.
I completely agree with your comment. We might be doing a poor job at explaining what Chainloop is compared to Sigstore.
Chainloop is built on top of Sigstore's (among from others) great OSS building blocks. We use cosign, in-toto and DSSE for generation or OCI for storing the attestations. It's true that today the signing is done using a asymmetric cosign key at the moment of the attestation crafting but we have plans on implementing keyless/identity signing and verifying using Sigstore fulcio+rekor.
Message in their customers dashboard.
"Dear Customers,
We're experiencing a DDoS attack on our DNSv2 system at the moment - this means that any domains that are using DNSv2 or FreeDNS nameservers may experience intermittent availability issues. We are currently in the process of mitigating the attack and are working hard to ensure a quick resolution. We sincerely apologize for the inconvenience caused."
There is another solution called Bitnami cloud (http://bitnami.org/cloud) that is not in the list.
I thought that rubystack was focused to give the users everything they need to start working with rails avoiding environment setup as well.
Sorry but I am trying to see the difference but I am not sure if I can.
So then the difference is some kind of friendly/more advanced installation interface and an easy way to get started installing less "stuff" than rubystack does?
What are the differences between RailsInstaller and RubyStack ?