Open source company Red Hat has teamed up with Black Duck Software to establish a secure model for containerised application delivery by providing verification that application containers are free from known vulnerabilities and include only certified content. “This validation is a major step forward in enabling enterprise-ready application containers,” the companies said in a joint statement. [caption id=“attachment_2351452” align=“alignleft” width=“380”]  Thinkstock[/caption] As an initial part of the collaboration, the companies plan to integrate Black Duck’s container scanning and open source security vulnerability-mapping software - Black Duck Hub - with OpenShift, Red Hat’s Platform-as-a-Service (PaaS) offering, providing reports and data on potential vulnerabilities present in container images made available in the OpenShift registry, a Red Hat-backed repository of validated, secure and trusted container images. Black Duck’s KnowledgeBase provides the backbone for the Hub, and includes information on 1.1 million open source projects, with detailed data on more than 100,000 known open source vulnerabilities across more than 350 billion lines of code. In addition, the companies plan to include Black Duck technologies as a set of complementary services within Red Hat’s current container certification workflow for application builders such as Independent Software Vendors (ISVs). “A significant part of an enterprise-ready container strategy is the ability to trust the code across the entire lifecycle of a containerized application, from development to management. Red Hat and Black Duck are extending the value of Red Hat’s platform and certification process to the broader developer community and our customers in addition to our robust partner ecosystem. This collaboration demonstrates Red Hat’s continued commitment to delivering not only Linux container-based innovation, but also the tools and ecosystem to help enterprises adopt containerized applications that are secure, certified and supported," Lars Herrmann, general manager, integrated solutions, Red Hat.
The companies plan to integrate Black Duck’s container scanning and open source security vulnerability-mapping software - Black Duck Hub - with OpenShift, Red Hat’s Platform-as-a-Service (PaaS) offering.
Advertisement
End of Article