thomrstrom, to infosec
@thomrstrom@triangletoot.party avatar

👋 My last was in 2022, so here's an update:

  • Head of Security at
  • Keenly interested in and
  • 30 years of experience messing with the Internet & UNIX systems
  • I build my own frames & spend more time tinkering than riding
  • Spend my idle time playing and wandering on 2-wheel EVs
  • Live in NC with my wife & kids
  • Contributed to 250+ projects including 100+ I've created - bincapz is my latest.
wyri, to random
@wyri@haxim.us avatar

Great, really should have a look at #chainguard based #Docker images: JavaScript Actions in Alpine containers are only supported on x64 Linux runners. Detected Linux Arm64

thomrstrom, to programming
@thomrstrom@triangletoot.party avatar

I don't normally shill for my employer here, but it's big news: https://www.wsj.com/articles/chainguard-an-open-source-security-firm-raises-61-million-a4a940da

It's been a rocket ship adventure, for sure. We tried a few things, but It turns out that 0-vulnerability open-source container images are a big deal.

Somehow in 2023, we are still at the point where projects like #NodeJS, #nginx & #PHP publish container images with hundreds of CVEs. We minimize, harden, and remove vulns from these images, and our customers love it.

Want 0 #CVE images? Choose #Chainguard.

mike, to random

I took a dive into today, the "secret sauce" from YouTube (and Planetscale) for crazy database scaling.

Honestly it does look really good, nicer than Galera, but they really need better documentation and examples for everyone that doesn't use Kubernetes. 😡

So for now I don't think I'm going to use it. That said, I think I will switch to Percona from MariaDB, to save myself the migration pain later.

mike,

Anyways, the last part of today's research dive was more #Docker.

The most interesting discovery was #distroless images. I was familiar with #Alpine #Linux, but I hadn't really stumbled across distroless yet. Specifically I noticed that #Envoy shipped a distroless image, but neglected to really explain it short of "it's faster and better".

Google's distroless project is limited to standalone application runners (Node, Java), but #ChainGuard has their #Wolfi images that cover more bases. 👍

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • ngwrru68w68
  • everett
  • InstantRegret
  • magazineikmin
  • thenastyranch
  • rosin
  • GTA5RPClips
  • Durango
  • Youngstown
  • slotface
  • khanakhh
  • kavyap
  • DreamBathrooms
  • provamag3
  • tacticalgear
  • osvaldo12
  • tester
  • cubers
  • cisconetworking
  • mdbf
  • ethstaker
  • modclub
  • Leos
  • anitta
  • normalnudes
  • megavids
  • lostlight
  • All magazines