By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: CNCF Accepts Kubescape as an Incubating Project
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > News > CNCF Accepts Kubescape as an Incubating Project
News

CNCF Accepts Kubescape as an Incubating Project

News Room
Last updated: 2025/03/31 at 4:28 AM
News Room Published 31 March 2025
Share
SHARE

The CNCF Technical Steering Committee (TOC) recently announced that it has accepted Kubescape as an incubating project. Kubescape offers security coverage for the Kubernetes environment from development to deployment. It is available as a CLI tool and a Kubernetes operator.

The announcement was made to the official CNCF blog and ARMO’s blog. ARMO is Kubescape’s parent company.

From its release in 2021, Kubescape has evolved from a CLI scanning tool for compliance with NSA-CISA Kubernetes Hardening guidelines to a full-fledged security platform.

The first release of Kubescape verified the cluster and workload configuration settings (e.g., Helm, YAML, RBAC, etc.) against the NSA-CISA Kubernetes Hardening Guidelines. The project further grew and met the growing security needs of Kubernetes DevOps and the cybersecurity community.

Kubescape can now perform configuration scanning, hardening recommendations, and vulnerability scanning against popular security frameworks (e.g., MITRE ATT&CK and Kubernetes CIS benchmark). It also offers an eBPF-based reachability analysis, Kubernetes Network Policy recommendations, and anomaly-based threat detection.

Under the hood, Kubescape uses Open Policy Agent to verify Kubernetes objects against a library of posture controls. It uses Grype for image scanning and Copacetic for image patching. The Inspecktor gadget is used for eBPF. Users can render the CLI scan results to HTML or PDF, export them to JSON, JUnit XML, or SARIF, or submit them to a cloud service.

Source: Kubescape GitHub Project

Kubescape integrates with IDEs, CI/CD pipelines (e.g., Kubescape GitHub Action), and monitoring systems such as Prometheus. It also supports in-cluster installation using a Kubernetes Operator.

Speaking about the announcement, Ben Hirschberg, CTO of ARMP and Core maintainer of Kubescape, said,

We decided to work with the CNCF because of its vibrant community of active contributors and users, as well as its clear pathway to project graduation. Our team members’ involvement in CNCF also played a key role in our decision.


CNCF’s emphasis on cloud native technology and strong community made it an ideal home for Kubescape.

Some notable adoptions of Kubescape are security prioritization at Intel, inclusion in AWS security training, improvement of helm chart security at Bitnami, and integration in CI/CD pipelines at Energi Danmark.

Discussing the usefulness of these security scanners, a Former Security Products PM at GitHub provided a good summary in this comment on a Hacker News post,

…In general, I think they’re well intentioned, and can be useful, but aren’t a panacea–they aren’t going to catch anything you’re not already looking for, they’re just going to make it easier to remedy/enforce the problems you already know about.

So far, the Kubescape project on GitHub has 10.6k stars. Interested users can refer to the contribution guide and the current issues on the Kubscaping board.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article What to Stream on TV This Week: 'The Bondsman,' 'Pulse' and More
Next Article Kelce and Swift ‘dine with Fox NFL star’ in secret vacation after Super Bowl
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

The Great Office Debate: Are RTO Mandates Really About Collaboration or Control? | HackerNoon
Computing
Samsung Galaxy Watch owners may have to pay extra for health features soon | Stuff
Gadget
Watch this person play The Witcher 3 on their Galaxy Watch Ultra
News
Apple updates iPhone, iPad pages with these labels to comply with eu rules
Software

You Might also Like

News

Watch this person play The Witcher 3 on their Galaxy Watch Ultra

2 Min Read
News

Jeff Bezos’ luxury superyacht heads to Venice for world’s most lavish wedding

4 Min Read
News

SMB-focused Finom closes €115M as European fintech heats up | News

8 Min Read
News

Surprise Sky & Virgin Media channel changes for movie fans due this week

2 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?