Supply chain, DevOps

Harness launches Artifact Registry to secure software supply chain

Supply chain vulnerability being exploited through a cyber attack on text code in an editor.

According to Silicon Angle, Harness Inc. has announced the general availability of its new product, Artifact Registry. This tool is designed to securely manage software packages throughout the integration and delivery lifecycle, addressing critical security concerns in modern software development.

Harness Artifact Registry centralizes and manages all machine-generated outputs from the development lifecycle, including binaries, container images, and configuration files. This ensures consistency from development to production and keeps management close to the development process. The registry supports a wide range of formats such as Docker, Helm, Python, and AI models. It aims to solve the industry problem of fragmented artifact management, which has contributed to supply chain attacks like the SolarWinds breach and the Shai-Hulud malware.

To combat these threats, Harness integrates security scanning directly into the registry workflow. A dependency firewall checks dependencies for vulnerabilities in real time as artifacts are added, blocking components with known issues, license violations, or untrusted sources before they enter the system. Items outside policy can be quarantined for human review.

Source: Silicon Angle

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds