
  <rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
      <title>Chaos and Order</title>
      <link>https://www.youngju.dev/blog</link>
      <description>천천히 올바르게. AI Researcher &amp; DevOps Engineer Youngju&#39;s tech blog. GPU/CUDA, LLM, MLOps, Kubernetes AI workloads, distributed training, and data engineering.</description>
      <language>ko</language>
      <managingEditor>fjvbn2003@gmail.com (Youngju Kim)</managingEditor>
      <webMaster>fjvbn2003@gmail.com (Youngju Kim)</webMaster>
      <lastBuildDate>Mon, 25 May 2026 00:00:00 GMT</lastBuildDate>
      <atom:link href="https://www.youngju.dev/tags/distroless/feed.xml" rel="self" type="application/rss+xml"/>
      
  <item>
    <guid>https://www.youngju.dev/blog/culture/2026-05-25-container-security-trivy-grype-snyk-sysdig-tetragon-falco-cosign-sigstore-2026-deep-dive.en</guid>
    <title>Container &amp; Supply-Chain Security in 2026 — Trivy / Grype / Snyk / Sysdig / Tetragon / Falco / Cosign / Sigstore Deep Dive</title>
    <link>https://www.youngju.dev/blog/culture/2026-05-25-container-security-trivy-grype-snyk-sysdig-tetragon-falco-cosign-sigstore-2026-deep-dive.en</link>
    <description>After the 2024 xz backdoor and the 2025 entry into force of the EU Cyber Resilience Act, container supply-chain security is no longer &quot;scan and forget&quot;. This is a May 2026 map of the full stack — Trivy/Grype/Snyk/Sysdig image scanners, Tetragon/Falco eBPF runtime security, Cosign/Sigstore keyless signing, in-toto/SLSA levels 1-4, CycloneDX/SPDX SBOMs, distroless images, gVisor/Kata sandboxes, and OPA Gatekeeper vs Kyverno admission controllers.</description>
    <pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate>
    <author>fjvbn2003@gmail.com (Youngju Kim)</author>
    <category>container-security</category><category>trivy</category><category>grype</category><category>snyk</category><category>sysdig</category><category>tetragon</category><category>falco</category><category>cosign</category><category>sigstore</category><category>sbom</category><category>slsa</category><category>distroless</category><category>gvisor</category><category>kata-containers</category><category>opa</category><category>kyverno</category>
  </item>

  <item>
    <guid>https://www.youngju.dev/blog/culture/2026-05-25-container-security-trivy-grype-snyk-sysdig-tetragon-falco-cosign-sigstore-2026-deep-dive.ja</guid>
    <title>コンテナ&amp;サプライチェーンセキュリティ 2026 ディープダイブ — Trivy / Grype / Snyk / Sysdig / Tetragon / Falco / Cosign / Sigstore 総まとめ</title>
    <link>https://www.youngju.dev/blog/culture/2026-05-25-container-security-trivy-grype-snyk-sysdig-tetragon-falco-cosign-sigstore-2026-deep-dive.ja</link>
    <description>2024年のxzバックドア事件と2025年のEU CRA(サイバーレジリエンス法)施行を経て、コンテナのサプライチェーンセキュリティはもはや「スキャンして終わり」ではない。Trivy/Grype/Snyk/Sysdigイメージスキャナー、Tetragon/Falco eBPFランタイムセキュリティ、Cosign/Sigstoreキーレス署名、in-toto/SLSAレベル1〜4、CycloneDX/SPDX SBOM、distrolessイメージ、gVisor/Kataサンドボックス、OPA Gatekeeper対Kyvernoアドミッションコントローラまで——2026年5月時点のサプライチェーンセキュリティ・フルスタック地図。</description>
    <pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate>
    <author>fjvbn2003@gmail.com (Youngju Kim)</author>
    <category>container-security</category><category>trivy</category><category>grype</category><category>snyk</category><category>sysdig</category><category>tetragon</category><category>falco</category><category>cosign</category><category>sigstore</category><category>sbom</category><category>slsa</category><category>distroless</category><category>gvisor</category><category>kata-containers</category><category>opa</category><category>kyverno</category>
  </item>

  <item>
    <guid>https://www.youngju.dev/blog/culture/2026-05-25-container-security-trivy-grype-snyk-sysdig-tetragon-falco-cosign-sigstore-2026-deep-dive</guid>
    <title>컨테이너 &amp; 공급망 보안 2026 딥다이브 — Trivy / Grype / Snyk / Sysdig / Tetragon / Falco / Cosign / Sigstore 총정리</title>
    <link>https://www.youngju.dev/blog/culture/2026-05-25-container-security-trivy-grype-snyk-sysdig-tetragon-falco-cosign-sigstore-2026-deep-dive</link>
    <description>2024년 xz 백도어 사건과 2025년 EU CRA(Cyber Resilience Act) 발효 이후 컨테이너 공급망 보안은 더 이상 &quot;scan하고 끝&quot;이 아니다. Trivy/Grype/Snyk/Sysdig 이미지 스캐너, Tetragon/Falco eBPF 런타임 보안, Cosign/Sigstore 키리스 서명, in-toto/SLSA 1-4 단계, CycloneDX/SPDX SBOM, distroless 이미지, gVisor/Kata 샌드박스, OPA Gatekeeper vs Kyverno 어드미션 컨트롤러까지 — 2026년 5월 현재의 공급망 보안 풀스택 지도.</description>
    <pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate>
    <author>fjvbn2003@gmail.com (Youngju Kim)</author>
    <category>container-security</category><category>trivy</category><category>grype</category><category>snyk</category><category>sysdig</category><category>tetragon</category><category>falco</category><category>cosign</category><category>sigstore</category><category>sbom</category><category>slsa</category><category>distroless</category><category>gvisor</category><category>kata-containers</category><category>opa</category><category>kyverno</category>
  </item>

    </channel>
  </rss>
