CNCF Brings In Notary, The Update Framework to Boost Container Security

Home / Press Highlights / CNCF Brings In Notary, The Update Framework to Boost Container Security

The Cloud Native Computing Foundation on Oct. 24 announced that it is expanding its project roster with the addition of the Notary container trust project and The Update Framework security effort. Notary relies on TUF, which is a software development and update model that was described in detail by co-creator Justin Cappos, an assistant professor at New York University, at the DockerCon 17 conference in April. “If you have the green HTTPS padlock in your browser, it tells you the browser has a secure connection to a server,’ Cappos said. ‘It doesn’t say anything about whether the server has a valid update or know what the correct update is and whether the server itself has been compromised.”