Wolfi OS: i-distro eyenzelwe izikhongozeli kunye nekhonkco lokubonelela

wolfi os

I-Wolfi lusasazo lwesoftware ye-GNU ekhaphukhaphu eyilwe malunga ne-minimalism, iyenza ilungele indawo ezigcinwe kuyo.

Ukuba ungomnye wabo basebenza kakhulu ngezikhongozeli, ndingacebisa ukuba ufunde eli nqaku lilandelayo apho siza kuthetha ngeWolfi OS, eyindawo entsha yokuhanjiswa kweLinux edibanisa eyona miba ibalaseleyo yemifanekiso ekhoyo yesiseko sesikhongozeli kunye nemilinganiselo yokhuseleko engagqibekanga. ukuba Ziya kubandakanya iisignesha zesoftware enikwe amandla eSigstore, ukuvela, kunye neeBOM zesoftware.

I-Wolfi OS lusasazo oluhluthiweyo lwenzelwe ixesha lendalo yamafu. Ayinayo i-kernel eyeyayo, kodwa kunoko ixhomekeke kwindawo engqongileyo (efana nexesha lesikhongozeli) ukunika enye. Olu lwahlulo lweenkxalabo eWolfi luthetha ukuba lulungelelaniswa nezicwangciso ezahlukeneyo.

Malunga Wolfi OS

Kwindawo yayo yokugcina kwi-GitHub sinokufumanisa ukuba:

I-Chainguard iqalise iprojekthi ye-Wolfi ukuze ikwazi ukudalwa kweMifanekiso ye-Chainguard, ingqokelela yethu yemifanekiso egciniweyo yokusasazwa ehlangabezana neemfuno zekhonkco lokubonelela ngesoftware ekhuselekileyo. Oku kufuna unikezelo lwe Linux enamalungu kubumbudumbudu obufanelekileyo kunye nenkxaso yazo zombini i-glibc kunye ne-musl, into engekafumaneki kwi-ecosystem ye-Linux yelifu.

Kukwakhankanyiwe ukuba uWolvi, ogama lakhe liphefumlelwe ngu eyona ngwane incinci emhlabeni, ineempawu ezithile eziphambili Yintoni eyahlulayo kwezinye ii-distros ezigxile kwindalo yelifu/yesiqulathi:

  • Ibonelela ngomgangatho ophezulu wokuqokelela-ixesha le-SBOM njengomgangatho wazo zonke iipakethi
  • Iipakethi zenzelwe ukuba zibe yigranular kunye nokuzimela, ukuxhasa imifanekiso encinci
  • Isebenzisa ifomathi ye-apk ezanyiweyo nethembekileyo
  • Inkqubo yokwakha echaza ngokupheleleyo kunye nenokuphinda ivelise kwakhona
  • Yenzelwe ukuxhasa i-glibc kunye ne-musl

Kufanelekile ukuba ukhankanye loo nto UWolfi OS lusasazo lweLinux yenzelwe zisuka nje kwasekuqaleni, oko kukuthi, akusekelwe kulo naluphi na olunye unikezelo olukhoyo kwaye lujoliswe ekuxhaseni iiparadigms zekhompyutha ezintsha, ezifana nezikhongozeli.

Nangona Wolfi inemigaqo yoyilo efanayo kwiAlpine (ezifana nokusebenzisa i-apk), yi-distro eyahlukileyo egxile kukhuseleko lwekhonkco lonikezelo. Ngokungafaniyo neAlpine, uWolvi okwangoku akazakhi eyakhe i-Linux kernel, kodwa endaweni yoko uxhomekeke kwindawo ehlala kuyo (umzekelo, ixesha lokuqhuba isikhongozeli) ukunika enye.

Kwaye kungenxa yokuba umdali weWolfi ukhuseleko lwekhonkco lokubonelela ngesoftware lukhethekile, kuba ukhankanya ukuba uneentlobo ezininzi zohlaselo ezinokujolisa amanqaku amaninzi ahlukeneyo kumjikelo wobomi besoftware. Awunakuthatha nje iqhekeza lesoftware yokhuseleko, uyivule, kwaye uzikhusele kuyo yonke into.

“Sibhekisa kuWolvi njenge-undistro kuba ayilulo usasazo olupheleleyo lweLinux eyenzelwe ukusebenza ngentsimbi engenanto, kodwa endaweni yokusasazwa okuhluthiweyo okwenzelwe ixesha lendalo yamafu. Okona kubaluleke kakhulu, asizange siyifake i-Linux kernel, kodwa endaweni yoko sithembele kwimo engqongileyo (efana ne-container runtime) ukuyibonelela," utshilo uDan Lorenc, i-CEO ye-Chainguard.

Ukongeza, ukuhanjiswa kweLinux ngokwabo ngokuqhelekileyo kukhulula kuphela iinguqulelo ezizinzileyo zesoftware ixesha elide, ngelixa abaphuhlisi abafakela isoftware (kwakhona) befaka ukufakwa ngesandla ukuze bafumane ezona mva, okanye iinguqulelo zamva nje. Ngenxa yoko, kukho uqhagamshelo olukhulu phakathi kwento enokubonwa ngabaskena ngee-CVEs zokhuseleko lwesoftware kwaye yintoni ekhoyo kwindawo eqhelekileyo.

UWolfi uthatha imifanekiso ehlaziywa rhoqo yezikhongozeli ezisisiseko oko kujoliswe kuko ubuthathaka obaziwayo, Ukuphelisa oku kulibaziseka phakathi konikezelo oluqhelekileyo kunye nemifanekiso yesikhongozeli, kunye nabasebenzisi abasebenzisa imifanekiso enobuthathaka obaziwayo. ingcuka vala lo msantsa ukuqinisekisa ukuba Imifanekiso yesikhongozeli inolwazi lweprovenance (apho imifanekiso ivela kwaye iqinisekisa ukuba ayiphazamiseki) kwaye yenza isizukulwana se-SBOM into enokuthi yenzeke ngexesha lokwakha, kwaye kungekhona ekupheleni.

ekugqibeleni ukuba ukhona unomdla wokwazi ngakumbi ngayo malunga noku kukhutshwa okutsha, ungakhangela iinkcukacha kwi eli khonkco lilandelayo.


Yiba ngowokuqala ukuphawula

Shiya uluvo lwakho

Idilesi yakho ye email aziyi kupapashwa. ezidingekayo ziphawulwe *

*

*

  1. Inoxanduva lwedatha: I-AB Internet Networks 2008 SL
  2. Injongo yedatha: Ulawulo lwe-SPAM, ulawulo lwezimvo.
  3. Umthetho: Imvume yakho
  4. Unxibelelwano lwedatha: Idatha ayizukuhanjiswa kubantu besithathu ngaphandle koxanduva lomthetho.
  5. Ukugcinwa kweenkcukacha
  6. Amalungelo: Ngalo naliphi na ixesha unganciphisa, uphinde uphinde ucime ulwazi lwakho.