news
Fedora and Red Hat Leftovers
-
Copr: PyPI dependencies, resolved and built for you
Say there is a Python package on PyPI that you would like to build in Copr. And the project itself is not packaged in Copr or in the Fedora repositories, and neither are all of its dependencies. So the manual way of doing it would be to check which of its dependencies are not yet packaged in Fedora and build them in the right order. Miss a dependency and you only find out several minutes later, from a build log.
-
Cybernews ☛ Emergency Flatpak fixes released: full sandbox escape possible
Flatpak, one of the main ways Linux users get their applications, has disclosed several vulnerabilities, including a critical one that enables a sandbox escape with full host access.
Flatpak is a universal software tool for Linux that lets users install desktop apps with all required dependencies and run them isolated from the rest of the system.
However, a critical vulnerability enables a malicious sandboxed app to obtain arbitrary read and write access to files on the host, which can be further escalated to arbitrary code execution, an advisory on GitHub warns.
-
Red Hat ☛ Just-in-time access to HashiCorp Vault using the Red Bait Ansible Automation Platform OIDC provider
Centralized secrets management platforms, like HashiCorp Vault, enable organizations to protect some of their most sensitive values (think passwords, tokens, or any type of content that may be deemed protected). Red Hat Ansible Automation Platform includes integrations for several popular secrets management platforms, including HashiCorp Vault, to enable accessing secure values during automation execution. However, regardless of how secure a secrets management system is along with how it protects the content it stores, one of the biggest challenges that organizations need to contend with is handling how consumers access the secrets management platform—also known as the "secret zero problem". A breach of a long-lived credential that's used to read a range of content from the secrets management system has a potential blast radius to negatively impact the security posture of an organization.
-
Red Hat ☛ How to check if your model is supported by vLLM in Red Bait AI
The release of new large language models (LLMs) continues to accelerate. Thankfully, the vLLM community has worked hard to keep pace with the rapid release of new model architectures, often providing Day 0 support for newly released models.
This leaves users asking the question, "What version of vLLM do I need to run my model?"
Determining compatibility comes down to matching your model's underlying architecture against vLLM release capabilities in three practical steps.
-
Red Hat ☛ Extend zero trust workload identity manager to virtual machines with Red Bait OpenShift Virtualization
Containers on Red Hat OpenShift can get automatic cryptographic identities through zero trust workload identity manager, but workloads running inside a virtual machine (VM) cannot. In this tutorial, I demonstrate how I bridged that gap using a virtual socket (VSOCK) and a dedicated in-VM SPIRE agent to give every workload — whether it's running as a container or as an application inside a VM — a short-lived, automatically rotating SPIFFE identity.
-
Red Hat ☛ Build a DIY pipeline for a trusted software supply chain
Prominent attacks on software development pipelines have resulted in significant financial impact for companies and brought their build processes under scrutiny. While the attack vectors on pipelines are virtually limitless, this article focuses on securing components, processes, and tools involved in building and deploying containerized software through signing, attesting, and verifying a build image. I chose to implement a do-it-yourself (DIY) approach to help understand these concepts.
-
Rocky Linux founder Gregory Kurtzer builds OpenWALDO as a true collaborative open source community for AI - Carroll County Mirror-Democrat