/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Google, IBM, and others announce Grafeas, an open-source API that gives users a standardized way for auditing and governing their software supply chain

Notes: A note is an item or condition … Google Cloud Platform Blog : Introducing Grafeas: An open-source API to audit and govern your software supply chain Tom Krazit / GeekWire : New open-source project led by Google aims to help companies track the history of their software John Morello / Twistlock : Building a Secure Software Supply Chain with Twistlock and Google's Grafeas Mike Wheatley / SiliconANGLE : Google and friends open-source Grafeas API to clean up software supply chains Katie Roof / TechCrunch : CarGurus spikes 72% in auto marketplace IPO Tweets: @coreos : CoreOS is proud to support Grafeas, Google's new open source project for image security & app lifecycle governance http://cloudplatform.googleblog.com/ ... Sean Kerner / @techjournalist : More than just an API, also a Policy engine - but kinda reminds me of Docker Content Trust http://www.eweek.com/... http://twitter.com/...

TechCrunch Frederic Lardinois

Context & Ripple Effects

Grafeas arrives six months after Google published its internal open-source documentation and processes, extending the same transparency instinct from how Google runs projects to how anyone can audit the components inside their software. The launch is a coalition play rather than a solo one: IBM co-announces, CoreOS publicly pledges support, and Twistlock's John Morello ships an integration showing how a security vendor plugs its scanning data into the new API.

First-order effects

  • Enterprises adopting containers gain a single standardized metadata format for tracking image provenance and vulnerabilities, instead of stitching together per-vendor audit trails.
  • Security vendors like Twistlock get a neutral write-target for their findings, making their tooling interoperable with any platform that speaks Grafeas rather than locked to one dashboard.

Second-order effects

Third-order effects

  • If standardized provenance metadata becomes default infrastructure, supply-chain governance shifts from a per-purchase compliance exercise to a property of the pipeline itself — the direction policy attention later followed when Google proposed an open-source maintenance marketplace after the White House security summit.
  • Open standards led by hyperscalers set up a recurring tension: the audit layer is common, but whoever operates the attestation service captures the trust relationship with enterprises.

The trend: Software supply-chain security is moving from ad-hoc vendor audits to shared open metadata standards that cloud providers then productize into paid assurance offerings.