foundation
autocert
foundation | autocert | |
---|---|---|
12 | 10 | |
526 | 2,941 | |
1.7% | 0.6% | |
9.4 | 8.1 | |
5 days ago | 9 days ago | |
Rich Text Format | Go | |
GNU General Public License v3.0 or later | BSD 3-clause "New" or "Revised" License |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
foundation
- Update code-of-conduct.md to resolve CNCF out of compliance activity
-
Ask HN: Canonical Dicussions for OSS Projects?
A mature open source project may be governed under an open source foundation which usually gives it a charter https://github.com/cncf/foundation/blob/main/charter.md#3-va...
... and/or set of values: https://kubernetes.io/community/values/
There's also a lot of open source guides here https://todogroup.org/resources/guides/ that may help you if you're looking at building mature open source projects.
-
OpenTF Announces Fork of Terraform
The CNCF has made exceptions on their license policy before, specifically for MPL based software. It'll probably be easier for OpenTF to go through that process than to relicense (which is likely not even possible for anyone other than Hashicorp).
- https://github.com/cncf/foundation/tree/main/license-excepti...
- https://github.com/cncf/foundation/blob/main/license-excepti...
- ebpf 月报 - 2023 年 1 月
-
Cubernetes
Your comment or post were removed for violating the CNCF Code of Conduct. Please take a moment to review that here: https://github.com/cncf/foundation/blob/master/code-of-conduct.md
-
A call to the open source community for help!
His behavior offends me as a professional software engineer and/ in my opinion, violates CNCF Code of Conduct https://github.com/cncf/foundation/blob/master/code-of-conduct.md.
-
Is Cloud Native meaningless jargon?
Anyone can become a member. Non-profit as in https://github.com/cncf/foundation/blob/master/charter.md
-
Cloud Native design
Read more about role of the CNCF, their projects and Values here.
- CNCF: Third Party Dependencies that have been Relicensed to AGPL
-
Minio Changes License to AGPL
https://github.com/cncf/foundation/blob/master/allowed-third...
I haven't read the details, or ever seen this policy before (I'm new to both projects) but it was summarized by one of our counterparts at the Linux Foundation here:
https://twitter.com/cra/status/1384859663615864833
Tl;dr: licenses must be approved for use, and the CNCF has this list of allowed licenses, AGPL is not on it. The CNCF is in the business of distributing permissively-licensed software is the short version I guess. I don't understand, I don't work on the legal side, I am a dev and I support end users.
It seems if your Apache 2.0 licensed project needs to modify and distribute as modified Grafana, which it seems likely we will need to do at some point, then you cannot distribute them together. Chris says they are going to work something out, but when a component has made a decision to re-license with a restrictive-copyleft license such as AGPL, I don't know what there is that can be done.
Maybe the CNCF adopts AGPL too, (which would mean that then all those "viral-GPL" FUD-spreaders will have been right...) that seems counter-productive if that is the outcome.
autocert
-
Current bcrypt is problematic I find. Made changes to core functionality. Looking for feedback
Pull request link
- GOlang ile şifreleme işlemleri için crypto paketi
- Argon2 or Argon2id still recommended over Bcrypt for Password Hashing?
-
SHA-3 Buffer Overflow
The version in the Golang stdlib is a pure-go implementation, but there's an assembler variant optimized for amd64 (https://github.com/golang/crypto/blob/master/sha3/keccakf_am...), which is apparently derived from the XKCP package.
Bad news for the (mostly-Golang) Ethereum ecosystem...
-
Web dev learning path advice
Learn crypto library and how to encrypt and hash: https://github.com/golang/crypto
-
Hashing password
In last section we have created users table in our database, but we are currently storing user's password in plain text. This is something we should never do, and instead we need to store hashed password with random salt. For that we will use golang/crypto library. First we need to expand our User structure:
- Minio Changes License to AGPL
-
SIEC elliptic curve vs other better known ones ?
So in conclusion, croc seems to be pretty secure as long as you use P-256 (or P-384). Internally, the standard golang.org/x/crypto library is used, which I can guarantee is very secure, as it is used in millions of web servers around the world, and Go is a language maintained by Google, which has many security professionals at their disposal. Ultimately, the decision is yours. While I can give you my opinion and point you to correct documents, you should trust nobody other than yourself. Not even me. But still, I recommend P-256 above everything else.
-
Crowdsourcing for healthcare tool accepting DOGE as payment feedback
I've been considering developing suck tools with Golang. Golang's crypto package golang crypto might be a great starting point if your familiar with language.
-
how does bcrypt.CompareHash function know which cost to select?
https://github.com/golang/crypto/blob/eec23a3978adcfd26c29f4153eaa3e3d9b2cc53a/bcrypt/bcrypt.go#L234-L254
What are some alternatives?
netboot.xyz - Your favorite operating systems in one place. A network-based bootable operating system installer based on iPXE.
lego - Let's Encrypt/ACME client and library written in Go
PIVX - Protected Instant Verified Transactions - Core wallet.
bitwarden-go - A Bitwarden-compatible server written in Golang
minio - The Object Store for AI Data Infrastructure
Themis - Easy to use cryptographic framework for data protection: secure messaging with forward secrecy and secure data storage. Has unified APIs across 14 platforms.
dash - Dash - Reinventing Cryptocurrency
simple-scrypt - A convenience library for generating, comparing and inspecting password hashes using the scrypt KDF in Go 🔑
toc - ⚖️ The CNCF Technical Oversight Committee (TOC) is the technical governing body of the CNCF Foundation.
acmetool - :lock: acmetool, an automatic certificate acquisition tool for ACME (Let's Encrypt)
manifesto - The OpenTF Manifesto expresses concern over HashiCorp's switch of the Terraform license from open-source to the Business Source License (BSL) and calls for the tool's return to a truly open-source license.
BadActor - BadActor.org An in-memory application driven jailer written in Go