Software/ platforms

Minimus Announces General Availability of Supply Chain Protection and minicli

Minimus Launches Supply Chain Protection & minicli

Minimus today announced the general availability of two new capabilities that help organizations secure software dependencies and manage custom container images as code: Minimus Supply Chain Protection and minicli.

Minimus Supply Chain Protection addresses the challenge of securely using the tens of millions of packages from the application package universe. These packages have thousands of interwoven dependencies, are often maintained by a single developer, and are updated far less frequently than operating system packages. Existing approaches to secure these packages such as malware scanning and building from source are limited in coverage and scale given the size and complexity of the ecosystems. 

Minimus Supply Chain Protection instead acts as a policy enforcement layer that sits between developers and public package repositories, allowing organizations to evaluate, control, and audit application dependencies before they are consumed by developers or CI/CD pipelines. A risk score for each package is assembled through an evaluation of package metadata, including commits, popularity, and use of a cooling-off period. Minimus provides default policies based on these risk factors, while exposing the underlying controls for teams that want to configure their own thresholds, allowlists, and blocklists.

Implemented as a pull-through proxy for NPM and PyPI, Supply Chain Protection operates with no impact on the developer experience, while giving security and platform teams visibility into package usage and the ability to enforce package trust policies across environments.

Customers can build multiple configurations with varying risk tolerance for environments and teams with different security priorities. Supply Chain Protection is supported by Minimus Actions, allowing customers to be notified of policy violations with varying enforcement levels and severities. A full audit log of policies and their impacts is available in a unified view across the platform.

Minimus minicli allows Minimus customers to extend both the visibility of custom images to their own local terminals and manage the full recipe for those images as code. With minicli, customers can view and manage existing private images, inspect custom image structures including additional packages, file bundles, and environment variables, export and version-control image configurations as YAML files, and trigger and monitor new image builds. 

This enables teams to integrate image management into existing Git-based workflows and CI/CD pipelines, bringing the same automation and change control used for application and infrastructure code to custom container images. minicli is available to download publicly via API for macOS and Linux on amd and arm platforms.

Minimus Supply Chain Protection and minicli are both available now. When combined with Minimus Images, which already remove 98%+ of vulnerabilities in container base images, customers can now apply consistent security controls across both the OS package layer and the application dependency layer. They can also manage the full recipe for those builds as code, fitting into any and all technology stacks that use container images.

Explore AITechPark for the latest advancements in AI, IOT, Cybersecurity, AITech News, and insightful updates from industry experts!

GlobeNewswire

GlobeNewswire is one of the world's largest newswire distribution networks, specializing in the delivery of corporate press releases financial disclosures and multimedia content to the media, investment community, individual investors and the general public.

Related posts

Magewell Releases Centralized Encoder/Decoder Management Software

PR Newswire

DoControl Joins AWS ISV Accelerate Program

PR Newswire

L.E.K. acquires award winning London consultancy Hi Mum! Said Dad

PR Newswire