-Content by TechnologyNewswire-
Minimus today announced the general availability of two new capabilities that help organisations secure software dependencies and manage custom container images as code: Minimus Supply Chain Protection and minicli.
Minimus Supply Chain Protection addresses the challenge of securely using the tens of millions of packages from the application package universe. These packages have thousands of interwoven dependencies, are often maintained by a single developer and are updated far less frequently than operating system packages. Existing approaches to secure these packages such as malware scanning and building from source are limited in coverage and scale given the size and complexity of the ecosystems.
Minimus Supply Chain Protection instead acts as a policy enforcement layer that sits between developers and public package repositories, allowing organisations to evaluate, control, and audit application dependencies before they are consumed by developers or CI/CD pipelines.
A risk score for each package is assembled through an evaluation of package metadata, including commits, popularity, and use of a cooling-off period. Minimus provides default policies based on these risk factors, while exposing the underlying controls for teams that want to configure their own thresholds, allowlists and blocklists.
More from News
- England’s New Tourist Tax Has No National Cap – What Does That Mean For Hospitality Businesses?
- The EU Cyber Resilience Act Starts Today: Can Businesses Really Report A Cyberattack In 24 Hours?
- Can Binge-Watching Be Addictive By Design? Inside The State Lawsuit Against Netflix
- Could Australia’s Proposed Algorithm Rule Break The Current Echo Chamber That Is Social Media Today?
- PASS Announces Schedule Hero: AI-Powered Scheduling Built For Home Care
- Portal26 Launches Recon: Ask Any Plain Language Question To Deliver Immediate, Actionable Answers To Any Question About AI Use In The Enterprise
- When AI Goes AWOL: What Should We Conclude From ChatGPT, Claude And Grok’s Simultaneous Outage?
- Will Mandatory App Redesigns Replace Fines As The EU’s Main Weapon Against Big Tech?
Implemented as a pull-through proxy for NPM and PyPI, Supply Chain Protection operates with no impact on the developer experience, while giving security and platform teams visibility into package usage and the ability to enforce package trust policies across environments.
Customers can build multiple configurations with varying risk tolerance for environments and teams with different security priorities. Supply Chain Protection is supported by Minimus Actions, allowing customers to be notified of policy violations with varying enforcement levels and severities. A full audit log of policies and their impacts is available in a unified view across the platform.
Minimus minicli allows Minimus customers to extend both the visibility of custom images to their own local terminals and manage the full recipe for those images as code. With minicli, customers can view and manage existing private images, inspect custom image structures including additional packages, file bundles, and environment variables, export and version-control image configurations as YAML files, and trigger and monitor new image builds.
This enables teams to integrate image management into existing Git-based workflows and CI/CD pipelines, bringing the same automation and change control used for application and infrastructure code to custom container images. minicli is available to download publicly via API for macOS and Linux on amd and arm platforms.
-This is a paid press release published via TechnologyNewswire-
