Blog
Engineering notes on Kubernetes SBOMs, vulnerability scanning, and EU software compliance from the team building StackRadar.
· 6 min read
What the EU Cyber Resilience Act means for your Kubernetes SBOMs
The CRA makes machine-readable SBOMs and 24-hour vulnerability reporting a legal requirement for software sold in the EU — with reporting obligations starting September 2026. What Kubernetes platform teams actually need to have in place.
complianceCRASBOM· 7 min read
StackRadar vs Trivy Operator: managed fleet visibility vs in-cluster CRDs
Trivy Operator is excellent at what it does — in-cluster scanning with results as Kubernetes CRDs. An honest look at where that model works, where it runs out of road, and how StackRadar differs.
comparisonsTrivy Operator