The Continuous Delivery Foundation (CDF) announced three developments on May 8, 2023, at the start of cdCon + GitOpsCon in Vancouver: broader CDEvents adoption for interoperability, new Tekton software-supply-chain security capabilities, and Emporous as an Ortelius sub-project. The announcement describes the state of those projects at that date; it does not establish their current status.
Which “Project Momentum” announcement is this?
The identifiable source is CDF’s release, “CD Foundation Announces Significant Project Momentum at cdCon + GitOpsCon”, published May 8, 2023. The Linux Foundation published the same release here. The event took place in Vancouver on May 8–9, 2023.
CDF’s announcement grouped the news into three related areas rather than reporting one numerical performance result:
- CDEvents adoption by Jenkins, Spinnaker, Tekton and Testkube;
- new Tekton features aimed at software supply-chain security; and
- Emporous, introduced as an Ortelius sub-project for managing content and artifact metadata.
CDEvents: interoperability across delivery tools
CDF described CDEvents as a “vendor-neutral specification for defining the format of event data to provide interoperability across services, platforms, and systems.” The practical goal is to let delivery tools exchange consistently structured events instead of relying on one platform’s proprietary event model.
#1 Best Overall
| Project | Announcement-time status (May 8, 2023) |
|---|---|
| Jenkins | The CDEvents Plugin for Jenkins was available. |
| Tekton | An experimental CDEvents controller was available. |
| Spinnaker | CDEvents support was in progress. |
| Testkube | Test events had been introduced to enable Testkube support. |
These labels describe the implementation state reported in the 2023 release, not a guarantee that every integration remains at the same maturity level. Andrea Frittoli, IBM Open Source Developer Advocate and chair of the CDF Technical Oversight Committee, said: “I’m really thrilled about the progress made by the CDEvents community, as the specification is adopted by more and more tools and its development continues empowered by the collaboration and feedback of end users.”
The interoperability case was also emphasized by participating users and vendors. Ger McMahon, Product Area Leader for ALM Tools and Platforms at Fidelity Investments, said: “The CDEvents project is key to enabling interoperability, which in turn simplifies the process of safely and securely delivering value to customers.” Frank Kelly, Head of Network Automation at Ericsson Software Technology, described the need for “innovative and simplified software and service deployment” underpinned by interoperability.
Testkube’s Product Manager Bruno Lopes added: “The Testkube team is proud to be part of this effort together with the CDF, both in crafting the specification and providing an initial implementation.”
Tekton’s announced supply-chain security additions
The release highlighted four Tekton developments. They were presented as announcement-time capabilities, so the list should not be read as a current feature matrix.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Rank #3
SLSA Level 2 support with Tekton Chains
Tekton Chains was announced with support for SLSA Level 2. Chains is Tekton’s component for generating and signing provenance and other supply-chain metadata around pipeline results; the CDF release tied that capability to the SLSA framework’s Level 2 requirements.
Sigstore support leaving experimental status
The announcement said Tekton’s Sigstore support was moving out of its experimental phase. Sigstore provides keyless signing and verification workflows designed to reduce the operational burden of managing long-lived signing keys. Billy Lynch, a Chainguard software engineer and maintainer of projects for Sigstore and Tekton Chains, explained the benefit this way: “Being able to sign artifacts without needing to worry about keys goes a long way to help developers secure their supply chains without needing to worry about the complexities of key management.”
Rank #4
Trusted Resources
Tekton Trusted Resources was included among the new security features. In the announcement’s context, the feature addressed trust in the resources consumed by a pipeline, extending supply-chain controls beyond the output artifact itself.
Reusable Catalog tasks on Artifact Hub
The release also pointed to reusable Tekton Catalog tasks made available through Artifact Hub. Shared tasks can provide standardized building blocks for pipelines, while publication through a common catalog gives teams a discoverable distribution point. Teams still need to review task provenance, permissions and maintenance before using a task in a production pipeline.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Al Huizenga, Tekton product manager at Google Cloud, summarized the rationale: “Developers need to have the right foundational patterns in place to create a secure software supply chain.”
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Emporous and its relationship to Ortelius
CDF introduced Emporous as an open-source toolkit and an Ortelius sub-project, initially created by open-source contributors at Red Hat. Its announced purpose was to manage different content types in a unified system and to store, organize and search software-artifact metadata alongside the artifacts themselves.
That positioning is distinct from CDEvents’ event interoperability and Tekton’s pipeline security features. Emporous was described as a metadata and content-management layer within the broader delivery ecosystem, not as a replacement for a CI/CD engine. The release does not establish whether Emporous remains active, has changed scope, or is available under the same terms today.
What the announcement does—and does not—prove
What it establishes
- CDF was publicly reporting coordinated progress across event interoperability, Tekton security and artifact metadata at cdCon + GitOpsCon in May 2023.
- CDEvents had named integrations or integration work involving Jenkins, Spinnaker, Tekton and Testkube, with different maturity labels for each.
- Tekton’s announced security set included SLSA Level 2 support with Chains, Sigstore support moving beyond experimental status, Trusted Resources and catalog tasks on Artifact Hub.
- Emporous was introduced as an Ortelius sub-project with a unified content and artifact-metadata management goal.
What it does not establish
- It provides no headline adoption, performance or deployment statistic.
- It is not a current compatibility or availability guide for any of the named projects.
- It does not mean every team must use the same CI/CD platform; the interoperability work was intended to let different tools exchange events.
Why the three announcements were presented together
The initiatives address different layers of a software-delivery system. CDEvents defines how systems communicate delivery events; Tekton’s features add provenance, signing and trusted-input controls inside pipeline workflows; Emporous organizes the metadata and content associated with software artifacts. Taken together, they describe an ecosystem approach in which independently developed tools can exchange signals, produce verifiable outputs and make those outputs easier to track.
For readers evaluating the news today, the safest interpretation is historical: this was CDF’s May 2023 progress report, not a promise that the projects’ APIs, maturity labels or governance have remained unchanged.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




