# Chainguard's CTO on why every build needs an identity

DevFeed: [Chainguard's CTO on why every build needs an identity](<https://devfeed.tech/articles/chainguard-s-cto-on-why-every-build-needs-an-identity-58066.md>)

Original publisher: [Read original article](<https://1password.com/blog/software-supply-chain-identity-security>)

Author: info@1password.com (Chris Fowler)

Published: 2026-09-08T00:00:00Z

Content type: article

Language: en

Sources: [1Password](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Risk](<https://devfeed.tech/topics/risk.md>), [.env](<https://devfeed.tech/topics/dotenv.md>)

Tags: [access-controls](<https://devfeed.tech/tags/access-controls.md>), [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [cto](<https://devfeed.tech/tags/cto.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [developers](<https://devfeed.tech/tags/developers.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [podcasts](<https://devfeed.tech/tags/podcasts.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>)

## AI overview

A podcast discussion with Chainguard CTO Matt Moore examines how software supply chain security intersects with identity and scoped access. It covers risks from open-source dependencies, base images, stolen credentials, and AI coding agents, and argues that teams should verify what enters a build, who changed it, and which credentials workflows can access.

## Source excerpt

How build identity and scoped access secure software Zero-Shot Learning is a podcast about how AI is built, secured, and deployed. Hosted by Nancy Wang, 1Password CTO, and Dev Tagare, Senior Director of Engineering at Google Gemini, it offers a builder's view of the architecture and complex decisions involved in shipping AI. Matt Moore, co-founder and CTO of Chainguard, joined the podcast to discuss the overlap between open-source software supply chain security and identity and access controls. Modern applications depend on open-source packages, base images, and tools that most teams don't maintain internally. When one of those dependencies is vulnerable, compromised, or published using stolen credentials, the compromise can move through the build and into software that reaches production. As AI coding agents gain authority, they introduce a new layer of uncertainty to the software development lifecycle. Matt argued that before shipping, teams need to know what enters a build, who or what changed it, and which credentials the workflow can access. Most of what you ship is inherited Developing with open-source projects includes known security risks. For teams working under time constraints, open-source projects provide packages, runtimes, tools, and the images they need to build applications and jumpstart a build, but those components also become part of the software an organization must inventory and update. Across industries, open-source software is a critical building block of the software supply chain. Black Duck's 2026 Open Source Security and Risk Analysis Report found open-source components in 98% of the 947 audited codebases it analyzed. The amount of software that we actually write to ship modern applications is this tiny tip of the iceberg, compared to what we're actually running in our environments." -Matt Moore, co-founder and CTO, Chainguard To help developers make safe choices, many organizations create approved package lists, internal registries, depend