# Continuous hardening of Chainguard's internal software supply chain

DevFeed: [Continuous hardening of Chainguard's internal software supply chain](<https://devfeed.tech/articles/continuous-hardening-of-chainguard-s-internal-software-supply-chain-13013.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/continuous-hardening-of-chainguards-internal-software-supply-chain>)

Published: 2024-02-21T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [Security](<https://devfeed.tech/topics/security.md>), [Docker Compose](<https://devfeed.tech/topics/docker-compose.md>), [Terraform](<https://devfeed.tech/topics/terraform.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [cosign](<https://devfeed.tech/tags/cosign.md>), [github](<https://devfeed.tech/tags/github.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [github-vulnerability](<https://devfeed.tech/tags/github-vulnerability.md>), [hardending](<https://devfeed.tech/tags/hardending.md>), [hardened-images](<https://devfeed.tech/tags/hardened-images.md>), [hardening](<https://devfeed.tech/tags/hardening.md>), [integrity](<https://devfeed.tech/tags/integrity.md>), [least-privilege](<https://devfeed.tech/tags/least-privilege.md>), [minimalism](<https://devfeed.tech/tags/minimalism.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [terraform-provider](<https://devfeed.tech/tags/terraform-provider.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

## AI overview

Chainguard describes how it mitigated a potentially vulnerable GitHub Actions workflow that could have affected the integrity of Docker images signed by its cosign Terraform Provider. The team responded within 24 hours and explains how least privilege, minimal defaults, and dependency minimization support software supply chain security.

## Source excerpt

See how Chainguard mitigated the potential vulnerable GitHub actions workflow "Pwn request" in less than 24 hours.