# chainguard containers

Published articles for chainguard containers.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Proven, not promised: Chainguard Containers achieves SLSA Build Level 3

DevFeed: [Proven, not promised: Chainguard Containers achieves SLSA Build Level 3](<https://devfeed.tech/articles/proven-not-promised-chainguard-containers-achieves-slsa-build-level-3-13206.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/proven-not-promised-chainguard-containers-achieves-slsa-build-level-3>)

Published: 2026-08-17T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [software bill of materials](<https://devfeed.tech/topics/software-bill-of-materials.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [security](<https://devfeed.tech/tags/security.md>), [signing](<https://devfeed.tech/tags/signing.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>)

### AI overview

Chainguard says Coalfire independently assessed the Chainguard Containers build and release system as meeting SLSA Build Level 3 requirements. The article describes hardened, isolated builds, separately managed signing, provenance generation, and signed SBOMs for releases.

### Source excerpt

Coalfire independently assessed Chainguard Containers at SLSA Build Level 3, validating hardened builds, provenance, and supply chain integrity.

## Why zero CVEs matters in mobile airgapped deployments

DevFeed: [Why zero CVEs matters in mobile airgapped deployments](<https://devfeed.tech/articles/why-zero-cves-matters-in-mobile-airgapped-deployments-13334.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/why-zero-cves-matters-in-mobile-airgapped-deployments>)

Published: 2026-07-28T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Containers](<https://devfeed.tech/topics/containers.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cves](<https://devfeed.tech/tags/cves.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article explains why disconnected mobile and air-gapped systems become increasingly exposed as vulnerabilities accumulate while patching and live feeds are unavailable. It argues that starting with low-CVE container images and refreshing them before departure can reduce the vulnerability backlog, citing Chainguard Containers' stated CVE reduction and daily rebuild practices.

### Source excerpt

Disconnected systems can't patch. Learn how minimal, zero-CVE containers help reduce vulnerability accumulation in air-gapped environments.

## Mitigating WordPress attacks with containers

DevFeed: [Mitigating WordPress attacks with containers](<https://devfeed.tech/articles/mitigating-wordpress-attacks-with-containers-13164.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/mitigating-wordpress-attacks-with-containers>)

Published: 2026-07-27T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [WordPress](<https://devfeed.tech/topics/wordpress.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [containers](<https://devfeed.tech/tags/containers.md>), [database](<https://devfeed.tech/tags/database.md>), [distroless](<https://devfeed.tech/tags/distroless.md>), [files](<https://devfeed.tech/tags/files.md>), [hardened-containers](<https://devfeed.tech/tags/hardened-containers.md>), [remote-code-execution](<https://devfeed.tech/tags/remote-code-execution.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [wordpress](<https://devfeed.tech/tags/wordpress.md>), [wordpress-cves](<https://devfeed.tech/tags/wordpress-cves.md>)

### AI overview

This article examines the wp2shell attack, in which two WordPress vulnerabilities can be chained to achieve remote code execution. It explains that hardened, distroless containers and read-only filesystems can limit an attacker's capabilities and simplify recovery, while emphasizing the need to update WordPress immediately.

### Source excerpt

The wp2shell WordPress exploit enables remote code execution. Learn how hardened containers help reduce the blast radius of compromise.

## Booz Allen Hamilton signs enterprise license agreement with Chainguard

DevFeed: [Booz Allen Hamilton signs enterprise license agreement with Chainguard](<https://devfeed.tech/articles/booz-allen-hamilton-signs-enterprise-license-agreement-with-chainguard-12897.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/booz-allen-hamilton-signs-enterprise-license-agreement-with-chainguard>)

Published: 2026-07-21T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [chainguard libraries](<https://devfeed.tech/topics/chainguard-libraries.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Development](<https://devfeed.tech/topics/development.md>)

Tags: [announce](<https://devfeed.tech/tags/announce.md>), [ato](<https://devfeed.tech/tags/ato.md>), [authority-to-operate](<https://devfeed.tech/tags/authority-to-operate.md>), [booz-allen-hamilton](<https://devfeed.tech/tags/booz-allen-hamilton.md>), [booz-allen-hamilton-engineering](<https://devfeed.tech/tags/booz-allen-hamilton-engineering.md>), [booz-chainguard-partnership](<https://devfeed.tech/tags/booz-chainguard-partnership.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-booz](<https://devfeed.tech/tags/chainguard-booz.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [development](<https://devfeed.tech/tags/development.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [government](<https://devfeed.tech/tags/government.md>), [partner](<https://devfeed.tech/tags/partner.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [trust](<https://devfeed.tech/tags/trust.md>), [us](<https://devfeed.tech/tags/us.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Booz Allen Hamilton has signed an enterprise license agreement with Chainguard, giving more than 6,000 engineers access to Chainguard Containers and Chainguard Libraries across U.S. government programs. The agreement is intended to support secure-by-default software delivery, vulnerability remediation, compliance, and software supply chain requirements.

### Source excerpt

Booz Allen and Chainguard partner to help 6,000+ engineers deliver secure-by-default software across U.S. government programs.

## This Shit is Hard: Getting software to run on robots (and then getting the robots to work)

DevFeed: [This Shit is Hard: Getting software to run on robots (and then getting the robots to work)](<https://devfeed.tech/articles/this-shit-is-hard-getting-software-to-run-on-robots-and-then-getting-the-robots-to-work-13280.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/this-shit-is-hard-getting-software-to-run-on-robots>)

Published: 2026-07-01T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Robotics](<https://devfeed.tech/topics/robotics.md>), [Software](<https://devfeed.tech/topics/software.md>), [Embedded Software Dev](<https://devfeed.tech/topics/embedded-software-dev.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [asylon-robotics](<https://devfeed.tech/tags/asylon-robotics.md>), [autonomous](<https://devfeed.tech/tags/autonomous.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-customer](<https://devfeed.tech/tags/chainguard-customer.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [cloud-infrastructure](<https://devfeed.tech/tags/cloud-infrastructure.md>), [critical-infrastructure](<https://devfeed.tech/tags/critical-infrastructure.md>), [drone](<https://devfeed.tech/tags/drone.md>), [embedded](<https://devfeed.tech/tags/embedded.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [firewalls](<https://devfeed.tech/tags/firewalls.md>), [hardware](<https://devfeed.tech/tags/hardware.md>), [robot-dogs](<https://devfeed.tech/tags/robot-dogs.md>), [robot-drones](<https://devfeed.tech/tags/robot-drones.md>), [robotics](<https://devfeed.tech/tags/robotics.md>), [robots](<https://devfeed.tech/tags/robots.md>), [software](<https://devfeed.tech/tags/software.md>), [this-shit-is-hard](<https://devfeed.tech/tags/this-shit-is-hard.md>)

### AI overview

Asylon Robotics Chief Engineer Eric Timmons explains the engineering challenges of deploying software on robotic dogs and drones, where embedded systems, hardware dependencies, CI/CD, cloud infrastructure, and real-world operating conditions interact.

### Source excerpt

Asylon Robotics Chief Engineer Eric Timmons shares lessons from building autonomous robots, where software, hardware, and real-world constraints collide.

## The State of Trusted Open Source: June 2026

DevFeed: [The State of Trusted Open Source: June 2026](<https://devfeed.tech/articles/the-state-of-trusted-open-source-june-2026-13271.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/the-state-of-trusted-open-source-june-2026>)

Published: 2026-06-30T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Open Source](<https://devfeed.tech/topics/open-source.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [ai](<https://devfeed.tech/tags/ai.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-data](<https://devfeed.tech/tags/cve-data.md>), [cves](<https://devfeed.tech/tags/cves.md>), [data](<https://devfeed.tech/tags/data.md>), [dependency](<https://devfeed.tech/tags/dependency.md>), [java](<https://devfeed.tech/tags/java.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [nginx](<https://devfeed.tech/tags/nginx.md>), [node](<https://devfeed.tech/tags/node.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [python](<https://devfeed.tech/tags/python.md>), [report](<https://devfeed.tech/tags/report.md>), [security](<https://devfeed.tech/tags/security.md>), [software](<https://devfeed.tech/tags/software.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [state-of-trusted-open-source](<https://devfeed.tech/tags/state-of-trusted-open-source.md>), [trends](<https://devfeed.tech/tags/trends.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

Chainguard's June 2026 report analyzes vulnerability data from more than 2,400 container image projects and 18,016 vulnerability instances observed from March through May 2026. It reports 886 distinct CVEs, with 63.1% of observed instances classified as high severity, and examines how AI-assisted development and security research are affecting software supply-chain risk.

### Source excerpt

AI is accelerating vulnerability discovery. Explore the latest trusted open source trends, dependency risks, and CVE insights from Chainguard's report.

## Everything we announced during AI Readiness Innovation Week

DevFeed: [Everything we announced during AI Readiness Innovation Week](<https://devfeed.tech/articles/everything-we-announced-during-ai-readiness-innovation-week-13033.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/everything-we-announced-during-ai-readiness-innovation-week>)

Published: 2026-06-25T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [ai-coding](<https://devfeed.tech/topics/ai-coding.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [chainguard libraries](<https://devfeed.tech/topics/chainguard-libraries.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [Frontier AI](<https://devfeed.tech/topics/frontier-ai.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-readiness](<https://devfeed.tech/tags/ai-readiness.md>), [athena](<https://devfeed.tech/tags/athena.md>), [aws-kiro](<https://devfeed.tech/tags/aws-kiro.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cursor](<https://devfeed.tech/tags/cursor.md>), [frontier-ai-models](<https://devfeed.tech/tags/frontier-ai-models.md>), [gartner-magic-quadrant](<https://devfeed.tech/tags/gartner-magic-quadrant.md>), [github](<https://devfeed.tech/tags/github.md>), [innovation](<https://devfeed.tech/tags/innovation.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [speed](<https://devfeed.tech/tags/speed.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Chainguard summarizes announcements from AI Readiness Innovation Week, covering supply-chain security advances for containers, libraries, CI/CD pipelines, AI agent skills, IDE integrations, partnerships, and an industry coalition. The article highlights Athena, a coalition designed to coordinate defense against vulnerabilities discovered by frontier AI models.

### Source excerpt

Read about everything Chainguard announced during AI Readiness Innovation Week, including new features for Chainguard Libraries and Chainguard Containers.

## Adopt hardened containers without changing your pipelines, tooling, or environment

DevFeed: [Adopt hardened containers without changing your pipelines, tooling, or environment](<https://devfeed.tech/articles/adopt-hardened-containers-without-changing-your-pipelines-tooling-or-environment-12865.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/adopt-hardened-containers-without-changing-your-pipelines-tooling-or-environment>)

Published: 2026-06-24T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Containers](<https://devfeed.tech/topics/containers.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [Security](<https://devfeed.tech/topics/security.md>), [Deployment](<https://devfeed.tech/topics/deployment.md>), [Tooling](<https://devfeed.tech/topics/tooling.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-redhat-rpm](<https://devfeed.tech/tags/chainguard-redhat-rpm.md>), [cmvp](<https://devfeed.tech/tags/cmvp.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cyclonedx](<https://devfeed.tech/tags/cyclonedx.md>), [dependabot](<https://devfeed.tech/tags/dependabot.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [fips](<https://devfeed.tech/tags/fips.md>), [hardened-containers](<https://devfeed.tech/tags/hardened-containers.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [rhel](<https://devfeed.tech/tags/rhel.md>), [rhel-10](<https://devfeed.tech/tags/rhel-10.md>), [rhel-9](<https://devfeed.tech/tags/rhel-9.md>), [rpm-10](<https://devfeed.tech/tags/rpm-10.md>), [rpm-9](<https://devfeed.tech/tags/rpm-9.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Chainguard announces updates to Chainguard Containers that support enterprise adoption of hardened images without changing existing pipelines, tooling, or environments. The updates include RPM support for RHEL 9 and RHEL 10, compatible image tags, a CMVP-validated Go Geomys FIPS image, Dependabot support for private registries, and flattened CycloneDX SBOMs for compliance tools.

### Source excerpt

Chainguard expands Containers with RPM support, FIPS enhancements, and easier migrations, bringing secure-by-default software to enterprise workflows.

## How Chainguard uses AI agents to enforce engineering standards across a monorepo

DevFeed: [How Chainguard uses AI agents to enforce engineering standards across a monorepo](<https://devfeed.tech/articles/this-shit-is-hard-how-ai-keeps-our-code-on-standard-13282.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/this-shit-is-hard-how-ai-keeps-our-code-on-standard>)

Published: 2026-06-24T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Bot](<https://devfeed.tech/topics/bot.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Pull Request](<https://devfeed.tech/topics/pull-request.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>)

Tags: [agentic](<https://devfeed.tech/tags/agentic.md>), [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-agent-skills](<https://devfeed.tech/tags/chainguard-agent-skills.md>), [chainguard-agents](<https://devfeed.tech/tags/chainguard-agents.md>), [chainguard-ai](<https://devfeed.tech/tags/chainguard-ai.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-engineering](<https://devfeed.tech/tags/chainguard-engineering.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [ci](<https://devfeed.tech/tags/ci.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [github](<https://devfeed.tech/tags/github.md>), [policy](<https://devfeed.tech/tags/policy.md>), [pull-request](<https://devfeed.tech/tags/pull-request.md>), [workflow](<https://devfeed.tech/tags/workflow.md>)

### AI overview

Chainguard describes a system of specialized AI agents built on DriftlessAF that continuously checks code against machine-readable engineering standards, fixes drift, and supports CI repair. Over eight weeks, it opened more than 4,700 standards-fix pull requests; 75% judged low-risk were auto-merged when AI judgment agreed with deterministic checks.

### Source excerpt

Chainguard uses AI-powered agents to continuously enforce engineering standards, remediate drift, and keep codebases aligned at scale.

## Chainguard plug-in now available on Cursor Marketplace

DevFeed: [Chainguard plug-in now available on Cursor Marketplace](<https://devfeed.tech/articles/chainguard-plug-in-now-available-on-cursor-marketplace-12976.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-plug-in-now-available-on-cursor-marketplace>)

Published: 2026-06-24T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [cursor](<https://devfeed.tech/topics/cursor.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [AI-assisted coding](<https://devfeed.tech/topics/ai-assisted-coding.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [ai-coding-agents](<https://devfeed.tech/tags/ai-coding-agents.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-cursor](<https://devfeed.tech/tags/chainguard-cursor.md>), [chainguard-cursor-marketplace](<https://devfeed.tech/tags/chainguard-cursor-marketplace.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cursor](<https://devfeed.tech/tags/cursor.md>), [cursor-chainguard-containers](<https://devfeed.tech/tags/cursor-chainguard-containers.md>), [cursor-chainguard-libraries](<https://devfeed.tech/tags/cursor-chainguard-libraries.md>), [libraries](<https://devfeed.tech/tags/libraries.md>), [mcp](<https://devfeed.tech/tags/mcp.md>), [plugin](<https://devfeed.tech/tags/plugin.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

Chainguard has launched a plugin on the Cursor Marketplace that connects Cursor to Chainguard Containers, Chainguard Libraries, and the Chainguard Repository. The plugin is intended to make secure-by-default artifacts available in AI coding workflows and help agents remediate known vulnerabilities.

### Source excerpt

Connect Cursor to Chainguard in minutes and make secure, malware-resistant containers and libraries the default for AI-generated code.

## Building a category: Chainguard named a Leader in the inaugural Gartner® Magic Quadrant™ for Software Supply Chain Security

DevFeed: [Building a category: Chainguard named a Leader in the inaugural Gartner® Magic Quadrant™ for Software Supply Chain Security](<https://devfeed.tech/articles/building-a-category-chainguard-named-a-leader-in-the-inaugural-gartner-magic-quadranttm-for-software-supply-chain-security-12901.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/building-a-category-chainguard-named-a-leader-in-the-inaugural-gartner-magic-quadrant-for-software-supply-chain-security>)

Published: 2026-06-22T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Security](<https://devfeed.tech/topics/security.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [chainguard libraries](<https://devfeed.tech/topics/chainguard-libraries.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-gartner](<https://devfeed.tech/tags/chainguard-gartner.md>), [chainguard-gartner-mq](<https://devfeed.tech/tags/chainguard-gartner-mq.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [gartner](<https://devfeed.tech/tags/gartner.md>), [gartner-magic-quadrant](<https://devfeed.tech/tags/gartner-magic-quadrant.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [software-supply-chain-security-gartner](<https://devfeed.tech/tags/software-supply-chain-security-gartner.md>), [software-supply-chain-security-mq](<https://devfeed.tech/tags/software-supply-chain-security-mq.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

Chainguard's article discusses its recognition as a Leader in Gartner's inaugural Magic Quadrant for Software Supply Chain Security. It argues that accelerating vulnerability exploitation and AI-assisted development require prevention-oriented, secure-by-default supply chain security. The article highlights Chainguard Containers, which provides minimal container images rebuilt daily from source, with zero CVEs, SBOMs, and verifiable signatures, and briefly introduces Chainguard Libraries.

### Source excerpt

Gartner names Chainguard a Leader in Software Supply Chain Security, highlighting its secure-by-default approach and market vision.

## The Maintainer of Last Resort

DevFeed: [The Maintainer of Last Resort](<https://devfeed.tech/articles/the-maintainer-of-last-resort-13262.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/the-maintainer-of-last-resort>)

Published: 2026-06-22T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Open Source](<https://devfeed.tech/topics/open-source.md>), [Maintainers](<https://devfeed.tech/topics/maintainers.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Software](<https://devfeed.tech/topics/software.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>)

Tags: [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [chainguard-open-source](<https://devfeed.tech/tags/chainguard-open-source.md>), [emertioss](<https://devfeed.tech/tags/emertioss.md>), [maintainers](<https://devfeed.tech/tags/maintainers.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-maintainer](<https://devfeed.tech/tags/open-source-maintainer.md>), [oss](<https://devfeed.tech/tags/oss.md>), [providers](<https://devfeed.tech/tags/providers.md>), [software](<https://devfeed.tech/tags/software.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Chainguard proposes a Maintainer of Last Resort as a neutral backstop for abandoned open source projects. The model would fork vulnerable packages, apply fixes, publish verifiable builds, and handle future vulnerability disclosures when upstream maintainers cannot respond in time.

### Source excerpt

Chainguard proposes a Maintainer of Last Resort to patch abandoned open source projects, publish trusted builds, and keep critical software secure.

## Introducing the Chainguard cinc-auditor image: STIG scanning for Chainguard Containers, ready to run

DevFeed: [Introducing the Chainguard cinc-auditor image: STIG scanning for Chainguard Containers, ready to run](<https://devfeed.tech/articles/introducing-the-chainguard-cinc-auditor-image-stig-scanning-for-chainguard-containers-ready-to-run-13123.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/introducing-the-chainguard-cinc-auditor-image-stig-scanning-for-chainguard-containers-ready-to-run>)

Published: 2026-06-18T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [anchore](<https://devfeed.tech/topics/anchore.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [anchore](<https://devfeed.tech/tags/anchore.md>), [anchore-enterprise](<https://devfeed.tech/tags/anchore-enterprise.md>), [apache](<https://devfeed.tech/tags/apache.md>), [built-from-source](<https://devfeed.tech/tags/built-from-source.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [cinc-auditor](<https://devfeed.tech/tags/cinc-auditor.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [pipeline](<https://devfeed.tech/tags/pipeline.md>), [scanner](<https://devfeed.tech/tags/scanner.md>), [stig](<https://devfeed.tech/tags/stig.md>), [stigs](<https://devfeed.tech/tags/stigs.md>)

### AI overview

Chainguard introduces a ready-to-run cinc-auditor container image for STIG scanning of Chainguard Containers. The image includes a maintained GPOS SRG InSpec profile, removes separate profile and dependency setup, and supports production compliance pipelines, including FedRAMP workflows.

### Source excerpt

Chainguard launches a ready-to-run STIG scanner with a built-in GPOS SRG InSpec profile, simplifying compliance scans for containers and FedRAMP workflows.

## Faster than the advisory

DevFeed: [Faster than the advisory](<https://devfeed.tech/articles/faster-than-the-advisory-13041.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/faster-than-the-advisory>)

Published: 2026-06-10T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [argo-cd](<https://devfeed.tech/topics/argo-cd.md>), [GitOps](<https://devfeed.tech/topics/gitops.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [chainguard os](<https://devfeed.tech/topics/chainguard-os.md>), [anthropic](<https://devfeed.tech/topics/anthropic.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [anthropic](<https://devfeed.tech/tags/anthropic.md>), [argo-cd](<https://devfeed.tech/tags/argo-cd.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-os](<https://devfeed.tech/tags/chainguard-os.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [gitops](<https://devfeed.tech/tags/gitops.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [scanner-advisories](<https://devfeed.tech/tags/scanner-advisories.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

The article explains how Chainguard Factory delivered a patched Argo CD version to Wolfi and Chainguard OS before the related security advisory reached GitHub's global advisory database. It argues that automated upstream tracking and rapid remediation are increasingly important because vulnerability exploitation and AI-assisted discovery are outpacing traditional disclosure timelines.

### Source excerpt

Chainguard often ships security fixes before advisories reach scanners. Learn why upstream speed matters in the era of AI-driven exploits.

## Miasma Phantom Gyp npm attack: 57 packages, 286 malicious versions hijack CI/CD pipelines via binding.gyp

DevFeed: [Miasma Phantom Gyp npm attack: 57 packages, 286 malicious versions hijack CI/CD pipelines via binding.gyp](<https://devfeed.tech/articles/miasma-phantom-gyp-npm-attack-57-packages-286-malicious-versions-hijack-ci-cd-pipelines-via-binding-gyp-12928.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-artifacts-safe-from-miasma-phantom-gyp-npm-attack>)

Published: 2026-06-05T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [npm packages](<https://devfeed.tech/topics/npm-packages.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Security](<https://devfeed.tech/topics/security.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [npm](<https://devfeed.tech/topics/npm.md>), [chainguard libraries](<https://devfeed.tech/topics/chainguard-libraries.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-actions](<https://devfeed.tech/tags/chainguard-actions.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [malware](<https://devfeed.tech/tags/malware.md>), [miasma](<https://devfeed.tech/tags/miasma.md>), [npm-security](<https://devfeed.tech/tags/npm-security.md>), [packages](<https://devfeed.tech/tags/packages.md>), [phantom-gyp](<https://devfeed.tech/tags/phantom-gyp.md>), [shai-hulud](<https://devfeed.tech/tags/shai-hulud.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>)

### AI overview

This article describes the Miasma Phantom Gyp npm supply-chain attack, in which attackers published 286 malicious versions across 57 packages. The self-replicating worm targeted CI/CD pipelines, harvested credentials, poisoned additional packages, modified workflows, and planted backdoor configurations in AI coding assistant directories. It also explains that Chainguard customers were protected because Chainguard Libraries builds from source and blocked the malicious versions.

### Source excerpt

A new npm supply chain worm compromised 57 packages and 286 versions. Learn how Chainguard blocked the attack and protected customers by design.

## AI-driven zero-day combinations are challenging software security and open-source consumption

DevFeed: [AI-driven zero-day combinations are challenging software security and open-source consumption](<https://devfeed.tech/articles/the-hardest-fork-13253.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/the-hardest-fork>)

Published: 2026-05-28T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Machine Learning, Security Attacks](<https://devfeed.tech/topics/machine-learning-security-attacks.md>), [Critical Infrastructure](<https://devfeed.tech/topics/critical-infrastructure.md>), [openssf](<https://devfeed.tech/topics/openssf.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [anthropic-mythos](<https://devfeed.tech/tags/anthropic-mythos.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [critical-infrastructure](<https://devfeed.tech/tags/critical-infrastructure.md>), [fork](<https://devfeed.tech/tags/fork.md>), [mfa](<https://devfeed.tech/tags/mfa.md>), [mythos](<https://devfeed.tech/tags/mythos.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [openssf](<https://devfeed.tech/tags/openssf.md>), [oss](<https://devfeed.tech/tags/oss.md>), [project-glasswing](<https://devfeed.tech/tags/project-glasswing.md>), [rust](<https://devfeed.tech/tags/rust.md>), [sast](<https://devfeed.tech/tags/sast.md>), [secure-open-source](<https://devfeed.tech/tags/secure-open-source.md>), [security](<https://devfeed.tech/tags/security.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>)

### AI overview

The article argues that Mythos represents a potential new class of software-security threat: AI-driven combinations of existing issues that can produce more serious attacks than individual scanner findings. It discusses the limits of government regulation and calls for stronger trust infrastructure, coordinated disclosure, and safer open-source consumption.

### Source excerpt

Mythos is changing software security fast. AI-driven zero-days demand new trust infrastructure, coordinated disclosure, and secure open source consumption.

## 5 security myths that Mythos ended (as told by a CISO)

DevFeed: [5 security myths that Mythos ended (as told by a CISO)](<https://devfeed.tech/articles/5-security-myths-that-mythos-ended-as-told-by-a-ciso-12854.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/5-security-myths-that-mythos-ended-as-told-by-a-ciso>)

Published: 2026-05-27T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [anthropic](<https://devfeed.tech/topics/anthropic.md>), [dataset](<https://devfeed.tech/topics/dataset.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-security](<https://devfeed.tech/tags/ai-security.md>), [anthropic](<https://devfeed.tech/tags/anthropic.md>), [anthropic-mythos-preview](<https://devfeed.tech/tags/anthropic-mythos-preview.md>), [chainguard-ai](<https://devfeed.tech/tags/chainguard-ai.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [cve](<https://devfeed.tech/tags/cve.md>), [dataset](<https://devfeed.tech/tags/dataset.md>), [exploits](<https://devfeed.tech/tags/exploits.md>), [git](<https://devfeed.tech/tags/git.md>), [mythos](<https://devfeed.tech/tags/mythos.md>), [project-glasswing](<https://devfeed.tech/tags/project-glasswing.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article argues that Anthropic's Mythos and broader AI-driven vulnerability discovery are invalidating long-standing security assumptions. It focuses on shrinking exploitation timelines, the growing importance of proactive vulnerability elimination, and the need for security teams to retire reactive mental models.

### Source excerpt

Mythos and AI-driven exploits are breaking old security assumptions. Learn the five myths security teams must retire to survive the new era.

## Preparing for Mythos: Practical advice for engineering teams

DevFeed: [Preparing for Mythos: Practical advice for engineering teams](<https://devfeed.tech/articles/preparing-for-mythos-practical-advice-for-engineering-teams-13203.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/preparing-for-mythos-practical-advice-for-engineering-teams>)

Published: 2026-05-26T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [ai security](<https://devfeed.tech/topics/ai-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [anthropic](<https://devfeed.tech/topics/anthropic.md>), [exploit chaining](<https://devfeed.tech/topics/exploit-chaining.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [cURL](<https://devfeed.tech/topics/curl.md>)

Tags: [advice](<https://devfeed.tech/tags/advice.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-security](<https://devfeed.tech/tags/ai-security.md>), [ai-vulnerability-remediation](<https://devfeed.tech/tags/ai-vulnerability-remediation.md>), [anthropic](<https://devfeed.tech/tags/anthropic.md>), [article](<https://devfeed.tech/tags/article.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-for-ai](<https://devfeed.tech/tags/chainguard-for-ai.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [exploit-chaining](<https://devfeed.tech/tags/exploit-chaining.md>), [exploits](<https://devfeed.tech/tags/exploits.md>), [mythos](<https://devfeed.tech/tags/mythos.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [work](<https://devfeed.tech/tags/work.md>)

### AI overview

This opinion assesses the security implications of Anthropic's Mythos model and argues that defenders should use AI-assisted methods to identify and remediate vulnerabilities. It says Mythos appears especially capable at exploiting vulnerabilities and chaining exploits, while a test on curl found one new non-critical vulnerability.

### Source excerpt

Anthropic's Mythos raises the stakes for software security. Learn how to survive faster exploits with secure-by-default supply chains and AI-assisted defense.

## Building for the AI era: Chainguard partners with Endor Labs

DevFeed: [Building for the AI era: Chainguard partners with Endor Labs](<https://devfeed.tech/articles/building-for-the-ai-era-chainguard-partners-with-endor-labs-12905.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/building-for-the-ai-era-chainguard-partners-with-endor-labs>)

Published: 2026-05-19T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [AI-assisted coding](<https://devfeed.tech/topics/ai-assisted-coding.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Library](<https://devfeed.tech/topics/library.md>), [Agent Skill](<https://devfeed.tech/topics/agent-skill.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-coding-agents](<https://devfeed.tech/tags/ai-coding-agents.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cves](<https://devfeed.tech/tags/cves.md>), [endor](<https://devfeed.tech/tags/endor.md>), [endor-labs](<https://devfeed.tech/tags/endor-labs.md>), [observability](<https://devfeed.tech/tags/observability.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Chainguard partners with Endor Labs to help teams building with AI coding agents secure the software supply chain. Chainguard provides source-built artifacts, daily rebuilds, signed SBOMs, and SLSA Level 3 provenance, while Endor Labs analyzes application context to identify vulnerabilities that are genuinely reachable and exploitable.

### Source excerpt

Chainguard and Endor Labs help teams build securely at AI speed with source-built artifacts, exploitability analysis, and fewer vulnerabilities to triage.

## Canada's CPCSC and Bill C-8 are coming. Here's what you need to do.

DevFeed: [Canada's CPCSC and Bill C-8 are coming. Here's what you need to do.](<https://devfeed.tech/articles/canada-s-cpcsc-and-bill-c-8-are-coming-here-s-what-you-need-to-do-12917.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/canadas-cpcsc-and-bill-c-8-are-coming-heres-what-you-need-to-do>)

Published: 2026-05-14T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Critical Infrastructure](<https://devfeed.tech/topics/critical-infrastructure.md>), [Security](<https://devfeed.tech/topics/security.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Cloud Native Ecosystem](<https://devfeed.tech/topics/cloud-native-ecosystem.md>)

Tags: [bill-c-8](<https://devfeed.tech/tags/bill-c-8.md>), [canada-cmmc](<https://devfeed.tech/tags/canada-cmmc.md>), [canadian-program-for-cyber-security-certification](<https://devfeed.tech/tags/canadian-program-for-cyber-security-certification.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [cmmc](<https://devfeed.tech/tags/cmmc.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cpcsc](<https://devfeed.tech/tags/cpcsc.md>), [critical-infrastructure](<https://devfeed.tech/tags/critical-infrastructure.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [federal-compliance](<https://devfeed.tech/tags/federal-compliance.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [nist](<https://devfeed.tech/tags/nist.md>), [zero-cve-containers](<https://devfeed.tech/tags/zero-cve-containers.md>)

### AI overview

This article explains Canada's Canadian Program for Cyber Security Certification (CPCSC) and Bill C-8, focusing on the implications for defence suppliers and organizations in critical infrastructure. It describes the CPCSC as a mandatory cybersecurity certification regime, compares its technical basis with CMMC and NIST Special Publications 800-171 and 800-172, and outlines why organizations should prepare for Level 1 requirements. The article also describes how Chainguard can help Canadian defence suppliers meet those requirements with secure, zero-CVE containers.

### Source excerpt

CPCSC compliance is coming fast. Learn how Chainguard helps Canadian defence suppliers meet Level 1 requirements with secure, zero-CVE containers.

## Luck isn't a security control: What happened with mini Shai-Hulud and what you need to do

DevFeed: [Luck isn't a security control: What happened with mini Shai-Hulud and what you need to do](<https://devfeed.tech/articles/luck-isn-t-a-security-control-what-happened-with-mini-shai-hulud-and-what-you-need-to-do-13141.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/luck-isnt-a-security-control-what-happened-with-mini-shai-hulud-and-what-you-need-to-do>)

Published: 2026-05-13T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [npm](<https://devfeed.tech/topics/npm.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [AI-assisted coding](<https://devfeed.tech/topics/ai-assisted-coding.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>)

Tags: [ai-coding-agents](<https://devfeed.tech/tags/ai-coding-agents.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [github](<https://devfeed.tech/tags/github.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [mini-shai-hulud](<https://devfeed.tech/tags/mini-shai-hulud.md>), [npm](<https://devfeed.tech/tags/npm.md>), [packages](<https://devfeed.tech/tags/packages.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [python](<https://devfeed.tech/tags/python.md>), [security](<https://devfeed.tech/tags/security.md>), [shai-hulud](<https://devfeed.tech/tags/shai-hulud.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [worm](<https://devfeed.tech/tags/worm.md>)

### AI overview

This article examines the mini Shai-Hulud supply chain worm, which affected more than 400 packages. It argues that malicious code can enter during package build and distribution without a CVE, and that teams should strengthen preventive security across registries, GitHub Actions, CI/CD pipelines, dependencies, AI coding agents, and configuration files.

### Source excerpt

A new supply chain worm hit 400+ packages. Learn why preventive security, not reactive patching, is the only way to stop the next attack.

## Chainguard brings first-party RHEL 9 and RHEL 10 RPM support to Chainguard OS, joins FINOS

DevFeed: [Chainguard brings first-party RHEL 9 and RHEL 10 RPM support to Chainguard OS, joins FINOS](<https://devfeed.tech/articles/chainguard-brings-first-party-rhel-9-and-rhel-10-rpm-support-to-chainguard-os-joins-finos-12933.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-brings-first-party-rhel-9-and-rhel-10-rpm-support-to-chainguard-os-joins-finos>)

Published: 2026-05-11T00:00:00Z

Content type: news

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard os](<https://devfeed.tech/topics/chainguard-os.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [Security](<https://devfeed.tech/topics/security.md>), [Critical Infrastructure](<https://devfeed.tech/topics/critical-infrastructure.md>), [Package Management](<https://devfeed.tech/topics/package-management.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Cloud Native Ecosystem](<https://devfeed.tech/topics/cloud-native-ecosystem.md>), [Resilience](<https://devfeed.tech/topics/resilience.md>), [APK](<https://devfeed.tech/topics/apk.md>), [Linux](<https://devfeed.tech/topics/linux.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-finserv](<https://devfeed.tech/tags/chainguard-finserv.md>), [chainguard-os](<https://devfeed.tech/tags/chainguard-os.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cloud-native](<https://devfeed.tech/tags/cloud-native.md>), [compatibility](<https://devfeed.tech/tags/compatibility.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container](<https://devfeed.tech/tags/container.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [critical-infrastructure](<https://devfeed.tech/tags/critical-infrastructure.md>), [cve](<https://devfeed.tech/tags/cve.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [hardening](<https://devfeed.tech/tags/hardening.md>), [images](<https://devfeed.tech/tags/images.md>), [linux](<https://devfeed.tech/tags/linux.md>), [make](<https://devfeed.tech/tags/make.md>), [mythos](<https://devfeed.tech/tags/mythos.md>), [open](<https://devfeed.tech/tags/open.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [project-glasswing](<https://devfeed.tech/tags/project-glasswing.md>), [rhel](<https://devfeed.tech/tags/rhel.md>), [rhel-10](<https://devfeed.tech/tags/rhel-10.md>), [rhel-9](<https://devfeed.tech/tags/rhel-9.md>)

### AI overview

Chainguard announces first-party RHEL 9 and RHEL 10 RPM compatibility for packages in Chainguard Containers built on Chainguard OS. The company also announces that it is joining FINOS to support open source collaboration in financial infrastructure.

### Source excerpt

Chainguard adds first-party RHEL 9/10 RPM compatibility and joins FINOS, helping financial institutions modernize securely for the AI-driven threat era.

## Building the business case for a secure open source supply chain

DevFeed: [Building the business case for a secure open source supply chain](<https://devfeed.tech/articles/building-the-business-case-for-a-secure-open-source-supply-chain-12911.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/building-the-business-case-for-a-secure-open-source-supply-chain>)

Published: 2026-05-05T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Open Source](<https://devfeed.tech/topics/open-source.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [distributed-systems](<https://devfeed.tech/topics/distributed-systems.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [engineering-culture](<https://devfeed.tech/topics/engineering-culture.md>)

Tags: [chainguard-assemble](<https://devfeed.tech/tags/chainguard-assemble.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-customers](<https://devfeed.tech/tags/chainguard-customers.md>), [cloud-infrastructure](<https://devfeed.tech/tags/cloud-infrastructure.md>), [cloud-native](<https://devfeed.tech/tags/cloud-native.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [continuous-delivery](<https://devfeed.tech/tags/continuous-delivery.md>), [cves](<https://devfeed.tech/tags/cves.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [distributed-systems](<https://devfeed.tech/tags/distributed-systems.md>), [kyndryl](<https://devfeed.tech/tags/kyndryl.md>), [kyndryl-open-source](<https://devfeed.tech/tags/kyndryl-open-source.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [productivity](<https://devfeed.tech/tags/productivity.md>), [resilience](<https://devfeed.tech/tags/resilience.md>), [secure-open-source](<https://devfeed.tech/tags/secure-open-source.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article explains how organizations can build a business case for a secure open source supply chain. It describes a shift from framing open source security solely around CVEs, scanner results, and patching toward presenting trusted open source as a driver of productivity, resilience, and delivery speed. It also explains why traditional vulnerability management struggles with continuous delivery, distributed systems, frequently rebuilt container images, changing dependencies, and global cloud infrastructure.

### Source excerpt

Learn how Kyndryl reframed open source security as a business driver -- reducing risk, lowering costs, and accelerating developer productivity.

## How we automatically test the world's most secure Linux distribution

DevFeed: [How we automatically test the world's most secure Linux distribution](<https://devfeed.tech/articles/how-we-automatically-test-the-world-s-most-secure-linux-distribution-13098.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/how-we-automatically-test-the-worlds-most-secure-linux-distribution>)

Published: 2026-05-01T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [test-coverage](<https://devfeed.tech/topics/test-coverage.md>), [chainguard os](<https://devfeed.tech/topics/chainguard-os.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-os](<https://devfeed.tech/tags/chainguard-os.md>), [chainguard-packages](<https://devfeed.tech/tags/chainguard-packages.md>), [chainguard-testing](<https://devfeed.tech/tags/chainguard-testing.md>), [linux](<https://devfeed.tech/tags/linux.md>), [test-coverage](<https://devfeed.tech/tags/test-coverage.md>)

### AI overview

Chainguard OS has achieved 100% test coverage across its package and subpackage catalog. The automated tests execute software, verify behavior, and test service lifecycles across x86_64 and aarch64 packages before release.

### Source excerpt

Chainguard OS achieves 100% package test coverage, verifying every component runs correctly to make rolling updates secure, reliable, and enterprise-ready.

[Next page](<https://devfeed.tech/tags/chainguard-containers.md?cursor=WyIyMDI2LTA1LTAxVDAwOjAwOjAwKzAwOjAwIiwgIjgxYWM3MDVkLWZjZmEtNDY0OS1iMDA5LTJkMjE5MTEwYWIyMiJd>)