# chainguard enforce

Published articles for chainguard enforce.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Join Chainguard at KubeCon EU in Amsterdam April 19-21!

DevFeed: [Join Chainguard at KubeCon EU in Amsterdam April 19-21!](<https://devfeed.tech/articles/join-chainguard-at-kubecon-eu-in-amsterdam-april-19-21-13131.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/join-chainguard-at-kubecon-eu-in-amsterdam-april-19-21>)

Published: 2023-04-13T00:00:00Z

Content type: news

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [chainguard enforce](<https://devfeed.tech/topics/chainguard-enforce.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>), [SPIRE](<https://devfeed.tech/topics/spire.md>), [eBPF](<https://devfeed.tech/topics/ebpf.md>), [observability](<https://devfeed.tech/topics/observability.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-enforce](<https://devfeed.tech/tags/chainguard-enforce.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [cloud-native](<https://devfeed.tech/tags/cloud-native.md>), [cncf](<https://devfeed.tech/tags/cncf.md>), [cves](<https://devfeed.tech/tags/cves.md>), [ebpf](<https://devfeed.tech/tags/ebpf.md>), [kubecon](<https://devfeed.tech/tags/kubecon.md>), [kubecon-eu](<https://devfeed.tech/tags/kubecon-eu.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [linux-foundation](<https://devfeed.tech/tags/linux-foundation.md>), [observability](<https://devfeed.tech/tags/observability.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [security](<https://devfeed.tech/tags/security.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [spire](<https://devfeed.tech/tags/spire.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>)

### AI overview

Chainguard announces its participation in KubeCon EU 2023 in Amsterdam, including booth demonstrations of the Chainguard platform and Chainguard Images. The article highlights comparisons of minimal container image size and CVE counts, Chainguard Enforce visibility into deployed software and dependencies, and conference sessions on CI/CD security on Kubernetes, SLSA, Tekton, Sigstore, SPIRE, and Falco.

### Source excerpt

Join Chainguard at KubeCon EU in Amsterdam, April 19-21, for groundbreaking insights into cloud-native technologies.

## The role of attestations in a secure software supply chain

DevFeed: [The role of attestations in a secure software supply chain](<https://devfeed.tech/articles/the-role-of-attestations-in-a-secure-software-supply-chain-13269.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/the-role-of-attestations-in-a-secure-software-supply-chain>)

Published: 2023-04-04T00:00:00Z

Content type: tutorial

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard enforce](<https://devfeed.tech/topics/chainguard-enforce.md>), [Docker Verified Publisher](<https://devfeed.tech/topics/docker-verified-publisher.md>)

Tags: [attestation](<https://devfeed.tech/tags/attestation.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-enforce](<https://devfeed.tech/tags/chainguard-enforce.md>), [digital-signatures](<https://devfeed.tech/tags/digital-signatures.md>), [integrity](<https://devfeed.tech/tags/integrity.md>), [policy](<https://devfeed.tech/tags/policy.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [secure-software-supply-chain](<https://devfeed.tech/tags/secure-software-supply-chain.md>), [security-policies](<https://devfeed.tech/tags/security-policies.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [software-attestations](<https://devfeed.tech/tags/software-attestations.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>)

### AI overview

This article explains how attestations support software supply-chain policy enforcement. It describes attestations as signed claims from identified speakers about code or build results, allowing deployment systems to verify policy requirements without repeating expensive or impractical checks.

### Source excerpt

Chainguard Enforce enables policy enforcement using attestations. Learn how to use these principles to create and enforce secure supply chain policies.

## ICYMI: What's new in Chainguard Academy

DevFeed: [ICYMI: What's new in Chainguard Academy](<https://devfeed.tech/articles/icymi-what-s-new-in-chainguard-academy-13099.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/icymi-whats-new-in-chainguard-academy>)

Published: 2023-04-03T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [openvex](<https://devfeed.tech/topics/openvex.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-academy](<https://devfeed.tech/tags/chainguard-academy.md>), [chainguard-enforce](<https://devfeed.tech/tags/chainguard-enforce.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [openvex](<https://devfeed.tech/tags/openvex.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [sigstore-policy-controller](<https://devfeed.tech/tags/sigstore-policy-controller.md>), [software-education](<https://devfeed.tech/tags/software-education.md>), [software-security-practices](<https://devfeed.tech/tags/software-security-practices.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Chainguard Academy has expanded to more than 300 tutorials, documentation pages, and reference materials covering open source projects and Chainguard products. The article highlights resources for Chainguard Images and Wolfi Images, OpenVEX, SBOMs, and Sigstore policy-controller.

### Source excerpt

See what's new in Chainguard Academy to help you level up your software supply chain and open source security knowledge.

## Are Kubernetes Validating Admission Policies the end of admission controllers?

DevFeed: [Are Kubernetes Validating Admission Policies the end of admission controllers?](<https://devfeed.tech/articles/are-kubernetes-validating-admission-policies-the-end-of-admission-controllers-12889.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/are-kubernetes-validating-admission-policies-the-end-of-admission-controllers>)

Published: 2023-03-31T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [API](<https://devfeed.tech/topics/api.md>), [Structured-data](<https://devfeed.tech/topics/structured-data.md>)

Tags: [admission-controller](<https://devfeed.tech/tags/admission-controller.md>), [api](<https://devfeed.tech/tags/api.md>), [api-server](<https://devfeed.tech/tags/api-server.md>), [blog-post](<https://devfeed.tech/tags/blog-post.md>), [chainguard-enforce](<https://devfeed.tech/tags/chainguard-enforce.md>), [common-expression-language](<https://devfeed.tech/tags/common-expression-language.md>), [complexity](<https://devfeed.tech/tags/complexity.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [fragmentation](<https://devfeed.tech/tags/fragmentation.md>), [integration](<https://devfeed.tech/tags/integration.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [kubernetes-admission-controller](<https://devfeed.tech/tags/kubernetes-admission-controller.md>), [performance](<https://devfeed.tech/tags/performance.md>), [policy](<https://devfeed.tech/tags/policy.md>), [security-policies](<https://devfeed.tech/tags/security-policies.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [validation](<https://devfeed.tech/tags/validation.md>)

### AI overview

The article explains how Kubernetes Validating Admission Policies, introduced in alpha in Kubernetes 1.26, let users evaluate many admission checks natively in the API server using Google's Common Expression Language (CEL). It argues that these policies improve performance, reliability, and integration by reducing reliance on webhooks, while noting that admission controllers remain necessary for policies beyond CEL's deliberately restricted capabilities.

### Source excerpt

Validating Admission Policies are here in Kubernetes 1.26. Read on to learn how they work and what they mean for admission controllers.

## Imposter commits in GitHub Actions can bypass allowed workflow settings

DevFeed: [Imposter commits in GitHub Actions can bypass allowed workflow settings](<https://devfeed.tech/articles/what-the-fork-imposter-commits-in-github-actions-and-ci-cd-13319.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/what-the-fork-imposter-commits-in-github-actions-and-ci-cd>)

Published: 2023-03-08T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [GitOps](<https://devfeed.tech/topics/gitops.md>), [Git](<https://devfeed.tech/topics/git.md>), [Pull Request](<https://devfeed.tech/topics/pull-request.md>)

Tags: [chainguard-enforce](<https://devfeed.tech/tags/chainguard-enforce.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [fork](<https://devfeed.tech/tags/fork.md>), [github](<https://devfeed.tech/tags/github.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [github-vulnerability](<https://devfeed.tech/tags/github-vulnerability.md>), [gitops](<https://devfeed.tech/tags/gitops.md>), [pull-request](<https://devfeed.tech/tags/pull-request.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [workflow](<https://devfeed.tech/tags/workflow.md>)

### AI overview

Chainguard reports a GitHub Actions vulnerability in which commits from forked repositories can bypass allowed workflow settings. The article explains how GitHub fork and commit-sharing behavior enables these imposter commits and why they pose a CI/CD supply-chain security risk.

### Source excerpt

Chainguard found a vulnerability in GitHub Actions that bypasses allowed Workflow settings by using commits from forked repositories. Read the report.

## Chainguard's perspective on the National Cybersecurity Strategy and secure software development

DevFeed: [Chainguard's perspective on the National Cybersecurity Strategy and secure software development](<https://devfeed.tech/articles/charting-a-secure-by-default-future-13002.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/charting-a-secure-by-default-future>)

Published: 2023-03-02T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [software-development](<https://devfeed.tech/topics/software-development.md>), [Memory Safety](<https://devfeed.tech/topics/memory-safety.md>), [software bill of materials](<https://devfeed.tech/topics/software-bill-of-materials.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-enforce](<https://devfeed.tech/tags/chainguard-enforce.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [memory-safety](<https://devfeed.tech/tags/memory-safety.md>), [national-cybersecurity-strategy](<https://devfeed.tech/tags/national-cybersecurity-strategy.md>), [nist](<https://devfeed.tech/tags/nist.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [standards](<https://devfeed.tech/tags/standards.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Chainguard discusses the National Cybersecurity Strategy's implications for software liability and secure software development, highlighting SBOM tooling, NIST frameworks, memory-safe languages, and open source software security.

### Source excerpt

Chainguard's vision for a 'Secure by Default' future: Pioneering strategies to integrate security into the tech fabric.

## apko: a year later

DevFeed: [apko: a year later](<https://devfeed.tech/articles/apko-a-year-later-12887.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/apko-a-year-later>)

Published: 2023-02-28T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Development](<https://devfeed.tech/topics/development.md>), [Package manager](<https://devfeed.tech/topics/package-manager.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Unix](<https://devfeed.tech/topics/unix.md>), [YAML](<https://devfeed.tech/topics/yaml.md>), [Terraform](<https://devfeed.tech/topics/terraform.md>)

Tags: [alpine](<https://devfeed.tech/tags/alpine.md>), [apk](<https://devfeed.tech/tags/apk.md>), [apko](<https://devfeed.tech/tags/apko.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-enforce](<https://devfeed.tech/tags/chainguard-enforce.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [cloud-native](<https://devfeed.tech/tags/cloud-native.md>), [development](<https://devfeed.tech/tags/development.md>), [distroless](<https://devfeed.tech/tags/distroless.md>), [golang](<https://devfeed.tech/tags/golang.md>), [linux](<https://devfeed.tech/tags/linux.md>), [macos](<https://devfeed.tech/tags/macos.md>), [melange](<https://devfeed.tech/tags/melange.md>), [secure-software-supply-chain](<https://devfeed.tech/tags/secure-software-supply-chain.md>), [terraform-provider](<https://devfeed.tech/tags/terraform-provider.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>), [yaml](<https://devfeed.tech/tags/yaml.md>)

### AI overview

This article reviews apko one year after its public release. It describes apko's native Go implementation of the apk package manager, which runs on UNIX-like systems including macOS and BSDs, and explains how its declarative YAML interface helped support an ecosystem that includes Chainguard Images, Melange, Wolfi, and a Terraform provider. The article presents apko as a foundation for secure software supply chains through images-as-code and frequent image rebuilds.

### Source excerpt

Dive in to apko and learn more about the project; where it's been in the past year, and where it's going.

## SBOMs in a multi-architecture world

DevFeed: [SBOMs in a multi-architecture world](<https://devfeed.tech/articles/sboms-in-a-multi-architecture-world-13215.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/sboms-in-a-multi-architecture-world>)

Published: 2023-02-22T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [container images](<https://devfeed.tech/topics/container-images.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>)

Tags: [architecture](<https://devfeed.tech/tags/architecture.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-enforce](<https://devfeed.tech/tags/chainguard-enforce.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>)

### AI overview

This article explains how Chainguard handles SBOMs for multi-architecture container images. Each architecture-specific image carries its own standalone SBOM, while the image index avoids duplicating variant information and instead references the constituent metadata.

### Source excerpt

As the world becomes more architecturally diverse, we at Chainguard want to make sure our users are armed with the tools they need to remain secure.

## Chainguard named an IDC Innovator for open source software supply chain security

DevFeed: [Chainguard named an IDC Innovator for open source software supply chain security](<https://devfeed.tech/articles/chainguard-named-an-idc-innovator-for-open-source-software-supply-chain-security-12970.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-named-an-idc-innovator-for-open-source-software-supply-chain-security>)

Published: 2023-02-15T00:00:00Z

Content type: news

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [idc](<https://devfeed.tech/topics/idc.md>), [chainguard enforce](<https://devfeed.tech/topics/chainguard-enforce.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [DevSecOps](<https://devfeed.tech/topics/devsecops.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>), [DevOps](<https://devfeed.tech/topics/devops.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-enforce](<https://devfeed.tech/tags/chainguard-enforce.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [idc-innovators](<https://devfeed.tech/tags/idc-innovators.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>)

### AI overview

Chainguard was named an IDC Innovator in a 2023 report on open source software supply chain security. The article describes Chainguard's developer platform, including Chainguard Images and Chainguard Enforce, and its use of SLSA and Sigstore to integrate security checkpoints throughout the software development lifecycle.

### Source excerpt

The IDC Innovators report profiles Chainguard as one of three companies offering enhanced capabilities for open source software supply chain management.

## Not all that's signed is secure: Verify the right way with TUF and Sigstore

DevFeed: [Not all that's signed is secure: Verify the right way with TUF and Sigstore](<https://devfeed.tech/articles/not-all-that-s-signed-is-secure-verify-the-right-way-with-tuf-and-sigstore-13189.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/not-all-thats-signed-is-secure-verify-the-right-way-with-tuf-and-sigstore>)

Published: 2023-02-08T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [sigstore](<https://devfeed.tech/topics/sigstore.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard enforce](<https://devfeed.tech/topics/chainguard-enforce.md>)

Tags: [chainguard-enforce](<https://devfeed.tech/tags/chainguard-enforce.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [policy](<https://devfeed.tech/tags/policy.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [signing](<https://devfeed.tech/tags/signing.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [software-signatures](<https://devfeed.tech/tags/software-signatures.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [supply-chain-attacks](<https://devfeed.tech/tags/supply-chain-attacks.md>), [verification](<https://devfeed.tech/tags/verification.md>)

### AI overview

The article summarizes a talk on using Sigstore and The Update Framework (TUF) to create verification policies for securing software supply chains. It explains that signing alone does not provide sufficient protection, because verifying the wrong way can leave systems vulnerable to supply chain attacks. It presents TUF as a way to build flexible verification policies and describes how Sigstore supports easier signing with rigorous verification.

### Source excerpt

CloudNativeSecurityCon: Marina Moore & Zack Newman on using Sigstore & The Update Framework TUF to create verification policies to secure software supply chains

## Chainguard & BoxBoat, an IBM company, announce strategic partnership to tackle software supply chain security

DevFeed: [Chainguard & BoxBoat, an IBM company, announce strategic partnership to tackle software supply chain security](<https://devfeed.tech/articles/chainguard-boxboat-an-ibm-company-announce-strategic-partnership-to-tackle-software-supply-chain-security-12932.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-boxboat-an-ibm-company-announce-strategic-partnership-to-tackle-software-supply-chain-security>)

Published: 2023-02-01T00:00:00Z

Content type: news

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [ibm](<https://devfeed.tech/topics/ibm.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [DevSecOps](<https://devfeed.tech/topics/devsecops.md>)

Tags: [boxboat](<https://devfeed.tech/tags/boxboat.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-enforce](<https://devfeed.tech/tags/chainguard-enforce.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [developer-security-platform](<https://devfeed.tech/tags/developer-security-platform.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [ibm](<https://devfeed.tech/tags/ibm.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [partnership](<https://devfeed.tech/tags/partnership.md>), [security](<https://devfeed.tech/tags/security.md>), [security-platform](<https://devfeed.tech/tags/security-platform.md>), [security-sldc](<https://devfeed.tech/tags/security-sldc.md>), [security-solutions](<https://devfeed.tech/tags/security-solutions.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>)

### AI overview

Chainguard and BoxBoat, an IBM company, announce a strategic partnership to help enterprises secure the software development lifecycle. The partnership combines software supply chain security products, open source expertise, and consulting services for cloud-native, containerization, DevOps, and DevSecOps environments. It highlights Chainguard Enforce, Sigstore-based roots of trust, and Chainguard Images, with incremental integration into existing developer workflows.

### Source excerpt

Chainguard & BoxBoat, an IBM company, partner to offer enterprises end-to-end security solutions and address security across the software development lifecycle.

## Come see us at CloudNativeSecurityCon in Seattle Feb 1-2!

DevFeed: [Come see us at CloudNativeSecurityCon in Seattle Feb 1-2!](<https://devfeed.tech/articles/come-see-us-at-cloudnativesecuritycon-in-seattle-feb-1-2-13011.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/come-see-us-at-cloudnativesecuritycon-in-seattle-feb-1-2>)

Published: 2023-01-27T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard enforce](<https://devfeed.tech/topics/chainguard-enforce.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Security](<https://devfeed.tech/topics/security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-enforce](<https://devfeed.tech/tags/chainguard-enforce.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [cloud-native](<https://devfeed.tech/tags/cloud-native.md>), [cloud-native-security-con](<https://devfeed.tech/tags/cloud-native-security-con.md>), [conference](<https://devfeed.tech/tags/conference.md>), [linux-foundation](<https://devfeed.tech/tags/linux-foundation.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [seattle](<https://devfeed.tech/tags/seattle.md>), [security](<https://devfeed.tech/tags/security.md>), [security-conference](<https://devfeed.tech/tags/security-conference.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>)

### AI overview

Chainguard announces its participation in CloudNativeSecurityCon NA 2023 in Seattle, where attendees can visit Booth S12 for demonstrations of Chainguard Enforce and Chainguard Images, meet the team, and discuss software supply chain, cloud-native, and open source security. The article also previews Chainguard speakers, a security panel, and a talk on securing source repositories.

### Source excerpt

We're in Seattle next week for CloudNativeSecurityCon NA 2023. Find us at Booth S12 February 1-2 for swag and demos of Chainguard Enforce and Chainguard Images.