# chainguard labs

Published articles for chainguard labs.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Project Safe Source: Identifying potential vulnerabilities in Wolfi upstream

DevFeed: [Project Safe Source: Identifying potential vulnerabilities in Wolfi upstream](<https://devfeed.tech/articles/project-safe-source-identifying-potential-vulnerabilities-in-wolfi-upstream-13204.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/project-safe-source-identifying-potential-vulnerabilities-in-wolfi-upstream>)

Author: About the Author

Published: 2024-08-23T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard labs](<https://devfeed.tech/topics/chainguard-labs.md>), [Pull Request](<https://devfeed.tech/topics/pull-request.md>), [Code](<https://devfeed.tech/topics/code.md>), [Bot](<https://devfeed.tech/topics/bot.md>)

Tags: [automated](<https://devfeed.tech/tags/automated.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-labs](<https://devfeed.tech/tags/chainguard-labs.md>), [code](<https://devfeed.tech/tags/code.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [project](<https://devfeed.tech/tags/project.md>), [pull-requests](<https://devfeed.tech/tags/pull-requests.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Chainguard's Project Safe Source used CodeQL to scan more than 1,000 open source projects packaged in Wolfi. The scan identified seven classes of potential vulnerabilities across 226 projects, totaling 1,878 alerts, and highlighted candidates for automated pull requests.

### Source excerpt

Chainguard's Project Safe Source uses CodeQL to identify & fix vulnerabilities in open source projects packaged in Wolfi with automated pull requests.

## Pairing security advisories with vulnerable functions using LLMs

DevFeed: [Pairing security advisories with vulnerable functions using LLMs](<https://devfeed.tech/articles/pairing-security-advisories-with-vulnerable-functions-using-llms-13201.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/pairing-security-advisories-with-vulnerable-functions-using-llms>)

Published: 2024-08-07T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Large Language Model](<https://devfeed.tech/topics/llm.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [Security](<https://devfeed.tech/topics/security.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Go](<https://devfeed.tech/topics/go.md>), [Google](<https://devfeed.tech/topics/google.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-labs](<https://devfeed.tech/tags/chainguard-labs.md>), [cve](<https://devfeed.tech/tags/cve.md>), [go](<https://devfeed.tech/tags/go.md>), [google](<https://devfeed.tech/tags/google.md>), [llms](<https://devfeed.tech/tags/llms.md>), [nvd](<https://devfeed.tech/tags/nvd.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

Chainguard Labs describes using large language models to pair security advisories with vulnerable functions and improve vulnerability data. The reported approach increased precision by 173% while reducing recall by 18% compared with naive methods.

### Source excerpt

Learn how Chainguard Labs is enhancing vulnerability data with large language models (LLMs) to improve the accuracy and efficiency of CVE identification.

## Wolfi's upstream security inspection: Scanning with OpenSSF Scorecard

DevFeed: [Wolfi's upstream security inspection: Scanning with OpenSSF Scorecard](<https://devfeed.tech/articles/wolfi-s-upstream-security-inspection-scanning-with-openssf-scorecard-13340.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/wolfis-upstream-security-inspection-scanning-with-openssf-scorecard>)

Published: 2024-08-02T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [openssf](<https://devfeed.tech/topics/openssf.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [Maintainers](<https://devfeed.tech/topics/maintainers.md>)

Tags: [chainguard-labs](<https://devfeed.tech/tags/chainguard-labs.md>), [github](<https://devfeed.tech/tags/github.md>), [maintainers](<https://devfeed.tech/tags/maintainers.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [openssf](<https://devfeed.tech/tags/openssf.md>), [research](<https://devfeed.tech/tags/research.md>), [security](<https://devfeed.tech/tags/security.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Chainguard Labs evaluated the security of 1,511 upstream Wolfi repositories using the OpenSSF Scorecard. The mean score was 5.4 out of 10; repositories associated with Ruby and C packages had lower average scores of 4.8 and 4.7, respectively.

### Source excerpt

Chainguard Labs analyzed the security of 1,500+ upstream Wolfi repositories using the OpenSSF Scorecard tool -- uncover the key findings in the latest research.

## Why your company is wasting thousands of hours on software vulnerabilities

DevFeed: [Why your company is wasting thousands of hours on software vulnerabilities](<https://devfeed.tech/articles/why-your-company-is-wasting-thousands-of-hours-on-software-vulnerabilities-13333.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/why-your-company-is-wasting-thousands-of-hours-on-software-vulnerabilities>)

Published: 2024-02-06T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [chainguard labs](<https://devfeed.tech/topics/chainguard-labs.md>)

Tags: [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [chainguard-labs](<https://devfeed.tech/tags/chainguard-labs.md>), [common-vulnerabilities-and-exposures](<https://devfeed.tech/tags/common-vulnerabilities-and-exposures.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cve-management](<https://devfeed.tech/tags/cve-management.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

Chainguard Labs interviewed approximately ten software professionals and found that companies building or deploying containers may spend thousands of hours each year on vulnerability management. The article attributes much of this burden to large numbers of known vulnerabilities and image-selection practices that disregard vulnerability counts.

### Source excerpt

Chainguard Labs surveyed nine companies to see how many hours they spent on vulnerability management each year. Check out this blog to see the results.

## A thought experiment on using low-vulnerability Chainguard Images to speed government software delivery

DevFeed: [A thought experiment on using low-vulnerability Chainguard Images to speed government software delivery](<https://devfeed.tech/articles/ship-software-to-uncle-sam-faster-with-zero-known-vulnerability-containers-13230.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/ship-software-to-uncle-sam-faster-with-zero-known-vulnerability-containers>)

Published: 2023-06-20T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Containers](<https://devfeed.tech/topics/containers.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [authority to operate](<https://devfeed.tech/topics/authority-to-operate.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard labs](<https://devfeed.tech/topics/chainguard-labs.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [ato](<https://devfeed.tech/tags/ato.md>), [authority-to-operate](<https://devfeed.tech/tags/authority-to-operate.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [chainguard-labs](<https://devfeed.tech/tags/chainguard-labs.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [containers](<https://devfeed.tech/tags/containers.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [government](<https://devfeed.tech/tags/government.md>), [image-cves](<https://devfeed.tech/tags/image-cves.md>), [secure-container-image](<https://devfeed.tech/tags/secure-container-image.md>), [secure-minimal-image](<https://devfeed.tech/tags/secure-minimal-image.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>), [vulnerability-scanner](<https://devfeed.tech/tags/vulnerability-scanner.md>)

### AI overview

This opinion article proposes studying whether Chainguard Images with zero-known or low vulnerability counts could reduce timelines and staff costs in government Authority to Operate processes. It presents this as a hypothesis requiring comparison with other ATO processes, not as a demonstrated result.

### Source excerpt

Discover how 0-known vulnerability containers from Chainguard Labs could accelerate software delivery to the government.

## Introducing "Speranza": Enhancing software signing with privacy and usability

DevFeed: [Introducing "Speranza": Enhancing software signing with privacy and usability](<https://devfeed.tech/articles/introducing-speranza-enhancing-software-signing-with-privacy-and-usability-13121.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/introducing-speranza-enhancing-software-signing-with-privacy-and-usability>)

Published: 2023-05-30T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>), [OpenID connect (OIDC)](<https://devfeed.tech/topics/oidc.md>), [npm](<https://devfeed.tech/topics/npm.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-labs](<https://devfeed.tech/tags/chainguard-labs.md>), [cryptography](<https://devfeed.tech/tags/cryptography.md>), [digital-signatures](<https://devfeed.tech/tags/digital-signatures.md>), [oidc](<https://devfeed.tech/tags/oidc.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [pii](<https://devfeed.tech/tags/pii.md>), [privacy](<https://devfeed.tech/tags/privacy.md>), [security](<https://devfeed.tech/tags/security.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [software-artifact-signing](<https://devfeed.tech/tags/software-artifact-signing.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [software-supply-chain-security-research](<https://devfeed.tech/tags/software-supply-chain-security-research.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>)

### AI overview

Chainguard Labs introduces Speranza, a research project for usable, privacy-friendly software signing. The article explains how it aims to improve software supply chain security while addressing the usability problems of long-lived cryptographic keys and the privacy risks of exposing maintainers' identities or metadata. It also discusses potential applications in open source package repositories and enterprise deployments of Sigstore.

### Source excerpt

Chainguard Labs announces, "Speranza: Usable, privacy-friendly software signing," to help balance usability and privacy for software signing techniques.

## Chainguard conducts SLSA software supply chain security audit of open source project Git

DevFeed: [Chainguard conducts SLSA software supply chain security audit of open source project Git](<https://devfeed.tech/articles/chainguard-conducts-slsa-software-supply-chain-security-audit-of-open-source-project-git-12934.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-conducts-slsa-software-supply-chain-security-audit-of-open-source-project-git>)

Published: 2023-03-01T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Git](<https://devfeed.tech/topics/git.md>), [slsa levels](<https://devfeed.tech/topics/slsa-levels.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [GitLab](<https://devfeed.tech/topics/gitlab.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-labs](<https://devfeed.tech/tags/chainguard-labs.md>), [git](<https://devfeed.tech/tags/git.md>), [gitlab](<https://devfeed.tech/tags/gitlab.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [open-source-technology-improvement-fund](<https://devfeed.tech/tags/open-source-technology-improvement-fund.md>), [ostif](<https://devfeed.tech/tags/ostif.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [security](<https://devfeed.tech/tags/security.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>)

### AI overview

Chainguard, GitLab, and OSTIF audit Git and git-for-windows using the SLSA framework to examine software supply chain security practices. The article finds that SLSA is a poor fit for Git because Git releases source code rather than built artifacts, while git-for-windows can be assessed through the framework. It also reports that Git's contributor community and existing tooling provide protection consistent with SLSA's goals, despite practices that are not machine-readable or machine-verifiable.

### Source excerpt

Chainguard, GitLab and OSTIF conduct a software supply chain security audit of the open source git project using SLSA levels.