# chainguard libraries for javascript

Published articles for chainguard libraries for javascript.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Chainguard Repository adds new policies, Chainguard Libraries for JavaScript is GA

DevFeed: [Chainguard Repository adds new policies, Chainguard Libraries for JavaScript is GA](<https://devfeed.tech/articles/chainguard-repository-adds-new-policies-chainguard-libraries-for-javascript-is-ga-12979.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-repository-adds-new-policies-chainguard-libraries-for-javascript-is-ga>)

Published: 2026-06-25T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard repository](<https://devfeed.tech/topics/chainguard-repository.md>), [chainguard libraries for javascript](<https://devfeed.tech/topics/chainguard-libraries-for-javascript.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [chainguard-libraries-for-java](<https://devfeed.tech/tags/chainguard-libraries-for-java.md>), [chainguard-libraries-for-javascript](<https://devfeed.tech/tags/chainguard-libraries-for-javascript.md>), [chainguard-libraries-for-python](<https://devfeed.tech/tags/chainguard-libraries-for-python.md>), [chainguard-repo](<https://devfeed.tech/tags/chainguard-repo.md>), [chainguard-repository](<https://devfeed.tech/tags/chainguard-repository.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [libraries](<https://devfeed.tech/tags/libraries.md>), [malware](<https://devfeed.tech/tags/malware.md>), [malware-scanner](<https://devfeed.tech/tags/malware-scanner.md>), [policy](<https://devfeed.tech/tags/policy.md>), [visibility](<https://devfeed.tech/tags/visibility.md>)

### AI overview

Chainguard announces new malware and greyware scanning for additional artifact types, expanded policy controls, and new visibility features in Chainguard Repository. The article also announces general availability of Chainguard Libraries for JavaScript.

### Source excerpt

Chainguard Repository adds malware and greyware scanning, expanded policy controls, and visibility to secure AI-driven software supply chains.

## npm Token Changes Improve Supply-Chain Security but MFA Phishing and Bypass Tokens Remain Risks

DevFeed: [npm Token Changes Improve Supply-Chain Security but MFA Phishing and Bypass Tokens Remain Risks](<https://devfeed.tech/articles/npm-s-update-to-harden-their-supply-chain-and-points-to-consider-13191.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/npm-update-to-harden-their-supply-chain-and-points-to-consider>)

Published: 2026-02-03T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [npm](<https://devfeed.tech/topics/npm.md>), [Security](<https://devfeed.tech/topics/security.md>), [MFA](<https://devfeed.tech/topics/mfa.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [OpenID connect (OIDC)](<https://devfeed.tech/topics/oidc.md>), [chainguard libraries](<https://devfeed.tech/topics/chainguard-libraries.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [chainguard-libraries-for-javascript](<https://devfeed.tech/tags/chainguard-libraries-for-javascript.md>), [javascript-packages](<https://devfeed.tech/tags/javascript-packages.md>), [malware](<https://devfeed.tech/tags/malware.md>), [mfa](<https://devfeed.tech/tags/mfa.md>), [npm](<https://devfeed.tech/tags/npm.md>), [oidc](<https://devfeed.tech/tags/oidc.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [secure-packages](<https://devfeed.tech/tags/secure-packages.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-attacks](<https://devfeed.tech/tags/supply-chain-attacks.md>)

### AI overview

The article examines npm's authentication overhaul after the Sha1-Hulud incident. It explains that short-lived session tokens, default MFA for publishing, and OIDC Trusted Publishing improve security, but MFA phishing and optional 90-day tokens with MFA bypass still leave projects vulnerable to supply-chain attacks.

### Source excerpt

npm's token changes help, but MFA phishing and optional bypass tokens still enable supply-chain attacks. Source-built Chainguard Libraries reduce the risk.

## Mitigating malware in the npm ecosystem with Chainguard Libraries

DevFeed: [Mitigating malware in the npm ecosystem with Chainguard Libraries](<https://devfeed.tech/articles/mitigating-malware-in-the-npm-ecosystem-with-chainguard-libraries-13162.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/mitigating-malware-in-the-npm-ecosystem-with-chainguard-libraries>)

Published: 2025-10-02T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard libraries](<https://devfeed.tech/topics/chainguard-libraries.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [npm packages](<https://devfeed.tech/topics/npm-packages.md>), [npm](<https://devfeed.tech/topics/npm.md>), [Security](<https://devfeed.tech/topics/security.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-ecosystem](<https://devfeed.tech/tags/chainguard-ecosystem.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [chainguard-libraries-for-javascript](<https://devfeed.tech/tags/chainguard-libraries-for-javascript.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [malicious-packages](<https://devfeed.tech/tags/malicious-packages.md>), [malware](<https://devfeed.tech/tags/malware.md>), [npm](<https://devfeed.tech/tags/npm.md>), [npm-malware](<https://devfeed.tech/tags/npm-malware.md>), [npm-package-attack](<https://devfeed.tech/tags/npm-package-attack.md>), [npm-packages](<https://devfeed.tech/tags/npm-packages.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>)

### AI overview

The article presents research on using Chainguard Libraries for JavaScript to mitigate malware in the npm ecosystem. By requiring attributable source code and validating source-to-artifact integrity through a build-from-source pipeline, the study found that approximately 99% of 8,783 known malicious npm packages would have been prevented from publication, while approximately 99.7% were blocked for users relying on Chainguard Libraries as their sole source of npm dependencies.

### Source excerpt

In a recent analysis, Chainguard Libraries for JavaScript prevented over 99% of malicious npm packages published to the npm registry.

## Announcing Chainguard Libraries for JavaScript: Malware-Resistant Dependencies Built Securely from Source

DevFeed: [Announcing Chainguard Libraries for JavaScript: Malware-Resistant Dependencies Built Securely from Source](<https://devfeed.tech/articles/announcing-chainguard-libraries-for-javascript-malware-resistant-dependencies-built-securely-from-source-12879.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/announcing-chainguard-libraries-for-javascript-malware-resistant-dependencies-built-securely-from-source>)

Published: 2025-09-25T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard libraries](<https://devfeed.tech/topics/chainguard-libraries.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [npm packages](<https://devfeed.tech/topics/npm-packages.md>), [npm](<https://devfeed.tech/topics/npm.md>)

Tags: [attacks](<https://devfeed.tech/tags/attacks.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [chainguard-libraries-for-javascript](<https://devfeed.tech/tags/chainguard-libraries-for-javascript.md>), [javacript](<https://devfeed.tech/tags/javacript.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [language-library-security](<https://devfeed.tech/tags/language-library-security.md>), [malware](<https://devfeed.tech/tags/malware.md>), [npm](<https://devfeed.tech/tags/npm.md>), [npm-packages](<https://devfeed.tech/tags/npm-packages.md>), [package-compromise](<https://devfeed.tech/tags/package-compromise.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [shai-hulud](<https://devfeed.tech/tags/shai-hulud.md>), [slsa](<https://devfeed.tech/tags/slsa.md>)

### AI overview

Chainguard announces Chainguard Libraries for JavaScript, a source of trusted language-dependency builds intended to protect developers and organizations from compromised packages, malicious updates, and registry-based attacks. The libraries are built from source on hardened SLSA L2 infrastructure, include provenance, and are designed to fit existing developer workflows.

### Source excerpt

Chainguard Libraries for JavaScript is designed to protect developers and organizations from compromised packages, malicious updates, and registry-based attacks.