# chainguard security

Published articles for chainguard security.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Chainguard Launches Bugcrowd Bug Bounty With Up to $200,000 in Rewards

DevFeed: [Chainguard Launches Bugcrowd Bug Bounty With Up to $200,000 in Rewards](<https://devfeed.tech/articles/we-re-putting-our-security-to-the-test-and-we-want-your-help-13313.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/we-are-putting-our-security-to-the-test-and-we-want-your-help>)

Published: 2026-07-06T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Bug Bounty](<https://devfeed.tech/topics/bugbounty.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [npm packages](<https://devfeed.tech/topics/npm-packages.md>)

Tags: [bounty](<https://devfeed.tech/tags/bounty.md>), [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [bugcrowd-bug-bounty](<https://devfeed.tech/tags/bugcrowd-bug-bounty.md>), [chainguard-bug-bounty](<https://devfeed.tech/tags/chainguard-bug-bounty.md>), [chainguard-security](<https://devfeed.tech/tags/chainguard-security.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [malicious-packages](<https://devfeed.tech/tags/malicious-packages.md>), [npm-packages](<https://devfeed.tech/tags/npm-packages.md>), [security](<https://devfeed.tech/tags/security.md>), [security-contest](<https://devfeed.tech/tags/security-contest.md>), [shai-hulud](<https://devfeed.tech/tags/shai-hulud.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Chainguard is running a Bugcrowd bug bounty from July 6-27, offering up to $200,000 to researchers who find vulnerabilities in its infrastructure and products.

### Source excerpt

Chainguard launches a Bugcrowd bounty with up to $200K in rewards, inviting researchers to test its infrastructure against real-world attacks.

## Three Ways to Make Your SDLC Secure-by-Default

DevFeed: [Three Ways to Make Your SDLC Secure-by-Default](<https://devfeed.tech/articles/three-ways-to-make-your-sdlc-secure-by-default-13293.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/three-ways-to-make-your-sdlc-secure-by-default>)

Published: 2025-10-20T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [sdlc](<https://devfeed.tech/topics/sdlc.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [chainguard-security](<https://devfeed.tech/tags/chainguard-security.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [cloud-native](<https://devfeed.tech/tags/cloud-native.md>), [cves](<https://devfeed.tech/tags/cves.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [sdlc](<https://devfeed.tech/tags/sdlc.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>)

### AI overview

This article presents secure-by-default software development lifecycle practices. It recommends embedding security throughout development, standardizing trusted foundations, securing dependencies and base images, and integrating security into developer tools, CI/CD workflows, and runtime artifacts.

### Source excerpt

Build secure software faster with Chainguard. Learn how secure-by-default SDLC practices eliminate CVEs, automate compliance, and embed trust from code to cloud.

## Simplify Continuous Compliance: How to Stay Audit-Ready and Ship Software Faster

DevFeed: [Simplify Continuous Compliance: How to Stay Audit-Ready and Ship Software Faster](<https://devfeed.tech/articles/simplify-continuous-compliance-how-to-stay-audit-ready-and-ship-software-faster-13233.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/simplify-continuous-compliance-how-to-stay-audit-ready-and-ship-software-faster>)

Published: 2025-10-14T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Software](<https://devfeed.tech/topics/software.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-security](<https://devfeed.tech/tags/chainguard-security.md>), [cmmc](<https://devfeed.tech/tags/cmmc.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [cves](<https://devfeed.tech/tags/cves.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [iso-27001](<https://devfeed.tech/tags/iso-27001.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [pci-dss](<https://devfeed.tech/tags/pci-dss.md>), [security](<https://devfeed.tech/tags/security.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>), [stateramp](<https://devfeed.tech/tags/stateramp.md>)

### AI overview

This article explains how organizations can treat software compliance as a continuous practice rather than a periodic audit exercise. It describes how open-source components, CVE remediation, provenance, SBOM coverage, and audit evidence affect platform engineering, application security, development velocity, and regulated-market access, while presenting Chainguard as a solution provider.

### Source excerpt

Turn compliance into a growth driver with Chainguard. Eliminate CVEs, stay audit-ready, and meet FedRAMP, SOC 2, and ISO 27001 with secure images.

## Applying Zero Trust Principles to Open Source Software Supply Chain Security

DevFeed: [Applying Zero Trust Principles to Open Source Software Supply Chain Security](<https://devfeed.tech/articles/this-shit-is-hard-applying-zero-trust-to-open-source-software-13299.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/unchained-this-shit-is-hard-applying-zero-trust-to-open-source-software>)

Published: 2025-09-29T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Zero Trust](<https://devfeed.tech/topics/zero-trust.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Git](<https://devfeed.tech/topics/git.md>)

Tags: [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [chainguard-security](<https://devfeed.tech/tags/chainguard-security.md>), [git](<https://devfeed.tech/tags/git.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [security](<https://devfeed.tech/tags/security.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [this-shit-is-hard](<https://devfeed.tech/tags/this-shit-is-hard.md>), [zero-trust](<https://devfeed.tech/tags/zero-trust.md>)

### AI overview

This article explains how Chainguard applies Zero Trust principles to open source software supply chain security. It discusses weaknesses in Git identity and long-lived credentials, including risks from impersonation, credential theft, and compromised package publishing.

### Source excerpt

Chainguard implements Zero Trust principles into everything we do to protect critical infrastructure in the age of open source. See how we do it.

## This Shit is Hard: Hardening glibc

DevFeed: [This Shit is Hard: Hardening glibc](<https://devfeed.tech/articles/this-shit-is-hard-hardening-glibc-13281.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/this-shit-is-hard-hardening-glibc>)

Published: 2025-08-20T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Compiler](<https://devfeed.tech/topics/compiler.md>), [gcc](<https://devfeed.tech/topics/gcc.md>), [toolchain](<https://devfeed.tech/topics/toolchain.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard packages](<https://devfeed.tech/topics/chainguard-packages.md>), [C](<https://devfeed.tech/topics/c.md>), [Linux](<https://devfeed.tech/topics/linux.md>)

Tags: [c](<https://devfeed.tech/tags/c.md>), [c-c-plus-plus](<https://devfeed.tech/tags/c-c-plus-plus.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-security](<https://devfeed.tech/tags/chainguard-security.md>), [compiler](<https://devfeed.tech/tags/compiler.md>), [compiler-flags](<https://devfeed.tech/tags/compiler-flags.md>), [gcc](<https://devfeed.tech/tags/gcc.md>), [glibc](<https://devfeed.tech/tags/glibc.md>), [hardening](<https://devfeed.tech/tags/hardening.md>), [openssf](<https://devfeed.tech/tags/openssf.md>), [security](<https://devfeed.tech/tags/security.md>), [toolchain](<https://devfeed.tech/tags/toolchain.md>)

### AI overview

Chainguard describes its effort to build glibc with hardened compiler flags. The work involved collaboration with the upstream GCC and glibc projects to resolve complex issues and ship a hardened version of the library.

### Source excerpt

Chainguard uses compiler flags to be proactive in the security of our products. See how our compiler flag usage helped us catch a complex bug in glibc.