# fedramp

Published articles for fedramp.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## FIPS 140-2 vs FIPS 140-3, Explained

DevFeed: [FIPS 140-2 vs FIPS 140-3, Explained](<https://devfeed.tech/articles/fips-140-2-vs-fips-140-3-explained-29647.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/fips-140-2-vs-fips-140-3-explained/>)

Author: info@goteleport.com (Mayur Pipaliya)

Published: 2026-09-09T00:00:00Z

Content type: article

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [fips 140-3](<https://devfeed.tech/topics/fips-140-3.md>), [FIPS validation](<https://devfeed.tech/topics/fips-validation.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [certificates](<https://devfeed.tech/topics/certificates.md>), [Security](<https://devfeed.tech/topics/security.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>)

Tags: [certificates](<https://devfeed.tech/tags/certificates.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cmvp](<https://devfeed.tech/tags/cmvp.md>), [cryptography](<https://devfeed.tech/tags/cryptography.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [fips](<https://devfeed.tech/tags/fips.md>), [fips-140-3](<https://devfeed.tech/tags/fips-140-3.md>), [fips-validation](<https://devfeed.tech/tags/fips-validation.md>), [security](<https://devfeed.tech/tags/security.md>), [sensitive-data](<https://devfeed.tech/tags/sensitive-data.md>)

### AI overview

This article explains the differences between FIPS 140-2 and FIPS 140-3, including the standards' origins, CMVP validation certificates, applicable requirements for protecting sensitive data, and the transition timeline through September 2026.

### Source excerpt

Understand key changes from FIPS 140-2 to FIPS 140-3.

## Announcing Chainguard container images for Go 1.27

DevFeed: [Announcing Chainguard container images for Go 1.27](<https://devfeed.tech/articles/announcing-chainguard-container-images-for-go-1-27-12876.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/announcing-chainguard-container-images-for-go-1-27>)

Published: 2026-08-31T00:00:00Z

Content type: news

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [container images](<https://devfeed.tech/topics/container-images.md>), [Go Language](<https://devfeed.tech/topics/go-language.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [Deployment](<https://devfeed.tech/topics/deployment.md>), [Security, Privacy and Abuse Prevention](<https://devfeed.tech/topics/security-privacy-and-abuse-prevention.md>), [Post-Quantum](<https://devfeed.tech/topics/post-quantum.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [container](<https://devfeed.tech/tags/container.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cryptography](<https://devfeed.tech/tags/cryptography.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [fedramp-ato](<https://devfeed.tech/tags/fedramp-ato.md>), [fips](<https://devfeed.tech/tags/fips.md>), [go](<https://devfeed.tech/tags/go.md>), [hardening](<https://devfeed.tech/tags/hardening.md>), [images](<https://devfeed.tech/tags/images.md>), [post-quantum](<https://devfeed.tech/tags/post-quantum.md>), [release](<https://devfeed.tech/tags/release.md>)

### AI overview

Chainguard announces three Go 1.27 container images: go, go-fips, and go-openssl-fips. The options differ in their FIPS-validated cryptography, including whether cryptography is built in or selected at deployment time.

### Source excerpt

Chainguard simplifies Go 1.27 with three images and a new option to choose FIPS-validated cryptography at deployment without recompiling.

## Engineering the Datadog Agent for FedRAMP High® Certification

DevFeed: [Engineering the Datadog Agent for FedRAMP High® Certification](<https://devfeed.tech/articles/engineering-the-datadog-agent-for-fedramp-high-certification-2267.md>)

Original publisher: [Read original article](<https://www.datadoghq.com/blog/engineering-the-datadog-agent-for-fedramp-high/>)

Author: Srdjan Grubor; Nathan Baker

Published: 2026-07-28T00:00:00Z

Content type: article

Language: en

Sources: [Datadog | The Monitor blog](<https://devfeed.tech/sources/datadog-the-monitor-blog.md>)

Topics: [Cryptography](<https://devfeed.tech/topics/cryptography.md>)

Tags: [architecture](<https://devfeed.tech/tags/architecture.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [cryptographic](<https://devfeed.tech/tags/cryptographic.md>), [cryptography](<https://devfeed.tech/tags/cryptography.md>), [datadog-agent](<https://devfeed.tech/tags/datadog-agent.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [go](<https://devfeed.tech/tags/go.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [logs](<https://devfeed.tech/tags/logs.md>), [metrics](<https://devfeed.tech/tags/metrics.md>), [network-configuration](<https://devfeed.tech/tags/network-configuration.md>), [observability](<https://devfeed.tech/tags/observability.md>), [python](<https://devfeed.tech/tags/python.md>), [security](<https://devfeed.tech/tags/security.md>), [traces](<https://devfeed.tech/tags/traces.md>)

### AI overview

The article explains how Datadog engineered its Agent to meet FedRAMP High requirements in customer-managed environments, emphasizing cryptographic enforcement across Go and Python runtimes.

### Source excerpt

Datadog achieves GovRAMP High authorization, bringing unified observability and security to state and local government agencies for critical systems.

## Announcing the CIS Benchmark for CockroachDB v25.x

DevFeed: [Announcing the CIS Benchmark for CockroachDB v25.x](<https://devfeed.tech/articles/announcing-the-cis-benchmark-for-cockroachdb-v25-x-23757.md>)

Original publisher: [Read original article](<https://cockroachlabs.com/blog/cis-benchmark-cockroachdb-security>)

Author: Adam Brennick,Ayog Mohanty

Published: 2026-07-14T00:00:00Z

Content type: release

Language: en

Sources: [Cockroach Labs](<https://devfeed.tech/sources/cockroach-labs.md>)

Topics: [Benchmark](<https://devfeed.tech/topics/benchmark.md>), [CockroachDB](<https://devfeed.tech/topics/cockroachdb.md>), [Security](<https://devfeed.tech/topics/security.md>), [Cockroach Labs](<https://devfeed.tech/topics/cockroach-labs.md>), [configuration](<https://devfeed.tech/topics/configuration.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Database](<https://devfeed.tech/topics/database.md>), [Self-hosted](<https://devfeed.tech/topics/self-hosted.md>)

Tags: [announce](<https://devfeed.tech/tags/announce.md>), [benchmark](<https://devfeed.tech/tags/benchmark.md>), [cockroach-labs](<https://devfeed.tech/tags/cockroach-labs.md>), [cockroachdb](<https://devfeed.tech/tags/cockroachdb.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [configuration](<https://devfeed.tech/tags/configuration.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [government](<https://devfeed.tech/tags/government.md>), [hipaa](<https://devfeed.tech/tags/hipaa.md>), [pci-dss](<https://devfeed.tech/tags/pci-dss.md>), [published](<https://devfeed.tech/tags/published.md>), [security](<https://devfeed.tech/tags/security.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>), [security-research](<https://devfeed.tech/tags/security-research.md>), [self-hosted](<https://devfeed.tech/tags/self-hosted.md>), [standard](<https://devfeed.tech/tags/standard.md>)

### AI overview

The Center for Internet Security has published the CIS CockroachDB v25.x Benchmark, providing a consensus-driven security configuration guide for self-hosted CockroachDB deployments. The article explains how the benchmark can support standardized security practices, audits, compliance reviews, and production configuration validation.

### Source excerpt

We're proud to announce that the Center for Internet Security (CIS) has published the CIS CockroachDB v25.x Benchmark.

## Preparing for OMB M-26-14: How Datadog supports federal logging maturity

DevFeed: [Preparing for OMB M-26-14: How Datadog supports federal logging maturity](<https://devfeed.tech/articles/preparing-for-omb-m-26-14-how-datadog-supports-federal-logging-maturity-2302.md>)

Original publisher: [Read original article](<https://www.datadoghq.com/blog/omb-m-26-14-federal-logging-maturity/>)

Author: Chris Leffler; Sophie Wang

Published: 2026-06-29T00:00:00Z

Content type: article

Language: en

Sources: [Datadog | The Monitor blog](<https://devfeed.tech/sources/datadog-the-monitor-blog.md>)

Topics: [SIEM, Security, Observability](<https://devfeed.tech/topics/siem-security-observability.md>), [log management](<https://devfeed.tech/topics/log-management.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [threat detection](<https://devfeed.tech/topics/threat-detection.md>), [incident](<https://devfeed.tech/topics/incident.md>), [Incident response](<https://devfeed.tech/topics/incident-response.md>), [observability](<https://devfeed.tech/topics/observability.md>), [Security](<https://devfeed.tech/topics/security.md>), [Security Operations Center](<https://devfeed.tech/topics/security-operations-center.md>), [Resilience](<https://devfeed.tech/topics/resilience.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>)

Tags: [bits-ai](<https://devfeed.tech/tags/bits-ai.md>), [cloud-siem](<https://devfeed.tech/tags/cloud-siem.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [govcloud](<https://devfeed.tech/tags/govcloud.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [log-management](<https://devfeed.tech/tags/log-management.md>), [logging](<https://devfeed.tech/tags/logging.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [observability](<https://devfeed.tech/tags/observability.md>), [resilience](<https://devfeed.tech/tags/resilience.md>), [security](<https://devfeed.tech/tags/security.md>), [security-operations-center](<https://devfeed.tech/tags/security-operations-center.md>), [soc](<https://devfeed.tech/tags/soc.md>), [systems](<https://devfeed.tech/tags/systems.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>), [threat-detection](<https://devfeed.tech/tags/threat-detection.md>), [workflow-automation](<https://devfeed.tech/tags/workflow-automation.md>)

### AI overview

This article explains how OMB Memorandum M-26-14 changes federal logging guidance from prescriptive requirements to a risk- and maturity-based model. It describes continuous event monitoring and threat hunting, investigation, response, and forensics, including centralized security telemetry, visibility across IT, OT, and IoT environments, threat detection, searchable and retrievable logs, cross-source correlation, incident response, and forensic analysis. It also presents Datadog as a unified observability and security platform for helping agencies meet these requirements.

### Source excerpt

Learn how Datadog helps federal agencies prepare for OMB M-26-14 by providing centralized telemetry data, threat detection, and automated incident response.

## Datadog achieves GovRAMP High authorization

DevFeed: [Datadog achieves GovRAMP High authorization](<https://devfeed.tech/articles/datadog-achieves-govramp-high-authorization-2254.md>)

Original publisher: [Read original article](<https://www.datadoghq.com/blog/datadog-achieves-govramp-high-authorization/>)

Author: Rukshan Gunawardana; Sophie Wang; Jason Hansen

Published: 2026-06-29T00:00:00Z

Content type: release

Language: en

Sources: [Datadog | The Monitor blog](<https://devfeed.tech/sources/datadog-the-monitor-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [observability](<https://devfeed.tech/topics/observability.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [systems](<https://devfeed.tech/topics/systems.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Resilience](<https://devfeed.tech/topics/resilience.md>), [telemetry](<https://devfeed.tech/topics/telemetry.md>), [ai observability](<https://devfeed.tech/topics/ai-observability.md>)

Tags: [agent-observability](<https://devfeed.tech/tags/agent-observability.md>), [ai-observability](<https://devfeed.tech/tags/ai-observability.md>), [aws](<https://devfeed.tech/tags/aws.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [dashboards](<https://devfeed.tech/tags/dashboards.md>), [database-monitoring](<https://devfeed.tech/tags/database-monitoring.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [government](<https://devfeed.tech/tags/government.md>), [infrastructure-monitoring](<https://devfeed.tech/tags/infrastructure-monitoring.md>), [log-management](<https://devfeed.tech/tags/log-management.md>), [logs](<https://devfeed.tech/tags/logs.md>), [metrics](<https://devfeed.tech/tags/metrics.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [networks](<https://devfeed.tech/tags/networks.md>), [observability](<https://devfeed.tech/tags/observability.md>), [resilience](<https://devfeed.tech/tags/resilience.md>), [security](<https://devfeed.tech/tags/security.md>), [systems](<https://devfeed.tech/tags/systems.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>)

### AI overview

Datadog announced GovRAMP High authorization for its government offering, extending its FedRAMP High certification and supporting state, local, tribal, territorial, and education organizations. The article explains how unified observability and security can consolidate monitoring data across applications, logs, networks, databases, infrastructure, and AI initiatives.

### Source excerpt

Datadog achieves GovRAMP High authorization, bringing unified observability and security to state and local government agencies for critical systems.

## Chainguard is named a Leader in the 2026 Gartner® Magic Quadrant™ for Software Supply Chain Security

DevFeed: [Chainguard is named a Leader in the 2026 Gartner® Magic Quadrant™ for Software Supply Chain Security](<https://devfeed.tech/articles/chainguard-is-named-a-leader-in-the-2026-gartner-magic-quadranttm-for-software-supply-chain-security-12961.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-is-named-a-leader-in-the-2026-gartner-magic-quadrant-for-software-supply-chain-security>)

Published: 2026-06-18T00:00:00Z

Content type: news

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-gartner](<https://devfeed.tech/tags/chainguard-gartner.md>), [chainguard-gartner-magic-quadrant](<https://devfeed.tech/tags/chainguard-gartner-magic-quadrant.md>), [cyber-resilience-act](<https://devfeed.tech/tags/cyber-resilience-act.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [gartner](<https://devfeed.tech/tags/gartner.md>), [gartner-mq-software-supply-chain](<https://devfeed.tech/tags/gartner-mq-software-supply-chain.md>), [nis2](<https://devfeed.tech/tags/nis2.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [security](<https://devfeed.tech/tags/security.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [software-supply-chain-security-gartner](<https://devfeed.tech/tags/software-supply-chain-security-gartner.md>)

### AI overview

Chainguard announces that it has been recognized as a Leader in the 2026 Gartner Magic Quadrant for Software Supply Chain Security. The article highlights Chainguard's secure-by-default approach, hardened open source artifacts, cryptographic signatures, signed SBOMs, and SLSA-aligned provenance, along with support for regulatory requirements.

### Source excerpt

Chainguard named a Leader in the 2026 Gartner® Magic Quadrant™ for Software Supply Chain Security, recognized for vision and secure-by-default innovation.

## Introducing the Chainguard cinc-auditor image: STIG scanning for Chainguard Containers, ready to run

DevFeed: [Introducing the Chainguard cinc-auditor image: STIG scanning for Chainguard Containers, ready to run](<https://devfeed.tech/articles/introducing-the-chainguard-cinc-auditor-image-stig-scanning-for-chainguard-containers-ready-to-run-13123.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/introducing-the-chainguard-cinc-auditor-image-stig-scanning-for-chainguard-containers-ready-to-run>)

Published: 2026-06-18T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [anchore](<https://devfeed.tech/topics/anchore.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [anchore](<https://devfeed.tech/tags/anchore.md>), [anchore-enterprise](<https://devfeed.tech/tags/anchore-enterprise.md>), [apache](<https://devfeed.tech/tags/apache.md>), [built-from-source](<https://devfeed.tech/tags/built-from-source.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [cinc-auditor](<https://devfeed.tech/tags/cinc-auditor.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [pipeline](<https://devfeed.tech/tags/pipeline.md>), [scanner](<https://devfeed.tech/tags/scanner.md>), [stig](<https://devfeed.tech/tags/stig.md>), [stigs](<https://devfeed.tech/tags/stigs.md>)

### AI overview

Chainguard introduces a ready-to-run cinc-auditor container image for STIG scanning of Chainguard Containers. The image includes a maintained GPOS SRG InSpec profile, removes separate profile and dependency setup, and supports production compliance pipelines, including FedRAMP workflows.

### Source excerpt

Chainguard launches a ready-to-run STIG scanner with a built-in GPOS SRG InSpec profile, simplifying compliance scans for containers and FedRAMP workflows.

## Automating Identity and Access for FedRAMP 20x KSIs with Teleport

DevFeed: [Automating Identity and Access for FedRAMP 20x KSIs with Teleport](<https://devfeed.tech/articles/automating-identity-and-access-for-fedramp-20x-ksis-with-teleport-29580.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/automating-identity-access-fedramp-20x/>)

Author: info@goteleport.com (Nicolas Morris)

Published: 2026-06-17T00:00:00Z

Content type: tutorial

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [audit trail](<https://devfeed.tech/topics/audit-trail.md>), [identity and access management](<https://devfeed.tech/topics/identity-and-access-management.md>), [Logging](<https://devfeed.tech/topics/logging.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [Security](<https://devfeed.tech/topics/security.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>)

Tags: [audit-trail](<https://devfeed.tech/tags/audit-trail.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [credentials](<https://devfeed.tech/tags/credentials.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [fedramp-20x](<https://devfeed.tech/tags/fedramp-20x.md>), [hardcoded-credentials](<https://devfeed.tech/tags/hardcoded-credentials.md>), [identity-and-access-management](<https://devfeed.tech/tags/identity-and-access-management.md>), [logging](<https://devfeed.tech/tags/logging.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

This article explains how FedRAMP 20x changes identity and access compliance toward persistent validation using machine-readable evidence. It describes how unified identity management and audit trails can help address gaps in machine-to-machine authentication and continuous KSI validation.

### Source excerpt

Learn how to automate identity and access for FedRAMP 20x KSIs with a unified audit trail for identities, access, and persistent evidence.

## Canada's CPCSC and Bill C-8 are coming. Here's what you need to do.

DevFeed: [Canada's CPCSC and Bill C-8 are coming. Here's what you need to do.](<https://devfeed.tech/articles/canada-s-cpcsc-and-bill-c-8-are-coming-here-s-what-you-need-to-do-12917.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/canadas-cpcsc-and-bill-c-8-are-coming-heres-what-you-need-to-do>)

Published: 2026-05-14T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Critical Infrastructure](<https://devfeed.tech/topics/critical-infrastructure.md>), [Security](<https://devfeed.tech/topics/security.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Cloud Native Ecosystem](<https://devfeed.tech/topics/cloud-native-ecosystem.md>)

Tags: [bill-c-8](<https://devfeed.tech/tags/bill-c-8.md>), [canada-cmmc](<https://devfeed.tech/tags/canada-cmmc.md>), [canadian-program-for-cyber-security-certification](<https://devfeed.tech/tags/canadian-program-for-cyber-security-certification.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [cmmc](<https://devfeed.tech/tags/cmmc.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cpcsc](<https://devfeed.tech/tags/cpcsc.md>), [critical-infrastructure](<https://devfeed.tech/tags/critical-infrastructure.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [federal-compliance](<https://devfeed.tech/tags/federal-compliance.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [nist](<https://devfeed.tech/tags/nist.md>), [zero-cve-containers](<https://devfeed.tech/tags/zero-cve-containers.md>)

### AI overview

This article explains Canada's Canadian Program for Cyber Security Certification (CPCSC) and Bill C-8, focusing on the implications for defence suppliers and organizations in critical infrastructure. It describes the CPCSC as a mandatory cybersecurity certification regime, compares its technical basis with CMMC and NIST Special Publications 800-171 and 800-172, and outlines why organizations should prepare for Level 1 requirements. The article also describes how Chainguard can help Canadian defence suppliers meet those requirements with secure, zero-CVE containers.

### Source excerpt

CPCSC compliance is coming fast. Learn how Chainguard helps Canadian defence suppliers meet Level 1 requirements with secure, zero-CVE containers.

## OpenAI available at FedRAMP Moderate

DevFeed: [OpenAI available at FedRAMP Moderate](<https://devfeed.tech/articles/openai-available-at-fedramp-moderate-6568.md>)

Original publisher: [Read original article](<https://openai.com/index/openai-available-at-fedramp-moderate>)

Published: 2026-04-27T14:00:00Z

Content type: news

Language: en

Sources: [OpenAI News](<https://devfeed.tech/sources/openai-news.md>)

Topics: [AI Chat](<https://devfeed.tech/topics/ai-chat.md>), [SDKs](<https://devfeed.tech/topics/sdks.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [api](<https://devfeed.tech/tags/api.md>), [chatgpt](<https://devfeed.tech/tags/chatgpt.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [global-affairs](<https://devfeed.tech/tags/global-affairs.md>), [government](<https://devfeed.tech/tags/government.md>), [openai](<https://devfeed.tech/tags/openai.md>), [security-privacy](<https://devfeed.tech/tags/security-privacy.md>)

### AI overview

OpenAI announced FedRAMP 20x Moderate authorization for ChatGPT Enterprise and its API Platform, expanding a path for U.S. federal agencies to use its managed AI products.

### Source excerpt

OpenAI is available at FedRAMP Moderate authorization for ChatGPT Enterprise and the OpenAI API, enabling secure AI adoption for U.S. federal agencies.

## How NASA and Chainguard used AI to support secure, compliant Artemis mission readiness

DevFeed: [How NASA and Chainguard used AI to support secure, compliant Artemis mission readiness](<https://devfeed.tech/articles/securing-the-next-moon-age-automated-compliance-powers-the-next-giant-leap-13226.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/securing-the-next-moon-age-automated-compliance-powers-the-next-giant-leap>)

Author: Dimension

Published: 2026-04-17T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [data](<https://devfeed.tech/topics/data.md>), [Retrieval-Augmented Generation](<https://devfeed.tech/topics/retrieval-augmented-generation.md>), [Model Context Protocol (MCP)](<https://devfeed.tech/topics/model-context-protocol-mcp.md>), [datasets](<https://devfeed.tech/topics/datasets.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>), [User Experience](<https://devfeed.tech/topics/user-experience.md>), [Scalability](<https://devfeed.tech/topics/scalability.md>), [Grafana](<https://devfeed.tech/topics/grafana.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-in-space](<https://devfeed.tech/tags/ai-in-space.md>), [artemis-2](<https://devfeed.tech/tags/artemis-2.md>), [artemis-ii](<https://devfeed.tech/tags/artemis-ii.md>), [automated](<https://devfeed.tech/tags/automated.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [data](<https://devfeed.tech/tags/data.md>), [embeddings](<https://devfeed.tech/tags/embeddings.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [mcp](<https://devfeed.tech/tags/mcp.md>), [pipelines](<https://devfeed.tech/tags/pipelines.md>), [retrieval](<https://devfeed.tech/tags/retrieval.md>), [safety](<https://devfeed.tech/tags/safety.md>), [scalability](<https://devfeed.tech/tags/scalability.md>), [space](<https://devfeed.tech/tags/space.md>), [user-experience](<https://devfeed.tech/tags/user-experience.md>)

### AI overview

The article describes how NASA and MRI Technologies partnered with Chainguard to build a secure, continuously compliant software foundation for Artemis and Habitable Worlds Observatory missions. It discusses attempts to use retrieval-augmented generation and MCP with mixed-format safety data, while highlighting unresolved data-fidelity and traceability challenges.

### Source excerpt

How NASA Artemis used AI and Chainguard to enable secure, compliant software and faster mission readiness in high-stakes environments.

## Managing third-party images at scale

DevFeed: [Managing third-party images at scale](<https://devfeed.tech/articles/managing-third-party-images-at-scale-13147.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/managing-third-party-images-at-scale>)

Published: 2026-04-16T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [container images](<https://devfeed.tech/topics/container-images.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>), [code productivity](<https://devfeed.tech/topics/code-productivity.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>)

Tags: [appian](<https://devfeed.tech/tags/appian.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [chainguard-os](<https://devfeed.tech/tags/chainguard-os.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-image](<https://devfeed.tech/tags/container-image.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [developer-velocity](<https://devfeed.tech/tags/developer-velocity.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [hardened-images](<https://devfeed.tech/tags/hardened-images.md>), [scale](<https://devfeed.tech/tags/scale.md>), [security](<https://devfeed.tech/tags/security.md>), [third-party-container-images](<https://devfeed.tech/tags/third-party-container-images.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This article explains how Appian approached managing third-party container images at scale with Chainguard. It describes the operational burden caused by image dependencies, vulnerabilities, maintenance, and compliance requirements, including the ongoing work needed for regulated environments such as FedRAMP. It also estimates that building a complete internal hardened-image program would require a dedicated team of 15 to 20 engineers.

### Source excerpt

Learn how companies can scale third-party container image management with Chainguard to reduce risk, cut toil, and accelerate compliance and developer velocity.

## FedRAMP 20x's cybersecurity requirements for AI-enabled SaaS

DevFeed: [FedRAMP 20x's cybersecurity requirements for AI-enabled SaaS](<https://devfeed.tech/articles/fedramp-ai-player-3-has-entered-the-game-29645.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/fedramp-ai-player-3/>)

Author: info@goteleport.com (George Chamales)

Published: 2026-03-13T00:00:00Z

Content type: opinion

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [Requirements](<https://devfeed.tech/topics/requirements.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Software as a service](<https://devfeed.tech/topics/saas.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>)

Tags: [compliance](<https://devfeed.tech/tags/compliance.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [fedramp-20x](<https://devfeed.tech/tags/fedramp-20x.md>), [government](<https://devfeed.tech/tags/government.md>), [news](<https://devfeed.tech/tags/news.md>), [product](<https://devfeed.tech/tags/product.md>), [program](<https://devfeed.tech/tags/program.md>), [requirements](<https://devfeed.tech/tags/requirements.md>), [security](<https://devfeed.tech/tags/security.md>), [team](<https://devfeed.tech/tags/team.md>), [technology](<https://devfeed.tech/tags/technology.md>)

### AI overview

This commentary examines FedRAMP 20x, a refactor of the US federal government's SaaS compliance standard, and considers how its Key Security Indicators apply to AI features. It argues that AI capabilities intersect with cybersecurity, people, and process requirements.

### Source excerpt

FedRAMP 20x: A new player has entered the game.

## Chainguard + Second Front: A faster, more secure path into government markets

DevFeed: [Chainguard + Second Front: A faster, more secure path into government markets](<https://devfeed.tech/articles/chainguard-second-front-a-faster-more-secure-path-into-government-markets-12980.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-second-front-a-faster-more-secure-path-into-government-markets>)

Published: 2026-02-20T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [DevSecOps](<https://devfeed.tech/topics/devsecops.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Deployment](<https://devfeed.tech/topics/deployment.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-for-compliance](<https://devfeed.tech/tags/chainguard-for-compliance.md>), [cmmc](<https://devfeed.tech/tags/cmmc.md>), [container-image-compliance](<https://devfeed.tech/tags/container-image-compliance.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve-remediation](<https://devfeed.tech/tags/cve-remediation.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [federal-compliance](<https://devfeed.tech/tags/federal-compliance.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [government](<https://devfeed.tech/tags/government.md>), [iso](<https://devfeed.tech/tags/iso.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [second-front-systems](<https://devfeed.tech/tags/second-front-systems.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [security](<https://devfeed.tech/tags/security.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>)

### AI overview

Chainguard and Second Front are partnering to help software companies pursue federal market requirements, including FedRAMP authorization and DoD impact-level accreditations. The article describes combining Chainguard's hardened container images with Second Front's Game Warden DevSecOps platform to support secure application delivery and vulnerability reduction.

### Source excerpt

Discover how Chainguard and Second Front are partnering to help build a secure path into government markets for your organization.

## Super SBOMs: See exactly what's inside

DevFeed: [Super SBOMs: See exactly what's inside](<https://devfeed.tech/articles/super-sboms-see-exactly-what-s-inside-13245.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/super-sboms-see-exactly-whats-inside>)

Published: 2026-01-29T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Security](<https://devfeed.tech/topics/security.md>), [spdx](<https://devfeed.tech/topics/spdx.md>)

Tags: [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-sboms](<https://devfeed.tech/tags/chainguard-sboms.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cyclonedx](<https://devfeed.tech/tags/cyclonedx.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [security](<https://devfeed.tech/tags/security.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [spdx](<https://devfeed.tech/tags/spdx.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

Chainguard Containers now provide richer SBOMs with binary-level details about embedded libraries and dependencies, along with CycloneDX support in addition to SPDX. The added visibility helps teams trace vulnerabilities and assess license compliance.

### Source excerpt

Chainguard Containers ship richer SBOMs with binary-level library details plus new CycloneDX support, making CVE impact and compliance tracing fast and clear.

## Chainguard Releases Ruby 4.0 Packages and Container Images

DevFeed: [Chainguard Releases Ruby 4.0 Packages and Container Images](<https://devfeed.tech/articles/unwrapping-ruby-4-0-chainguard-delivers-a-gem-just-in-time-for-boxing-day-13307.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/unwrapping-ruby-4-0>)

Published: 2025-12-26T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Ruby](<https://devfeed.tech/topics/ruby.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [Containers](<https://devfeed.tech/topics/containers.md>)

Tags: [architectures](<https://devfeed.tech/tags/architectures.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-ruby-image](<https://devfeed.tech/tags/chainguard-ruby-image.md>), [cmvp](<https://devfeed.tech/tags/cmvp.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [ruby](<https://devfeed.tech/tags/ruby.md>), [ruby-programming-language](<https://devfeed.tech/tags/ruby-programming-language.md>)

### AI overview

Chainguard announces packages and container images for Ruby 4.0, which includes performance improvements and language refinements. The images support x86_64 and ARM64, include stated hardening and runtime-security features, and are available through Chainguard, Docker Hub, and AWS Public ECR.

### Source excerpt

Chainguard delivers Ruby 4.0 container images: secure, zero-CVE, FIPS-ready, and available free so developers can adopt the latest Ruby safely and fast.

## Figma Make is now available in Figma for Government

DevFeed: [Figma Make is now available in Figma for Government](<https://devfeed.tech/articles/figma-make-is-now-available-in-figma-for-government-9690.md>)

Original publisher: [Read original article](<https://www.figma.com/blog/figma-make-for-gov/>)

Author: Figma

Published: 2025-12-11T00:00:00Z

Content type: article

Language: en

Sources: [Figma Blog](<https://devfeed.tech/sources/figma-blog.md>)

Topics: [Figma](<https://devfeed.tech/topics/figma.md>), [Accessibility](<https://devfeed.tech/topics/accessibility.md>), [User interface design](<https://devfeed.tech/topics/ui-design.md>), [Usability](<https://devfeed.tech/topics/usability.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [accessibility](<https://devfeed.tech/tags/accessibility.md>), [collaboration](<https://devfeed.tech/tags/collaboration.md>), [design](<https://devfeed.tech/tags/design.md>), [design-consistency](<https://devfeed.tech/tags/design-consistency.md>), [executive](<https://devfeed.tech/tags/executive.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [figma](<https://devfeed.tech/tags/figma.md>), [government](<https://devfeed.tech/tags/government.md>), [prototypes](<https://devfeed.tech/tags/prototypes.md>), [prototyping](<https://devfeed.tech/tags/prototyping.md>), [public-sector](<https://devfeed.tech/tags/public-sector.md>), [resources](<https://devfeed.tech/tags/resources.md>), [security](<https://devfeed.tech/tags/security.md>), [speed](<https://devfeed.tech/tags/speed.md>), [standards](<https://devfeed.tech/tags/standards.md>), [tools](<https://devfeed.tech/tags/tools.md>), [tools-and-resources](<https://devfeed.tech/tags/tools-and-resources.md>)

### AI overview

Figma Make is now available in Figma for Government, enabling government teams to create interactive prototypes, collaborate securely, and test ideas more quickly while modernizing public services.

### Source excerpt

With Figma Make now available in Figma for Government, teams can prototype faster, collaborate securely, and accelerate progress on modernizing public services.

## Get up to Speed on FedRAMP 20x

DevFeed: [Get up to Speed on FedRAMP 20x](<https://devfeed.tech/articles/get-up-to-speed-on-fedramp-20x-13064.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/get-up-to-speed-on-fedramp-20x>)

Published: 2025-10-23T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Cloud](<https://devfeed.tech/topics/cloud.md>), [DevSecOps](<https://devfeed.tech/topics/devsecops.md>), [Security](<https://devfeed.tech/topics/security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [Cloud Native Ecosystem](<https://devfeed.tech/topics/cloud-native-ecosystem.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Automation](<https://devfeed.tech/topics/automation.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [Software as a service](<https://devfeed.tech/topics/saas.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [2026](<https://devfeed.tech/tags/2026.md>), [ato](<https://devfeed.tech/tags/ato.md>), [automation](<https://devfeed.tech/tags/automation.md>), [chainguard-compliance](<https://devfeed.tech/tags/chainguard-compliance.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-fedramp-solution](<https://devfeed.tech/tags/chainguard-fedramp-solution.md>), [chainguard-for-fedramp](<https://devfeed.tech/tags/chainguard-for-fedramp.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cloud-native](<https://devfeed.tech/tags/cloud-native.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [containers](<https://devfeed.tech/tags/containers.md>), [containers-for-fedramp](<https://devfeed.tech/tags/containers-for-fedramp.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [fedramp-20x](<https://devfeed.tech/tags/fedramp-20x.md>), [fedramp-containers](<https://devfeed.tech/tags/fedramp-containers.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [saas](<https://devfeed.tech/tags/saas.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [standards](<https://devfeed.tech/tags/standards.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

FedRAMP 20x modernizes cloud authorization through continuous, automation-driven assurance, machine-readable documentation, and streamlined assessment processes. The article explains implications for containerized workloads, vulnerability management, software supply-chain security, ATOs, and organizations transitioning from FedRAMP Rev. 5.

### Source excerpt

FedRAMP 20x is transforming cloud compliance with automation and continuous security. Learn how Chainguard Containers simplify 20x readiness with 0-CVE images.

## Chainguard + Booz Allen: Delivering Trusted Open-Source Software to U.S. Government Agencies

DevFeed: [Chainguard + Booz Allen: Delivering Trusted Open-Source Software to U.S. Government Agencies](<https://devfeed.tech/articles/chainguard-booz-allen-delivering-trusted-open-source-software-to-u-s-government-agencies-12931.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-booz-allen-delivering-trusted-open-source-software-to-u-s-government-agencies>)

Published: 2025-10-15T00:00:00Z

Content type: news

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [announce](<https://devfeed.tech/tags/announce.md>), [ato](<https://devfeed.tech/tags/ato.md>), [booz-allen-hamilton](<https://devfeed.tech/tags/booz-allen-hamilton.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-booz-partnership](<https://devfeed.tech/tags/chainguard-booz-partnership.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-dod-partnership](<https://devfeed.tech/tags/chainguard-dod-partnership.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [common-vulnerabilities-and-exposures](<https://devfeed.tech/tags/common-vulnerabilities-and-exposures.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [fips](<https://devfeed.tech/tags/fips.md>), [government](<https://devfeed.tech/tags/government.md>), [hardened-containers](<https://devfeed.tech/tags/hardened-containers.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [security](<https://devfeed.tech/tags/security.md>), [stateramp](<https://devfeed.tech/tags/stateramp.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [zero-cve-container-images](<https://devfeed.tech/tags/zero-cve-container-images.md>)

### AI overview

Chainguard and Booz Allen announced a partnership to help U.S. government agencies and defense programs secure software supply chains, reduce vulnerabilities, and accelerate compliance. The partnership combines Booz Allen's mission expertise with Chainguard's secure-by-default open-source software, including hardened containers that helped one defense-related program obtain authorization to operate in eight weeks.

### Source excerpt

Chainguard and Booz Allen partner to help federal programs eliminate vulnerabilities, save engineering time, and accelerate compliance timelines.

## Simplify Continuous Compliance: How to Stay Audit-Ready and Ship Software Faster

DevFeed: [Simplify Continuous Compliance: How to Stay Audit-Ready and Ship Software Faster](<https://devfeed.tech/articles/simplify-continuous-compliance-how-to-stay-audit-ready-and-ship-software-faster-13233.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/simplify-continuous-compliance-how-to-stay-audit-ready-and-ship-software-faster>)

Published: 2025-10-14T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Software](<https://devfeed.tech/topics/software.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-security](<https://devfeed.tech/tags/chainguard-security.md>), [cmmc](<https://devfeed.tech/tags/cmmc.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [cves](<https://devfeed.tech/tags/cves.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [iso-27001](<https://devfeed.tech/tags/iso-27001.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [pci-dss](<https://devfeed.tech/tags/pci-dss.md>), [security](<https://devfeed.tech/tags/security.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>), [stateramp](<https://devfeed.tech/tags/stateramp.md>)

### AI overview

This article explains how organizations can treat software compliance as a continuous practice rather than a periodic audit exercise. It describes how open-source components, CVE remediation, provenance, SBOM coverage, and audit evidence affect platform engineering, application security, development velocity, and regulated-market access, while presenting Chainguard as a solution provider.

### Source excerpt

Turn compliance into a growth driver with Chainguard. Eliminate CVEs, stay audit-ready, and meet FedRAMP, SOC 2, and ISO 27001 with secure images.

## Announcing Kernel-Independent FIPS for Java

DevFeed: [Announcing Kernel-Independent FIPS for Java](<https://devfeed.tech/articles/announcing-kernel-independent-fips-for-java-12886.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/announcing-kernel-independent-fips-for-java>)

Published: 2025-08-14T00:00:00Z

Content type: news

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Java](<https://devfeed.tech/topics/java.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Linux](<https://devfeed.tech/topics/linux.md>)

Tags: [amazon](<https://devfeed.tech/tags/amazon.md>), [ato](<https://devfeed.tech/tags/ato.md>), [azure](<https://devfeed.tech/tags/azure.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-fips-images](<https://devfeed.tech/tags/chainguard-fips-images.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cos](<https://devfeed.tech/tags/cos.md>), [cryptography](<https://devfeed.tech/tags/cryptography.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [fedramp-ato](<https://devfeed.tech/tags/fedramp-ato.md>), [fedramp-containers](<https://devfeed.tech/tags/fedramp-containers.md>), [fips](<https://devfeed.tech/tags/fips.md>), [implementation](<https://devfeed.tech/tags/implementation.md>), [java](<https://devfeed.tech/tags/java.md>), [linux](<https://devfeed.tech/tags/linux.md>), [nist](<https://devfeed.tech/tags/nist.md>), [openssl](<https://devfeed.tech/tags/openssl.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

Chainguard announces Kernel-Independent FIPS availability across its Java FIPS image catalog. The update uses FIPS-validated cryptography and validated userspace entropy, allowing Java FIPS workloads to run with any host kernel and on platforms including GKE with COS, Amazon Bottlerocket, Flatcar Linux, and Azure Linux. It is intended to simplify production deployment and accelerate FedRAMP authorization to operate.

### Source excerpt

Kernel-Independent FIPS is now available across the full catalog of Chainguard FIPS images for Java, simplifying and accelerating compliance for FedRAMP ATO.

## How Collaboration.Ai Saved 2 Years and $2 Million with Chainguard, Second Front, and AWS

DevFeed: [How Collaboration.Ai Saved 2 Years and $2 Million with Chainguard, Second Front, and AWS](<https://devfeed.tech/articles/how-collaboration-ai-saved-2-years-and-2-million-with-chainguard-second-front-and-aws-13085.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/how-collaboration-ai-saved-2-years-and-2-million-with-chainguard-second-front-and-aws>)

Published: 2025-07-23T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [DevSecOps](<https://devfeed.tech/topics/devsecops.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>)

Tags: [ato](<https://devfeed.tech/tags/ato.md>), [authority-to-operate](<https://devfeed.tech/tags/authority-to-operate.md>), [aws](<https://devfeed.tech/tags/aws.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cost](<https://devfeed.tech/tags/cost.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [fedramp-ato](<https://devfeed.tech/tags/fedramp-ato.md>), [fedramp-containers](<https://devfeed.tech/tags/fedramp-containers.md>), [govcloud](<https://devfeed.tech/tags/govcloud.md>), [hardened-images](<https://devfeed.tech/tags/hardened-images.md>), [secondfront](<https://devfeed.tech/tags/secondfront.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Collaboration.Ai used Chainguard Containers, Second Front's Game Warden platform, and AWS GovCloud to accelerate CrowdVector's path toward DoD compliance. The combination reduced vulnerabilities by 97% and lowered compliance costs by $2 million.

### Source excerpt

Collaboraton.AI used a combination of Chainguard Containers, Second Front, and AWS to reduce vulnerabilities by 97% and lower compliance costs by $2 million.

## FIPS-Validated Container Images: When, Where, and Why

DevFeed: [FIPS-Validated Container Images: When, Where, and Why](<https://devfeed.tech/articles/fips-validated-container-images-when-where-and-why-13046.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/fips-validated-container-images-when-where-why>)

Published: 2025-07-10T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cryptography](<https://devfeed.tech/tags/cryptography.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [financial-services](<https://devfeed.tech/tags/financial-services.md>), [fips](<https://devfeed.tech/tags/fips.md>), [fips-validation](<https://devfeed.tech/tags/fips-validation.md>), [healthcare](<https://devfeed.tech/tags/healthcare.md>), [nist](<https://devfeed.tech/tags/nist.md>), [public-sector](<https://devfeed.tech/tags/public-sector.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

This article explains why FIPS-validated cryptography is required at the container image level for workloads subject to FedRAMP and NIST 800-53 requirements. It describes Chainguard's FIPS-validated container images, their cryptographic boundaries, and how they help organizations address compliance and authorization requirements in regulated environments.

### Source excerpt

Chainguard's catalog of 1,400+ trusted container images includes 400+ FIPS-validated variants.

[Next page](<https://devfeed.tech/tags/fedramp.md?cursor=WyIyMDI1LTA3LTEwVDAwOjAwOjAwKzAwOjAwIiwgIjVkZDlhNDIyLTI0NzQtNGE4Zi05ODIwLWM2NjhiMDM5YmE1MCJd>)