# open source artifacts

Published articles for open source artifacts.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Introducing Chainguard Repository: A unified experience for secure-by-default open source artifacts

DevFeed: [Introducing Chainguard Repository: A unified experience for secure-by-default open source artifacts](<https://devfeed.tech/articles/introducing-chainguard-repository-a-unified-experience-for-secure-by-default-open-source-artifacts-13113.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/introducing-chainguard-repository>)

Published: 2026-03-17T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard repository](<https://devfeed.tech/topics/chainguard-repository.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Security](<https://devfeed.tech/topics/security.md>), [Containers](<https://devfeed.tech/topics/containers.md>)

Tags: [agent-skills](<https://devfeed.tech/tags/agent-skills.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-repo](<https://devfeed.tech/tags/chainguard-repo.md>), [chainguard-repository](<https://devfeed.tech/tags/chainguard-repository.md>), [ci-cd-workflows](<https://devfeed.tech/tags/ci-cd-workflows.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [libraries](<https://devfeed.tech/tags/libraries.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-artifacts](<https://devfeed.tech/tags/open-source-artifacts.md>), [packages](<https://devfeed.tech/tags/packages.md>), [policy](<https://devfeed.tech/tags/policy.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [virtual-machine-images](<https://devfeed.tech/tags/virtual-machine-images.md>)

### AI overview

Chainguard introduces Chainguard Repository, a unified experience for consuming secure-by-default open source artifacts with configurable policy enforcement. It brings together container images, libraries, OS packages, agent skills, CI/CD workflows, and virtual machine images through Chainguard-managed endpoints and provides compliance controls, security improvements through source rebuilds, and visibility dashboards.

### Source excerpt

Chainguard Repository is a single, Chainguard-managed experience for pulling secure-by-default artifacts with built-in, configurable policy enforcement.

## Open Source Supply Chain Security Gotchas to Avoid in 2025

DevFeed: [Open Source Supply Chain Security Gotchas to Avoid in 2025](<https://devfeed.tech/articles/the-engineer-s-never-gift-guide-avoiding-the-nightmare-before-christmas-13251.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/the-engineers-never-gift-guide>)

Published: 2025-12-10T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [chainguard-christmas](<https://devfeed.tech/tags/chainguard-christmas.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [gotchas](<https://devfeed.tech/tags/gotchas.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-artifacts](<https://devfeed.tech/tags/open-source-artifacts.md>), [open-source-components](<https://devfeed.tech/tags/open-source-components.md>), [opinion](<https://devfeed.tech/tags/opinion.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>)

### AI overview

This commentary uses holiday gift metaphors to identify open source supply chain security pitfalls. It warns that repackaged binaries and image catalogs with questionable provenance can introduce maintenance burdens, technical debt, vulnerabilities, and malicious-code risks, and presents building directly from source as a critical control.

### Source excerpt

Skip the "security gift traps." This holiday guide flags common open source supply chain gotchas and shows what to choose instead for speed and trust.

## Scaling Trust Through Partnership: Introducing the Chainguard Partner Program

DevFeed: [Scaling Trust Through Partnership: Introducing the Chainguard Partner Program](<https://devfeed.tech/articles/scaling-trust-through-partnership-introducing-the-chainguard-partner-program-13217.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/scaling-trust-through-partnership-introducing-the-chainguard-partner-program>)

Published: 2025-08-13T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>)

Tags: [amazon](<https://devfeed.tech/tags/amazon.md>), [aws](<https://devfeed.tech/tags/aws.md>), [azure](<https://devfeed.tech/tags/azure.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [channel](<https://devfeed.tech/tags/channel.md>), [gcp](<https://devfeed.tech/tags/gcp.md>), [google](<https://devfeed.tech/tags/google.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-artifacts](<https://devfeed.tech/tags/open-source-artifacts.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [partner](<https://devfeed.tech/tags/partner.md>), [partnership](<https://devfeed.tech/tags/partnership.md>), [program](<https://devfeed.tech/tags/program.md>)

### AI overview

Chainguard announces a global Partner Program designed to help channel partners deliver trusted open source software to customers. The program includes a two-tier structure, partner incentives, technical enablement, and joint go-to-market support.

### Source excerpt

The Chainguard Partner Program is a global initiative to empower our channel partners to deliver trusted open source software to customers around the world.

## Why Chainguard's Full-Stack Approach to Secure Software Supply Chain Is Built to Scale

DevFeed: [Why Chainguard's Full-Stack Approach to Secure Software Supply Chain Is Built to Scale](<https://devfeed.tech/articles/why-chainguard-s-full-stack-approach-to-secure-software-supply-chain-is-built-to-scale-13328.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/why-chainguards-full-stack-approach-to-secure-software-supply-chain-is-built-to-scale>)

Published: 2025-07-09T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard os](<https://devfeed.tech/topics/chainguard-os.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [automated](<https://devfeed.tech/tags/automated.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-factory](<https://devfeed.tech/tags/chainguard-factory.md>), [chainguard-os](<https://devfeed.tech/tags/chainguard-os.md>), [cve](<https://devfeed.tech/tags/cve.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [open-source-artifacts](<https://devfeed.tech/tags/open-source-artifacts.md>), [open-source-software-security](<https://devfeed.tech/tags/open-source-software-security.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [reproducibility](<https://devfeed.tech/tags/reproducibility.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [secure-software-supply-chain](<https://devfeed.tech/tags/secure-software-supply-chain.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>)

### AI overview

The article presents Chainguard's integrated approach to software supply chain security, combining Chainguard OS with the Chainguard Factory. It describes reproducible source builds, incremental updates, traceable contents, verifiable metadata, and automated maintenance of open source artifacts.

### Source excerpt

Learn how Chainguard OS and the Chainguard Factory delivers the only scalable path to secure, reliable software artifacts.

## New Maven Central signing key and snapshot location

DevFeed: [New Maven Central signing key and snapshot location](<https://devfeed.tech/articles/new-maven-central-signing-key-and-snapshot-location-29012.md>)

Original publisher: [Read original article](<https://code.cash.app/new-maven-central-signing-key-and-snapshot-location>)

Author: Jake Wharton

Published: 2025-06-13T00:00:00Z

Content type: release

Language: en

Sources: [Cash App Code Blog](<https://devfeed.tech/sources/cash-app-code-blog.md>)

Topics: [Maven Central](<https://devfeed.tech/topics/maven-central.md>), [Maven](<https://devfeed.tech/topics/maven.md>), [Publishing](<https://devfeed.tech/topics/publishing.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [end-of-life](<https://devfeed.tech/tags/end-of-life.md>), [maven-central](<https://devfeed.tech/tags/maven-central.md>), [open-source-artifacts](<https://devfeed.tech/tags/open-source-artifacts.md>), [public-key](<https://devfeed.tech/tags/public-key.md>), [release](<https://devfeed.tech/tags/release.md>), [server-android](<https://devfeed.tech/tags/server-android.md>), [signing](<https://devfeed.tech/tags/signing.md>), [snapshot](<https://devfeed.tech/tags/snapshot.md>), [snapshots](<https://devfeed.tech/tags/snapshots.md>), [verification](<https://devfeed.tech/tags/verification.md>)

### AI overview

Cash App migrated its open source artifact publishing to Sonatype's new platform after OSSRH reached end of life. The change introduces a company-wide GPG signing key and moves snapshot builds to the Central Portal Snapshot repository.

### Source excerpt

In response to Sonatype announcing the end-of-life for OSSRH, we have migrated to their new publishing platform for our open source artifacts. This is otherwise a transparent change for those who consume these artifacts from Maven Central, but there are two related changes which might affect your builds.

## Trusted Container Images: A Better Way to Build and Deploy Software

DevFeed: [Trusted Container Images: A Better Way to Build and Deploy Software](<https://devfeed.tech/articles/trusted-container-images-a-better-way-to-build-and-deploy-software-13297.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/trusted-container-images-a-better-way-to-build-and-deploy-software>)

Published: 2025-06-11T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Docker Hardened Images](<https://devfeed.tech/topics/docker-hardened-images.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Security](<https://devfeed.tech/topics/security.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [buyers-guide](<https://devfeed.tech/tags/buyers-guide.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [chainguard-vms](<https://devfeed.tech/tags/chainguard-vms.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [open-source-artifacts](<https://devfeed.tech/tags/open-source-artifacts.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [secure-container-images](<https://devfeed.tech/tags/secure-container-images.md>), [secure-open-source-artifacts](<https://devfeed.tech/tags/secure-open-source-artifacts.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>)

### AI overview

Chainguard's Buyer's Guide presents trusted container images and other open source artifacts as a way for enterprise engineering and security teams to reduce maintenance work, address supply-chain risks, and simplify compliance. It highlights Chainguard Containers as minimal, hardened images continuously built from source.

### Source excerpt

Chainguard's Trusted Container Images and Open Source Artifacts Buyer's Guide helps you improve supply chain security and reduce costly engineering toil.