# open source software

Published articles for open source software.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## New Hampshire bill HB1273 could enshrine software freedom principles into law

DevFeed: [New Hampshire bill HB1273 could enshrine software freedom principles into law](<https://devfeed.tech/articles/new-hampshire-usa-may-soon-enshrine-software-freedom-into-law-your-help-is-needed-32739.md>)

Original publisher: [Read original article](<https://libreboot.org/news/usa-libre.html>)

Author: Leah Rowe

Published: 2026-09-17T04:32:50.666044Z

Content type: opinion

Language: en

Sources: [News about Libreboot releases and development](<https://devfeed.tech/sources/news-about-libreboot-releases-and-development.md>)

Topics: [Open Source](<https://devfeed.tech/topics/open-source.md>), [make](<https://devfeed.tech/topics/make.md>), [Software](<https://devfeed.tech/topics/software.md>), [libreboot](<https://devfeed.tech/topics/libreboot.md>)

Tags: [article](<https://devfeed.tech/tags/article.md>), [bios](<https://devfeed.tech/tags/bios.md>), [canoeboot](<https://devfeed.tech/tags/canoeboot.md>), [coreboot](<https://devfeed.tech/tags/coreboot.md>), [free-software](<https://devfeed.tech/tags/free-software.md>), [law](<https://devfeed.tech/tags/law.md>), [libre](<https://devfeed.tech/tags/libre.md>), [libreboot](<https://devfeed.tech/tags/libreboot.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [opensource](<https://devfeed.tech/tags/opensource.md>), [software](<https://devfeed.tech/tags/software.md>), [uefi](<https://devfeed.tech/tags/uefi.md>)

### AI overview

Leah Rowe discusses proposed New Hampshire bill HB1273, which the article says would enshrine software freedom and open-source principles into law. The article explains libre software and urges readers, especially those near New Hampshire, to pay attention and share the information.

### Source excerpt

Article: New Hampshire (USA) may soon enshrine Software Freedom into law. YOUR HELP IS NEEDED! Web link: https://libreboot.org/news/usa-libre.html

## What's New in OSS at Khan Academy

DevFeed: [What's New in OSS at Khan Academy](<https://devfeed.tech/articles/what-s-new-in-oss-at-khan-academy-27396.md>)

Original publisher: [Read original article](<http://engineering.khanacademy.org/posts/new-oss-activity.htm>)

Author: Khan Academy

Published: 2017-04-03T22:00:00Z

Content type: article

Language: en

Sources: [Khan Academy](<https://devfeed.tech/sources/khan-academy.md>)

Topics: [Open Source](<https://devfeed.tech/topics/open-source.md>), [Software](<https://devfeed.tech/topics/software.md>), [React](<https://devfeed.tech/topics/react.md>), [Functional programming](<https://devfeed.tech/topics/functional-programming.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [Algorithms](<https://devfeed.tech/topics/algorithms.md>), [jQuery](<https://devfeed.tech/topics/jquery.md>)

Tags: [algorithms](<https://devfeed.tech/tags/algorithms.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [functional-programming](<https://devfeed.tech/tags/functional-programming.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [news](<https://devfeed.tech/tags/news.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [oss](<https://devfeed.tech/tags/oss.md>), [react](<https://devfeed.tech/tags/react.md>), [web-frontend](<https://devfeed.tech/tags/web-frontend.md>)

### AI overview

Khan Academy highlights several recent open-source projects, including Mu Lambda, a small JavaScript library of functional programming utilities; React Balance Text, a React wrapper for Adobe's Balance-Text project; Fuzzy Match Utils, which uses string-matching algorithms for filtering; and React Multi Select.

### Source excerpt

By Brian Genisio At Khan Academy, we rely heavily on Open Source Software (OSS). The majority of our ... Read more

## Open Secure AI Alliance Joins the Linux Foundation to Build a Shared, Open Defense Stack for the AI Era

DevFeed: [Open Secure AI Alliance Joins the Linux Foundation to Build a Shared, Open Defense Stack for the AI Era](<https://devfeed.tech/articles/open-secure-ai-alliance-joins-the-linux-foundation-to-build-a-shared-open-defense-stack-for-the-ai-era-17457.md>)

Original publisher: [Read original article](<https://www.linuxfoundation.org/blog/open-secure-ai-alliance-joins-the-linux-foundation-to-build-a-shared-open-defense-stack-for-the-ai-era>)

Author: andrewb@proximabiz.com (The Linux Foundation)

Published: 2026-09-14T16:00:00Z

Content type: news

Language: en

Sources: [Linux Foundation - Blog](<https://devfeed.tech/sources/linux-foundation-blog.md>)

Topics: [Linux](<https://devfeed.tech/topics/linux.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Securing AI](<https://devfeed.tech/topics/securing-ai.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security](<https://devfeed.tech/topics/security.md>), [Resilience](<https://devfeed.tech/topics/resilience.md>), [Inference](<https://devfeed.tech/topics/inference.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-security](<https://devfeed.tech/tags/ai-security.md>), [collaboration](<https://devfeed.tech/tags/collaboration.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [governance](<https://devfeed.tech/tags/governance.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [linux](<https://devfeed.tech/tags/linux.md>), [models](<https://devfeed.tech/tags/models.md>), [nvidia](<https://devfeed.tech/tags/nvidia.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [resilience](<https://devfeed.tech/tags/resilience.md>), [security](<https://devfeed.tech/tags/security.md>), [september-2026](<https://devfeed.tech/tags/september-2026.md>), [standards](<https://devfeed.tech/tags/standards.md>)

### AI overview

The Open Secure AI Alliance has joined the Linux Foundation under neutral governance. It aims to help organizations collaborate on open AI security tools, research, shared standards, and verifiable defenses spanning models, inference, agents, identity, policy, enforcement, containment, and infrastructure.

### Source excerpt

Originally founded by dozens of enterprise leaders and NVIDIA, the Alliance moves to neutral governance to expand industry collaboration on open AI security tools, research and shared defenses

## LTM Builds a Lightwell Remediation Services Practice Around IBM and Red Hat's $5B Open-Source Program

DevFeed: [LTM Builds a Lightwell Remediation Services Practice Around IBM and Red Hat's $5B Open-Source Program](<https://devfeed.tech/articles/ltm-builds-a-lightwell-remediation-services-practice-around-ibm-and-red-hat-s-5b-open-source-program-12366.md>)

Original publisher: [Read original article](<https://www.storagereview.com/news/ltm-builds-a-lightwell-remediation-services-practice-around-ibm-and-red-hats-5b-open-source-program>)

Author: Harold Fritts

Published: 2026-09-11T16:35:51Z

Content type: news

Language: en

Sources: [StorageReview.com](<https://devfeed.tech/sources/storagereview-com.md>)

Topics: [ibm](<https://devfeed.tech/topics/ibm.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [DevSecOps](<https://devfeed.tech/topics/devsecops.md>), [Deployment](<https://devfeed.tech/topics/deployment.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [ibm](<https://devfeed.tech/tags/ibm.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [red-hat](<https://devfeed.tech/tags/red-hat.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [testing](<https://devfeed.tech/tags/testing.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

LTM is developing a remediation services practice around IBM and Red Hat's Lightwell program, which provides AI-generated, vendor-validated fixes for open-source software vulnerabilities. The offering is intended to help customers plan, prioritize, test, validate, and deploy patches at scale.

### Source excerpt

LTM, the Larsen & Toubro Group services company that was LTIMindtree until its February rebrand, is building a Lightwell remediation services practice around the $5 billion IBM and Red Hat program for securing open-source software with AI-generated, vendor-validated fixes. IBM's clearinghouse produces validated, production-ready patches for open-source dependencies; LTM's job is getting them into customer The post LTM Builds a Lightwell Remediation Services Practice Around IBM and Red Hat's $5B Open-Source Program appeared first on StorageReview.com.

## MAST in the Age of Open Source Software |Guardsquare

DevFeed: [MAST in the Age of Open Source Software |Guardsquare](<https://devfeed.tech/articles/mast-in-the-age-of-open-source-software-guardsquare-26310.md>)

Original publisher: [Read original article](<https://www.guardsquare.com/blog/open-source-software-mast>)

Author: Simon Haven - Product Marketing Manager

Published: 2026-09-01T10:59:01Z

Content type: article

Language: en

Sources: [Guardsquare Blog](<https://devfeed.tech/sources/guardsquare-blog.md>)

Topics: [Open Source](<https://devfeed.tech/topics/open-source.md>), [Mobile Security](<https://devfeed.tech/topics/mobile-security.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [npm](<https://devfeed.tech/topics/npm.md>)

Tags: [app-security-testing](<https://devfeed.tech/tags/app-security-testing.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [appsweep](<https://devfeed.tech/tags/appsweep.md>), [general](<https://devfeed.tech/tags/general.md>), [malware](<https://devfeed.tech/tags/malware.md>), [mobile](<https://devfeed.tech/tags/mobile.md>), [mobile-apps](<https://devfeed.tech/tags/mobile-apps.md>), [npm](<https://devfeed.tech/tags/npm.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This article explains why mobile application security testing is important when apps use free and open source software. It describes how vulnerable, deprecated, compromised, and transitive third-party dependencies can expand an app's attack surface, citing a September 2025 npm supply chain attack as an example.

### Source excerpt

Building with free and open source software (FOSS) has become common practice for app developers. In 2022, it was estimated that between 70% and 90% of any given software codebase was made up of open source components. Leveraging open source projects presents many advantages:

## Agent Night demo recap: How Mastra turned its issue backlog into a software factory

DevFeed: [Agent Night demo recap: How Mastra turned its issue backlog into a software factory](<https://devfeed.tech/articles/agent-night-demo-recap-how-mastra-turned-its-issue-backlog-into-a-software-factory-15988.md>)

Original publisher: [Read original article](<https://workos.com/blog/agent-night-mastra-software-factory-demo-recap>)

Author: WorkOS

Published: 2026-08-17T19:04:08Z

Content type: news

Language: en

Sources: [WorkOS Blog](<https://devfeed.tech/sources/workos-blog.md>)

Topics: [Development](<https://devfeed.tech/topics/development.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [coding](<https://devfeed.tech/topics/coding.md>), [Software](<https://devfeed.tech/topics/software.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [agentic](<https://devfeed.tech/tags/agentic.md>), [agentic-development](<https://devfeed.tech/tags/agentic-development.md>), [agents](<https://devfeed.tech/tags/agents.md>), [coding](<https://devfeed.tech/tags/coding.md>), [demo](<https://devfeed.tech/tags/demo.md>), [development](<https://devfeed.tech/tags/development.md>), [harness](<https://devfeed.tech/tags/harness.md>), [mastra](<https://devfeed.tech/tags/mastra.md>), [memory](<https://devfeed.tech/tags/memory.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [recap](<https://devfeed.tech/tags/recap.md>), [software](<https://devfeed.tech/tags/software.md>), [terminal](<https://devfeed.tech/tags/terminal.md>)

### AI overview

The article recaps Abhi Aiyer's Agent Night demonstration of Mastra's open source software factory. It describes observational memory, Mastra Code, and the AgentController, which supports building interactive agent applications with modes, models, storage, workspaces, approvals, subagents, and channels.

### Source excerpt

Abhi Aiyer, co-founder and CTO of Mastra, demoed the company's open source software factory at Agent Night: memory, harness, a rules engine around work.

## Reverse Engineering a PostHog SuperDay

DevFeed: [Reverse Engineering a PostHog SuperDay](<https://devfeed.tech/articles/reverse-engineering-a-posthog-superday-32359.md>)

Original publisher: [Read original article](<https://joshtronic.com/2026/08/09/reverse-engineering-posthog-superday/>)

Author: Josh Sherman

Published: 2026-08-09T00:00:00Z

Content type: opinion

Language: en

Sources: [Josh Sherman](<https://devfeed.tech/sources/josh-sherman.md>)

Topics: [Reverse Engineering](<https://devfeed.tech/topics/reverse-engineering.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Software](<https://devfeed.tech/topics/software.md>)

Tags: [engineering](<https://devfeed.tech/tags/engineering.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [oss](<https://devfeed.tech/tags/oss.md>), [reverse-engineering](<https://devfeed.tech/tags/reverse-engineering.md>)

### AI overview

The author describes examining PostHog's onboarding wizard and open-source repositories while trying to understand whether certain issues and pull requests were connected to potential candidates. The author remains uncertain about this theory but found the core team's constructive feedback notable.

### Source excerpt

I'm not here to bullshit anybody, I have never been through a PostHog SuperDay. Like many humans, I've read about it on their website, as they are a company that over-communicates just about everything. This tale started when I got curious about their onboarding wizard. Their pivot from analytics to self-driving systems mirrors what I've been working on for the last couple of years, which has accelerated greatly over the last 3 months. Figured there was probably something I could learn and possibly bite off to include in my own system. Figuring out what to do I've been around open source software (OSS) for a good long while now. Even though I've had some strong opinions about the state of things over the years, I still believe it's the way. If not for OSS, I wouldn't be able to say things like "I wrote a Lorem Ipsum generator that's somehow been installed over 1 million times." These days, most projects have a label on their issues that indicate what's good for a new contributor to pick on. PostHog's repos are no different, except the repo I was looking at didn't have any issues tagged with the good first issue tag. Not a big deal, with 100+ open issues I figured I'd be able to find something I could pick up to give me a chance to play with the codebase. I did find a handful of things, I even started to chase down one of them. As I did I realized I kept talking myself out of each issue because what appeared to be low hanging fruit was stuff that I could defend deprioritizing. A pattern started to emerge Along this journey of trying to find an issue worth fighting for, I started to notice a pattern of somewhat disparate issues and PRs opened by the same contributor. I also noticed that core team members (read: employees) were commenting on these issues and PRs and not in the usual "yea or nay" fashion that I see. The comments were constructive in a way that you'd be with a more junior teammate that you're attempting to mentor and train up. Not a bad thing, but the fe

## Codeberg's Generative AI Policy and the Future of Open Source Hosting

DevFeed: [Codeberg's Generative AI Policy and the Future of Open Source Hosting](<https://devfeed.tech/articles/codeberg-divides-30730.md>)

Original publisher: [Read original article](<https://lucumr.pocoo.org/2026/7/24/codeberg-divides/>)

Author: Armin Ronacher

Published: 2026-07-24T00:00:00Z

Content type: opinion

Language: en

Sources: [Armin Ronacher](<https://devfeed.tech/sources/armin-ronacher.md>)

Topics: [Open Source](<https://devfeed.tech/topics/open-source.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>), [Generative AI](<https://devfeed.tech/topics/generative-ai.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [generative-ai](<https://devfeed.tech/tags/generative-ai.md>), [github](<https://devfeed.tech/tags/github.md>), [llms](<https://devfeed.tech/tags/llms.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [thoughts](<https://devfeed.tech/tags/thoughts.md>)

### AI overview

The article examines Codeberg's new terms excluding projects mostly written by generative AI tools. It argues that the policy is vague and may be difficult to enforce, and suggests that clearer rules targeting spam or abusive resource consumption could be preferable. The author argues that well-used LLMs should remain welcome in the Open Source community.

### Source excerpt

Codeberg recently changed its terms to exclude projects that are largely written with generative AI. Considering I want GitHub to get some competition I have thoughts about this. GitHub's governance has never been democratic and there is plenty about the platform that I dislike. Yet I do not need my infrastructure to be democratic but I need it to be predictable and reasonably neutral towards the Open Source software hosted on it. A democratic provider without a clear constitution can be worse at those things than a corporation is. Codeberg is entirely within its rights to do run the platform like they want. It is a German association with members and a democratic process, and that process produced a result. But a democratic vote says nothing about whether the decision is a good one, particularly for the people already depending on the platform. A majority can still decide that certain projects and people no longer belong. The new terms prohibit projects that mostly consist of code written by generative AI tools. That's fine, but these days I could not assign authorship percentages to my recent projects. For me this rule is quite vague and I would bet that it makes it hard to enforce. In practice my assumptoin is that the center will leave. If anything a harsher line would probably be preferable. If Codeberg wants no LLM involvement, it should say so. On the other hand if the objection is just spam and abusive resource consumption, it should write rules for those instead. Now it defers the details of the policy to moderators and the communit which already draws a much harder boundary than the text does, judging by the tone of the discussion around it. It is a shame that the Open Source and Free Software communities are splitting this deeply over LLMs and agents. These systems have problems, but these tools are also becoming part of how software is made. The Open Source world needs to figure out how to engage with that future. More importantly, LLMs if used well, sho

## Not just development, distribution of software may change as well

DevFeed: [Not just development, distribution of software may change as well](<https://devfeed.tech/articles/not-just-development-distribution-of-software-may-change-as-well-20661.md>)

Original publisher: [Read original article](<http://antirez.com/news/170>)

Published: 2026-07-22T14:52:39Z

Content type: opinion

Language: en

Sources: [Antirez](<https://devfeed.tech/sources/antirez.md>)

Topics: [AI-assisted coding](<https://devfeed.tech/topics/ai-assisted-coding.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Template](<https://devfeed.tech/topics/template.md>), [Redis](<https://devfeed.tech/topics/redis.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-coding](<https://devfeed.tech/tags/ai-coding.md>), [coding-agents](<https://devfeed.tech/tags/coding-agents.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [redis](<https://devfeed.tech/tags/redis.md>)

### AI overview

The article argues that AI coding and coding agents may change how open-source software is distributed and maintained. Instead of relying only on stable and unstable branches, repositories may also serve as adaptable templates that users customize for their own requirements. Redis is presented as an example involving proposed memory savings for sorted sets.

### Source excerpt

Even if you are as averse to semver as I used to be in the course of my programming activity, you can still think of open source software distribution as something that used to follow a fixed number of steps. There is a branch where developments happen, and this branch oftentimes happens to be not really ready for reliable work. Then you freeze the developments for a certain amount of time (even if, in the meantime, the work can continue on some new unstable branch), fix bugs, ask people to test it. At some point the number of bug reports starts to drop, your team and your users start to believe there are no longer obvious critical flaws that are easy to discover in the next few weeks: then you call the branch 2.4 or whatever, and that's it. However now, with AI coding, it's not just development that has changed, but also the act itself of using software is affected: it is not just you that can ask an AI to do certain changes to the software, but also the recipient of the software itself. This is obvious in the domains where a piece of software has its main user base among programmers, but this is also true in general, as more and more technologically inclined users have AI access and coding agents. Because of this change, the idea of just having a stable branch with everything polished, and an unstable branch where everything is a work in progress, may no longer be the right way to do things. A code repository can also be a finished product, but could be even more useful if it is a template for how to do things around a given problem. Maybe the user will modify the code in order to specialize it for a specific set of requirements, hardware, specific problems to solve. Also, what is too unstable or unproven for the general public may be the right thing for another set of users. Take the example of Redis. For weeks now I have been iterating on a PR that provides strong memory savings for sorted sets. This work, if accepted, will hit every user of Redis, from people t

## Growing up the hard way

DevFeed: [Growing up the hard way](<https://devfeed.tech/articles/growing-up-the-hard-way-13072.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/growing-up-the-hard-way>)

Published: 2026-07-22T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Open Source](<https://devfeed.tech/topics/open-source.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [ai regulation](<https://devfeed.tech/topics/ai-regulation.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [chainguard-software-supply-chain-security](<https://devfeed.tech/tags/chainguard-software-supply-chain-security.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [oss](<https://devfeed.tech/tags/oss.md>), [security](<https://devfeed.tech/tags/security.md>), [shai-hulud](<https://devfeed.tech/tags/shai-hulud.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [solarwinds](<https://devfeed.tech/tags/solarwinds.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [teampcp](<https://devfeed.tech/tags/teampcp.md>)

### AI overview

This opinion argues that open source is entering a difficult transition after supply-chain incidents, regulatory pressure, and the industrialization of malware. It forecasts that the Open Source definition will remain intact while enterprise and regulatory requirements change which open source software organizations are willing or permitted to consume, with AI-driven vulnerability discovery and poisoned distribution channels creating pressure on both fronts.

### Source excerpt

Open source is growing up. Explore why AI, regulation, and enterprise security are reshaping how organizations consume open source software.

## Rewrote my blog with Zine

DevFeed: [Rewrote my blog with Zine](<https://devfeed.tech/articles/rewrote-my-blog-with-zine-20806.md>)

Original publisher: [Read original article](<https://drewdevault.com/blog/Rewrite-with-zine/>)

Author: April

Published: 2026-04-19T00:00:00Z

Content type: article

Language: en

Sources: [Drew DeVault](<https://devfeed.tech/sources/drew-devault.md>)

Topics: [Website](<https://devfeed.tech/topics/website.md>), [Hugo](<https://devfeed.tech/topics/hugo.md>), [Jekyll](<https://devfeed.tech/topics/jekyll.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [blog](<https://devfeed.tech/tags/blog.md>), [blog-post](<https://devfeed.tech/tags/blog-post.md>), [github-pages](<https://devfeed.tech/tags/github-pages.md>), [hugo](<https://devfeed.tech/tags/hugo.md>), [jekyll](<https://devfeed.tech/tags/jekyll.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [static-site-generator](<https://devfeed.tech/tags/static-site-generator.md>)

### AI overview

The author describes rewriting their blog from Hugo to Zine after frustrations with Hugo's complexity and backwards-incompatible changes. They also discuss porting nearly 400 archived posts and exploring Zine's SuperHTML and SuperMD tools.

### Source excerpt

15 years ago, on December 11th, 2010, at the bold age of 17, I wrote my first blog post on the wonders of the Windows Phone 7 on Blogspot. I started blogging as a kid at the behest of a family friend at Microsoft, who promised she'd make sure I would become the youngest Microsoft MVP if I started blogging. That never came to pass, though, because as I entered adulthood and started to grow independent of my Microsoft-friendly family I quickly began down the path to the free and open source software community. Early blog posts covered intriguing topics such as complaining about my parent's internet filter, a horrible hack to "replace" the battery of a dead gameboy game, announcing my friend's Minecraft guild had a new website (in PHP), and so on. After Blogspot, I moved to Jekyll on GitHub pages, publishing You don't need jQuery in 2013. For a long time this was the oldest post on the site. I'm pretty proud of my writing skills and have a solid grasp on who I am today, but the further back you go the worse my writing, ideas, values, and politics all get. I was growing up in front of the world on this blog, you know? It's pretty embarassing to keep all of this old stuff around. But, I decided a long time ago to keep all of it up, so that people can understand where I've come from, and that everyone has to start somewhere.1 At some point - I'm not sure when - I switched from Jekyll to Hugo, and I've stuck with it since. But lately I've been frustrated with it. I'd like my blog engine to remain relatively stable and simple, but Hugo is quite complex and over the past few years I've been bitten by a number of annoying and backwards-incompatible changes. And, as part of my efforts to remove vibe-coded software from my stack, I was disappointed to learn that Hugo is being vibe coded now, and so rewriting my blog went onto the todo list. Choosing the right static site generator (SSG) was a bit of a frustrating process. Other leading candidates, like Pelican or Zola, are also

## Introducing Chainguard Commercial Builds: Secure-by-default containers for commercial software

DevFeed: [Introducing Chainguard Commercial Builds: Secure-by-default containers for commercial software](<https://devfeed.tech/articles/introducing-chainguard-commercial-builds-secure-by-default-containers-for-commercial-software-13109.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/introducing-chainguard-commercial-builds>)

Published: 2026-03-17T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard commercial builds](<https://devfeed.tech/topics/chainguard-commercial-builds.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [azul](<https://devfeed.tech/tags/azul.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-commercial-builds](<https://devfeed.tech/tags/chainguard-commercial-builds.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [containers](<https://devfeed.tech/tags/containers.md>), [elastic](<https://devfeed.tech/tags/elastic.md>), [f5-nginx](<https://devfeed.tech/tags/f5-nginx.md>), [gitlab](<https://devfeed.tech/tags/gitlab.md>), [grafana-labs](<https://devfeed.tech/tags/grafana-labs.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [partnership](<https://devfeed.tech/tags/partnership.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Chainguard announces Commercial Builds, a partnership program with commercial and open source software providers. The program packages their software with the Chainguard Factory to provide hardened container images and support more consistent software supply chain security.

### Source excerpt

Chainguard Commercial Builds is a new partnership program with commercial and open source software providers to package software using the Chainguard Factory.

## The State of Trusted Open Source: December 2025

DevFeed: [The State of Trusted Open Source: December 2025](<https://devfeed.tech/articles/the-state-of-trusted-open-source-december-2025-13270.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/the-state-of-trusted-open-source-december-2025>)

Published: 2025-12-18T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Open Source](<https://devfeed.tech/topics/open-source.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [ai](<https://devfeed.tech/tags/ai.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-cves](<https://devfeed.tech/tags/chainguard-cves.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [chainguard-report](<https://devfeed.tech/tags/chainguard-report.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cve-data](<https://devfeed.tech/tags/cve-data.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [report](<https://devfeed.tech/tags/report.md>), [security](<https://devfeed.tech/tags/security.md>), [state-of-trusted-open-source](<https://devfeed.tech/tags/state-of-trusted-open-source.md>), [trends](<https://devfeed.tech/tags/trends.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Chainguard's December 2025 State of Trusted Open Source report examines open source usage, CVE data, vulnerability remediation, and compliance trends across its customer base and container image catalog. It highlights Python's role in AI workloads, the prevalence of longtail images in production, the concentration of remediated vulnerabilities outside the top 20 projects, FIPS image usage, and remediation of Critical CVEs in under 20 hours on average.

### Source excerpt

Chainguard's State of Trusted Open Source for December 2025 dives into usage trends for Chainguard Containers, CVE data, and why remediation speed matters.

## Litestream VFS

DevFeed: [Litestream VFS](<https://devfeed.tech/articles/litestream-vfs-1705.md>)

Original publisher: [Read original article](<https://fly.io/blog/litestream-vfs/>)

Published: 2025-12-11T00:00:00Z

Content type: article

Language: en

Sources: [The Fly Blog](<https://devfeed.tech/sources/the-fly-blog.md>)

Topics: [SQLite](<https://devfeed.tech/topics/sqlite.md>), [Amazon S3](<https://devfeed.tech/topics/amazon-s3.md>), [Databases](<https://devfeed.tech/topics/databases.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Development](<https://devfeed.tech/topics/development.md>)

Tags: [cdn](<https://devfeed.tech/tags/cdn.md>), [close-to-users](<https://devfeed.tech/tags/close-to-users.md>), [database](<https://devfeed.tech/tags/database.md>), [deploy-app-servers](<https://devfeed.tech/tags/deploy-app-servers.md>), [dev](<https://devfeed.tech/tags/dev.md>), [docker](<https://devfeed.tech/tags/docker.md>), [elixir](<https://devfeed.tech/tags/elixir.md>), [fly](<https://devfeed.tech/tags/fly.md>), [fly-io](<https://devfeed.tech/tags/fly-io.md>), [heroku-alternative](<https://devfeed.tech/tags/heroku-alternative.md>), [heroku-competitor](<https://devfeed.tech/tags/heroku-competitor.md>), [hosting](<https://devfeed.tech/tags/hosting.md>), [i](<https://devfeed.tech/tags/i.md>), [networking](<https://devfeed.tech/tags/networking.md>), [object-storage](<https://devfeed.tech/tags/object-storage.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [postgresql-clusters](<https://devfeed.tech/tags/postgresql-clusters.md>), [s3](<https://devfeed.tech/tags/s3.md>), [servers](<https://devfeed.tech/tags/servers.md>), [sql](<https://devfeed.tech/tags/sql.md>), [sqlite](<https://devfeed.tech/tags/sqlite.md>)

### AI overview

The article introduces Litestream VFS, which lets SQLite query Litestream-backed databases directly from object storage such as Amazon S3. It supports querying without downloading the entire database and provides SQL- and pragma-based point-in-time recovery. The article also explains how Litestream v0.5 uses LTX ordered page sets and compaction to restore the latest versions of changed database pages efficiently.

### Source excerpt

I'm Ben Johnson, and I work on Litestream at Fly.io. Litestream is the missing backup/restore system for SQLite. It's free, open-source software that should run anywhere, and you can read more about it here. Again with the sandwiches: assume we've got a SQLite database of sandwich ratings, and we've backed it up with Litestream to an S3 bucket. Now, on our local host, load up AWS credentials and an S3 path into our environment. Open SQLite and: Wrap text Copy to clipboard $ sqlite3 SQLite version 3.50.4 2025-07-30 19:33:53 sqlite> .load litestream.so sqlite> .open file:///my.db?vfs=litestream SQLite is now working from that remote database, defined by the Litestream backup files in the S3 path we configured. We can query it: Wrap text Copy to clipboard sqlite> SELECT * FROM sandwich_ratings ORDER BY RANDOM() LIMIT 3 ; 22|Veggie Delight|New York|4 30|Meatball|Los Angeles|5 168|Chicken Shawarma Wrap|Detroit|5 This is Litestream VFS. It runs SQLite hot off an object storage URL. As long as you can load the shared library our tree builds for you, it'll work in your application the same way it does in the SQLite shell. Fun fact: we didn't have to download the whole database to run this query. More about this in a bit. Meanwhile, somewhere in prod, someone has it in for meatball subs and wants to knock them out of the bracket - oh, fuck: Wrap text Copy to clipboard sqlite> UPDATE sandwich_ratings SET stars = 1 ; They forgot the WHERE clause! Wrap text Copy to clipboard sqlite> SELECT * FROM sandwich_ratings ORDER BY RANDOM() LIMIT 3 ; 97|French Dip|Los Angeles|1 140|Bánh Mì|San Francisco|1 62|Italian Beef|Chicago|1 Italian Beefs and Bánh Mìs, all at 1 star. Disaster! But wait, back on our dev machine: Wrap text Copy to clipboard sqlite> PRAGMA litestream_time = '5 minutes ago'; sqlite> select * from sandwich_ratings ORDER BY RANDOM() LIMIT 3 ; 30|Meatball|Los Angeles|5 33|Ham & Swiss|Los Angeles|2 163|Chicken Shawarma Wrap|Detroit|5 We're now querying that database from a

## Chainguard Joins IBM PDE Factory to Advance Trusted Open Source Software for Public Sector Missions

DevFeed: [Chainguard Joins IBM PDE Factory to Advance Trusted Open Source Software for Public Sector Missions](<https://devfeed.tech/articles/chainguard-joins-ibm-pde-factory-to-advance-trusted-open-source-software-for-public-sector-missions-12965.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-joins-ibm-pde-factory-to-advance-trusted-open-source-software-for-public-sector-missions>)

Published: 2025-11-04T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [ibm](<https://devfeed.tech/topics/ibm.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-ibm-partnership](<https://devfeed.tech/tags/chainguard-ibm-partnership.md>), [chainguard-x-ibm](<https://devfeed.tech/tags/chainguard-x-ibm.md>), [containers](<https://devfeed.tech/tags/containers.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [government](<https://devfeed.tech/tags/government.md>), [ibm](<https://devfeed.tech/tags/ibm.md>), [ibm-containers](<https://devfeed.tech/tags/ibm-containers.md>), [ibm-factory](<https://devfeed.tech/tags/ibm-factory.md>), [ibm-pde-factory](<https://devfeed.tech/tags/ibm-pde-factory.md>), [modernization](<https://devfeed.tech/tags/modernization.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [public-sector](<https://devfeed.tech/tags/public-sector.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [secure-software-supply-chain](<https://devfeed.tech/tags/secure-software-supply-chain.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [zero-cve-containers](<https://devfeed.tech/tags/zero-cve-containers.md>)

### AI overview

Chainguard has joined IBM's PDE Factory, an open source-powered secure software development platform for government agencies and regulated enterprises. The integration provides access to Chainguard container images as agencies modernize while addressing security, compliance, and software supply chain requirements.

### Source excerpt

Chainguard joins IBM's PDE Factory to deliver secure, zero-CVE containers for government agencies, accelerating compliance, modernization, and innovation.

## A critique of FUTO's open-source claims, grant program, and affiliations

DevFeed: [A critique of FUTO's open-source claims, grant program, and affiliations](<https://devfeed.tech/articles/what-s-up-with-futo-20817.md>)

Original publisher: [Read original article](<https://drewdevault.com/blog/Whats-up-with-FUTO/>)

Author: October

Published: 2025-10-22T00:00:00Z

Content type: opinion

Language: en

Sources: [Drew DeVault](<https://devfeed.tech/sources/drew-devault.md>)

Topics: [Open Source](<https://devfeed.tech/topics/open-source.md>), [foss](<https://devfeed.tech/topics/foss.md>), [Cloudflare](<https://devfeed.tech/topics/cloudflare.md>)

Tags: [cloudflare](<https://devfeed.tech/tags/cloudflare.md>), [foss](<https://devfeed.tech/tags/foss.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>)

### AI overview

The article criticizes FUTO's use of the term "open source," arguing that the organization applies it to commercial source-available software. It also questions FUTO's grant program, its use of project logos and names, and its collaborations and promotions.

### Source excerpt

Some time ago, I noticed some new organization called FUTO popping up here and there. I'm always interested in seeing new organizations that fund open source popping up, and seeing as they claim several notable projects on their roster, I explored their website with interest and gratitude. I was first confused, and then annoyed by what I found. Confused, because their website is littered with bizzare manifestos,1 and ultimately annoyed because they were playing fast and loose with the term "open source", using it to describe commercial source-available software. FUTO eventually clarified their stance on "open source", first through satire and then somewhat more soberly, perpetuating the self-serving myth that "open source" software can privilege one party over anyone else and still be called open source. I mentally categorized them as problematic but hoped that their donations or grants for genuinely open source projects would do more good than the harm done by this nonsense. By now I've learned better. tl;dr: FUTO is not being honest about their "grant program", they don't have permission to pass off these logos or project names as endorsements, and they collaborate with and promote mask-off, self-proclaimed fascists. An early sign that something is off with FUTO is in that "sober" explanation of their "disdain for OSI approved licenses", where they make a point of criticizing the Open Source Initiative for banning Eric S. Raymond (aka ESR) from their mailing lists, citing right-wing reactionary conspiracy theorist Bryan Lunduke's blog post on the incident. Raymond is, as you may know, one of the founders of OSI and a bigoted asshole. He was banned from the mailing lists, not because he's a bigoted asshole, but because he was being a toxic jerk on the mailing list in question. Healthy institutions outgrow their founders. That said, FUTO's citation and perspective on the ESR incident could be generously explained as a simple mistake, and we should probably match gen

## Three Ways to Make Your SDLC Secure-by-Default

DevFeed: [Three Ways to Make Your SDLC Secure-by-Default](<https://devfeed.tech/articles/three-ways-to-make-your-sdlc-secure-by-default-13293.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/three-ways-to-make-your-sdlc-secure-by-default>)

Published: 2025-10-20T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [sdlc](<https://devfeed.tech/topics/sdlc.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [chainguard-security](<https://devfeed.tech/tags/chainguard-security.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [cloud-native](<https://devfeed.tech/tags/cloud-native.md>), [cves](<https://devfeed.tech/tags/cves.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [sdlc](<https://devfeed.tech/tags/sdlc.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>)

### AI overview

This article presents secure-by-default software development lifecycle practices. It recommends embedding security throughout development, standardizing trusted foundations, securing dependencies and base images, and integrating security into developer tools, CI/CD workflows, and runtime artifacts.

### Source excerpt

Build secure software faster with Chainguard. Learn how secure-by-default SDLC practices eliminate CVEs, automate compliance, and embed trust from code to cloud.

## Chainguard + Booz Allen: Delivering Trusted Open-Source Software to U.S. Government Agencies

DevFeed: [Chainguard + Booz Allen: Delivering Trusted Open-Source Software to U.S. Government Agencies](<https://devfeed.tech/articles/chainguard-booz-allen-delivering-trusted-open-source-software-to-u-s-government-agencies-12931.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-booz-allen-delivering-trusted-open-source-software-to-u-s-government-agencies>)

Published: 2025-10-15T00:00:00Z

Content type: news

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [announce](<https://devfeed.tech/tags/announce.md>), [ato](<https://devfeed.tech/tags/ato.md>), [booz-allen-hamilton](<https://devfeed.tech/tags/booz-allen-hamilton.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-booz-partnership](<https://devfeed.tech/tags/chainguard-booz-partnership.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-dod-partnership](<https://devfeed.tech/tags/chainguard-dod-partnership.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [common-vulnerabilities-and-exposures](<https://devfeed.tech/tags/common-vulnerabilities-and-exposures.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [fips](<https://devfeed.tech/tags/fips.md>), [government](<https://devfeed.tech/tags/government.md>), [hardened-containers](<https://devfeed.tech/tags/hardened-containers.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [security](<https://devfeed.tech/tags/security.md>), [stateramp](<https://devfeed.tech/tags/stateramp.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [zero-cve-container-images](<https://devfeed.tech/tags/zero-cve-container-images.md>)

### AI overview

Chainguard and Booz Allen announced a partnership to help U.S. government agencies and defense programs secure software supply chains, reduce vulnerabilities, and accelerate compliance. The partnership combines Booz Allen's mission expertise with Chainguard's secure-by-default open-source software, including hardened containers that helped one defense-related program obtain authorization to operate in eight weeks.

### Source excerpt

Chainguard and Booz Allen partner to help federal programs eliminate vulnerabilities, save engineering time, and accelerate compliance timelines.

## Simplify Continuous Compliance: How to Stay Audit-Ready and Ship Software Faster

DevFeed: [Simplify Continuous Compliance: How to Stay Audit-Ready and Ship Software Faster](<https://devfeed.tech/articles/simplify-continuous-compliance-how-to-stay-audit-ready-and-ship-software-faster-13233.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/simplify-continuous-compliance-how-to-stay-audit-ready-and-ship-software-faster>)

Published: 2025-10-14T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Software](<https://devfeed.tech/topics/software.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-security](<https://devfeed.tech/tags/chainguard-security.md>), [cmmc](<https://devfeed.tech/tags/cmmc.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [cves](<https://devfeed.tech/tags/cves.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [iso-27001](<https://devfeed.tech/tags/iso-27001.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [pci-dss](<https://devfeed.tech/tags/pci-dss.md>), [security](<https://devfeed.tech/tags/security.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>), [stateramp](<https://devfeed.tech/tags/stateramp.md>)

### AI overview

This article explains how organizations can treat software compliance as a continuous practice rather than a periodic audit exercise. It describes how open-source components, CVE remediation, provenance, SBOM coverage, and audit evidence affect platform engineering, application security, development velocity, and regulated-market access, while presenting Chainguard as a solution provider.

### Source excerpt

Turn compliance into a growth driver with Chainguard. Eliminate CVEs, stay audit-ready, and meet FedRAMP, SOC 2, and ISO 27001 with secure images.

## Applying Zero Trust Principles to Open Source Software Supply Chain Security

DevFeed: [Applying Zero Trust Principles to Open Source Software Supply Chain Security](<https://devfeed.tech/articles/this-shit-is-hard-applying-zero-trust-to-open-source-software-13299.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/unchained-this-shit-is-hard-applying-zero-trust-to-open-source-software>)

Published: 2025-09-29T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Zero Trust](<https://devfeed.tech/topics/zero-trust.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Git](<https://devfeed.tech/topics/git.md>)

Tags: [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [chainguard-security](<https://devfeed.tech/tags/chainguard-security.md>), [git](<https://devfeed.tech/tags/git.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [security](<https://devfeed.tech/tags/security.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [this-shit-is-hard](<https://devfeed.tech/tags/this-shit-is-hard.md>), [zero-trust](<https://devfeed.tech/tags/zero-trust.md>)

### AI overview

This article explains how Chainguard applies Zero Trust principles to open source software supply chain security. It discusses weaknesses in Git identity and long-lived credentials, including risks from impersonation, credential theft, and compromised package publishing.

### Source excerpt

Chainguard implements Zero Trust principles into everything we do to protect critical infrastructure in the age of open source. See how we do it.

## Chainguard Named on the Cloud 100 and a Best Workplace in 2025

DevFeed: [Chainguard Named on the Cloud 100 and a Best Workplace in 2025](<https://devfeed.tech/articles/chainguard-named-on-the-cloud-100-and-a-best-workplace-in-2025-12971.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-named-on-the-cloud-100-and-a-best-workplace-in-2025>)

Published: 2025-09-11T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Security](<https://devfeed.tech/topics/security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [awards](<https://devfeed.tech/tags/awards.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-forbes-cloud-100](<https://devfeed.tech/tags/chainguard-forbes-cloud-100.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cloud-100](<https://devfeed.tech/tags/cloud-100.md>), [company](<https://devfeed.tech/tags/company.md>), [containers](<https://devfeed.tech/tags/containers.md>), [fortune-best-places-to-work](<https://devfeed.tech/tags/fortune-best-places-to-work.md>), [gptw](<https://devfeed.tech/tags/gptw.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [recognition](<https://devfeed.tech/tags/recognition.md>), [security](<https://devfeed.tech/tags/security.md>), [software](<https://devfeed.tech/tags/software.md>)

### AI overview

Chainguard announces recognition from the Forbes Cloud 100, Fortune Best Workplaces in Technology, and Great Place to Work. The article connects these honors to Chainguard's mission of making open source software more trustworthy and providing hardened, secure, production-ready builds through Chainguard Containers.

### Source excerpt

Chainguard has been recognized by the Forbes Cloud 100, Fortune Best Workplaces in Technology, and received a Great Place to Work certification.

## Scaling Trust Through Partnership: Introducing the Chainguard Partner Program

DevFeed: [Scaling Trust Through Partnership: Introducing the Chainguard Partner Program](<https://devfeed.tech/articles/scaling-trust-through-partnership-introducing-the-chainguard-partner-program-13217.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/scaling-trust-through-partnership-introducing-the-chainguard-partner-program>)

Published: 2025-08-13T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>)

Tags: [amazon](<https://devfeed.tech/tags/amazon.md>), [aws](<https://devfeed.tech/tags/aws.md>), [azure](<https://devfeed.tech/tags/azure.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [channel](<https://devfeed.tech/tags/channel.md>), [gcp](<https://devfeed.tech/tags/gcp.md>), [google](<https://devfeed.tech/tags/google.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-artifacts](<https://devfeed.tech/tags/open-source-artifacts.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [partner](<https://devfeed.tech/tags/partner.md>), [partnership](<https://devfeed.tech/tags/partnership.md>), [program](<https://devfeed.tech/tags/program.md>)

### AI overview

Chainguard announces a global Partner Program designed to help channel partners deliver trusted open source software to customers. The program includes a two-tier structure, partner incentives, technical enablement, and joint go-to-market support.

### Source excerpt

The Chainguard Partner Program is a global initiative to empower our channel partners to deliver trusted open source software to customers around the world.

## Introducing First-Party Helm Charts for Chainguard Containers

DevFeed: [Introducing First-Party Helm Charts for Chainguard Containers](<https://devfeed.tech/articles/introducing-first-party-helm-charts-for-chainguard-containers-13115.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/introducing-first-party-helm-charts-for-chainguard-containers>)

Published: 2025-07-08T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Helm charts](<https://devfeed.tech/topics/helm-charts.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Deployment](<https://devfeed.tech/topics/deployment.md>)

Tags: [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [containers](<https://devfeed.tech/tags/containers.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [helm](<https://devfeed.tech/tags/helm.md>), [helm-charts](<https://devfeed.tech/tags/helm-charts.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [oci](<https://devfeed.tech/tags/oci.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [release](<https://devfeed.tech/tags/release.md>)

### AI overview

Chainguard announces the beta launch of first-party Helm Charts designed to work with its continuously updated container images. The charts aim to simplify Kubernetes deployment and management and are provided as OCI artifacts in customers' private registries.

### Source excerpt

Chainguard first-party Helm Charts are designed to work seamlessly with our continuously updated container images. Discover more about our Helm Charts.

## Windmill for Supporting Indigenous Communities - Conservation Metrics Case Study

DevFeed: [Windmill for Supporting Indigenous Communities - Conservation Metrics Case Study](<https://devfeed.tech/articles/windmill-for-supporting-indigenous-communities-conservation-metrics-case-study-30712.md>)

Original publisher: [Read original article](<https://www.windmill.dev/blog/conservation-metrics-case-study>)

Author: Rudo Kemper

Published: 2025-06-03T00:00:00Z

Content type: article

Language: en

Sources: [Windmill Blog](<https://devfeed.tech/sources/windmill-blog.md>)

Topics: [data-processing](<https://devfeed.tech/topics/data-processing.md>), [etl](<https://devfeed.tech/topics/etl.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [data](<https://devfeed.tech/topics/data.md>)

Tags: [brazil](<https://devfeed.tech/tags/brazil.md>), [case-study](<https://devfeed.tech/tags/case-study.md>), [case-study-testimonial-tech-for-good](<https://devfeed.tech/tags/case-study-testimonial-tech-for-good.md>), [dagster](<https://devfeed.tech/tags/dagster.md>), [dashboards](<https://devfeed.tech/tags/dashboards.md>), [data](<https://devfeed.tech/tags/data.md>), [data-processing](<https://devfeed.tech/tags/data-processing.md>), [etl](<https://devfeed.tech/tags/etl.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [tech-for-good](<https://devfeed.tech/tags/tech-for-good.md>), [testimonial](<https://devfeed.tech/tags/testimonial.md>), [whatsapp](<https://devfeed.tech/tags/whatsapp.md>), [windmill](<https://devfeed.tech/tags/windmill.md>), [work](<https://devfeed.tech/tags/work.md>), [workflow](<https://devfeed.tech/tags/workflow.md>)

### AI overview

This case study describes how Conservation Metrics uses Windmill to support environmental monitoring and data sovereignty initiatives with indigenous communities. The workflows collect data from field applications and wildlife sensors, process and load it into databases, generate reports and alerts, notify communities through WhatsApp, and update monitoring dashboards.

### Source excerpt

This is a testimonial from Rudo Kemper from Conservation Metrics about how Windmill has helped them build open-source software for indigenous communities, enabling automated data processing and critical alerts for environmental protection.

[Next page](<https://devfeed.tech/tags/open-source-software.md?cursor=WyIyMDI1LTA2LTAzVDAwOjAwOjAwKzAwOjAwIiwgIjgyNzJkMGI3LWFmM2ItNDliYS05OWYyLTVkN2RhZDFiN2M2YyJd>)