# open source software security

Published articles for open source software security.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Why Chainguard's Full-Stack Approach to Secure Software Supply Chain Is Built to Scale

DevFeed: [Why Chainguard's Full-Stack Approach to Secure Software Supply Chain Is Built to Scale](<https://devfeed.tech/articles/why-chainguard-s-full-stack-approach-to-secure-software-supply-chain-is-built-to-scale-13328.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/why-chainguards-full-stack-approach-to-secure-software-supply-chain-is-built-to-scale>)

Published: 2025-07-09T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard os](<https://devfeed.tech/topics/chainguard-os.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [automated](<https://devfeed.tech/tags/automated.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-factory](<https://devfeed.tech/tags/chainguard-factory.md>), [chainguard-os](<https://devfeed.tech/tags/chainguard-os.md>), [cve](<https://devfeed.tech/tags/cve.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [open-source-artifacts](<https://devfeed.tech/tags/open-source-artifacts.md>), [open-source-software-security](<https://devfeed.tech/tags/open-source-software-security.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [reproducibility](<https://devfeed.tech/tags/reproducibility.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [secure-software-supply-chain](<https://devfeed.tech/tags/secure-software-supply-chain.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>)

### AI overview

The article presents Chainguard's integrated approach to software supply chain security, combining Chainguard OS with the Chainguard Factory. It describes reproducible source builds, incremental updates, traceable contents, verifiable metadata, and automated maintenance of open source artifacts.

### Source excerpt

Learn how Chainguard OS and the Chainguard Factory delivers the only scalable path to secure, reliable software artifacts.

## Our approach to continuous documentation for Chainguard Images

DevFeed: [Our approach to continuous documentation for Chainguard Images](<https://devfeed.tech/articles/our-approach-to-continuous-documentation-for-chainguard-images-13200.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/our-approach-to-continuous-documentation-for-chainguard-images>)

Published: 2024-01-24T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Documentation](<https://devfeed.tech/topics/documentation.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [PHP](<https://devfeed.tech/topics/php.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [YAML](<https://devfeed.tech/topics/yaml.md>), [JSON](<https://devfeed.tech/topics/json.md>), [Terraform](<https://devfeed.tech/topics/terraform.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [devops](<https://devfeed.tech/tags/devops.md>), [documentation](<https://devfeed.tech/tags/documentation.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [json](<https://devfeed.tech/tags/json.md>), [open-source-software-security](<https://devfeed.tech/tags/open-source-software-security.md>), [oss](<https://devfeed.tech/tags/oss.md>), [php](<https://devfeed.tech/tags/php.md>), [refactoring](<https://devfeed.tech/tags/refactoring.md>), [terraform](<https://devfeed.tech/tags/terraform.md>), [yaml](<https://devfeed.tech/tags/yaml.md>)

### AI overview

This article explains Chainguard's Autodocs system for continuously generating documentation for Chainguard Images. The workflow uses image metadata, README files, PHP, GitHub Actions, JSON caches, and the Chainguard Registry to generate approximately 1,600 Markdown pages for about 500 images at each run.

### Source excerpt

Elevate your DevOps with Chainguard's Autodocs: Continuous, automated documentations for secure container images made easy.

## Software development security redefined: Sourcegraph's story

DevFeed: [Software development security redefined: Sourcegraph's story](<https://devfeed.tech/articles/software-development-security-redefined-sourcegraph-s-story-13236.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/software-development-security-redefined-sourcegraphs-story>)

Published: 2023-12-20T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [software bill of materials](<https://devfeed.tech/topics/software-bill-of-materials.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [customer-story](<https://devfeed.tech/tags/customer-story.md>), [cve](<https://devfeed.tech/tags/cve.md>), [open-source-software-security](<https://devfeed.tech/tags/open-source-software-security.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [sourcegraph](<https://devfeed.tech/tags/sourcegraph.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

This customer story describes how Sourcegraph used Chainguard Images, built on Wolfi OS, together with OpenVEX and SBOMs to simplify vulnerability management and strengthen software supply chain security. The article states that Sourcegraph achieved zero known vulnerabilities in a short timespan.

### Source excerpt

Sourcegraph's story: leveraging Chainguard's technology for streamlined software development and heightened security.

## Application and AI roundup - September

DevFeed: [Application and AI roundup - September](<https://devfeed.tech/articles/application-and-ai-roundup-september-36687.md>)

Original publisher: [Read original article](<https://shostack.org/blog/appsec-roundup-september/>)

Author: Adam

Published: 2023-10-04T00:00:00Z

Content type: article

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [Memory Safety](<https://devfeed.tech/topics/memory-safety.md>), [c/c++](<https://devfeed.tech/topics/c-c-plus-plus.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Zig](<https://devfeed.tech/topics/zig.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [cisa](<https://devfeed.tech/topics/cisa.md>)

Tags: [appsec](<https://devfeed.tech/tags/appsec.md>), [c-c-plus-plus](<https://devfeed.tech/tags/c-c-plus-plus.md>), [c-plus-plus](<https://devfeed.tech/tags/c-plus-plus.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [development](<https://devfeed.tech/tags/development.md>), [memory-safety](<https://devfeed.tech/tags/memory-safety.md>), [open-source-software-security](<https://devfeed.tech/tags/open-source-software-security.md>)

### AI overview

A September roundup covering application security developments involving memory safety, C and C++, Zig, hardware memory tagging, secure-by-design AI guidance, cybersecurity policy for medical devices, and open-source software security.

### Source excerpt

September was a big month in appsec for both memory safety and policy

## Chainguard Announces Participation in Hacker Summer Camp Security Conferences

DevFeed: [Chainguard Announces Participation in Hacker Summer Camp Security Conferences](<https://devfeed.tech/articles/get-in-chainguard-we-re-going-to-fabulous-las-vegas-13059.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/get-in-chainguard-were-going-to-fabulous-las-vegas>)

Published: 2023-08-04T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [software composition analysis](<https://devfeed.tech/topics/software-composition-analysis.md>)

Tags: [black-hat](<https://devfeed.tech/tags/black-hat.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [defcon](<https://devfeed.tech/tags/defcon.md>), [open-source-software-security](<https://devfeed.tech/tags/open-source-software-security.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [sca](<https://devfeed.tech/tags/sca.md>)

### AI overview

Chainguard announces its participation in BSides, Black Hat, and DEFCON in Las Vegas, including a talk on limitations of software composition analysis and software bills of material in vulnerability management.

### Source excerpt

Join the Hacker Summer Camp: A hub for cybersecurity enthusiasts to explore, learn, and collaborate on cutting-edge security strategies.

## Open source software takes center stage at RSA

DevFeed: [Open source software takes center stage at RSA](<https://devfeed.tech/articles/open-source-software-takes-center-stage-at-rsa-13196.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/open-source-software-takes-center-stage-at-rsa>)

Published: 2023-04-24T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [npm](<https://devfeed.tech/topics/npm.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>), [Python](<https://devfeed.tech/topics/python.md>), [OpenID connect (OIDC)](<https://devfeed.tech/topics/oidc.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>)

Tags: [npm](<https://devfeed.tech/tags/npm.md>), [oidc](<https://devfeed.tech/tags/oidc.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [open-source-software-security](<https://devfeed.tech/tags/open-source-software-security.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [python](<https://devfeed.tech/tags/python.md>), [security](<https://devfeed.tech/tags/security.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>)

### AI overview

The article examines why open-source software security became a major topic at the 2023 RSA Conference. It discusses software supply-chain risks, including the Log4j exploit, and highlights package provenance in npm, Sigstore-based signing and verification, and trusted publishers using OpenID Connect in PyPI.

### Source excerpt

Open source software security takes center stage in the 2023 RSA Trends Report. Learn why it's a top concern.

## OSS Security: Chainguard Spring 2023 update

DevFeed: [OSS Security: Chainguard Spring 2023 update](<https://devfeed.tech/articles/oss-security-chainguard-spring-2023-update-13199.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/oss-security-chainguard-spring-2023-update>)

Published: 2023-03-22T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Security](<https://devfeed.tech/topics/security.md>), [software bill of materials](<https://devfeed.tech/topics/software-bill-of-materials.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [cloud-native](<https://devfeed.tech/tags/cloud-native.md>), [cloud-native-security-con](<https://devfeed.tech/tags/cloud-native-security-con.md>), [fosdem](<https://devfeed.tech/tags/fosdem.md>), [foss](<https://devfeed.tech/tags/foss.md>), [gitops](<https://devfeed.tech/tags/gitops.md>), [kubecon-eu](<https://devfeed.tech/tags/kubecon-eu.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [open-source-software-security](<https://devfeed.tech/tags/open-source-software-security.md>), [openssf](<https://devfeed.tech/tags/openssf.md>), [oss](<https://devfeed.tech/tags/oss.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>)

### AI overview

Chainguard's Spring 2023 update describes its involvement in open-source software security during the first part of 2023. It covers community leadership, conference talks and workshops, software freedom advocacy, and efforts to make software bills of materials useful and widely adopted for supply-chain security.

### Source excerpt

Chainguard believes open source is important and we mean it. Check out how we've been involved in OSS Security in the first part of 2023.