# sbom

Published articles for sbom.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Prepare for the Cyber Resilience Act's 24-hour reporting deadline

DevFeed: [Prepare for the Cyber Resilience Act's 24-hour reporting deadline](<https://devfeed.tech/articles/prepare-for-the-cyber-resilience-act-s-24-hour-reporting-deadline-88.md>)

Original publisher: [Read original article](<https://about.gitlab.com/blog/cyber-resilience-act-reporting-deadline/>)

Author: Amit Shalem

Published: 2026-09-10T00:00:00Z

Content type: article

Language: en

Sources: [GitLab](<https://devfeed.tech/sources/gitlab.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Incident response](<https://devfeed.tech/topics/incident-response.md>)

Tags: [compliance](<https://devfeed.tech/tags/compliance.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [europe](<https://devfeed.tech/tags/europe.md>), [features](<https://devfeed.tech/tags/features.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article explains the Cyber Resilience Act requirement for manufacturers to report actively exploited product vulnerabilities within 24 hours of becoming aware of them. It presents continuous software supply-chain detection, dependency scanning, SBOM monitoring, KEV status, EPSS scores, and container scanning as ways GitLab can help organizations identify and prioritize reportable risks.

### Source excerpt

Starting on September 11, 2026, many businesses that place software on the European Union (EU) market will have 24 hours to file a report once they learn that a vulnerability in one of their products is being actively exploited. This is a new requirement under the Cyber Resilience Act (CRA), the EU law that sets cybersecurity requirements for products with digital elements sold in Europe, put in place to ensure those products are secure by design and supported against new threats. The most stringent requirements under the CRA apply to the manufacturers that make those products, from large software vendors to companies shipping connected hardware. The challenge a business faces to stay compliant is not the filing itself. It is finding out fast enough that a vulnerability in something you shipped is being actively exploited in your software supply chain. The 24-hour clock starts the moment you become aware, this is why detection is so important. Continuous detection is an engineering solution rather than a one-off compliance one. GitLab's software supply chain security capabilities are built to help you find active exploitation in what you shipped, automatically and continuously. This article walks through four questions you should ask yourself about your own pipeline's continuous detection solution today. Reporting requirement starts in September 2026 Beginning September 11, 2026, manufacturers have to report an actively exploited vulnerability within 24 hours of becoming aware of it. The reporting runs in three stages each submitted simultaneously to the European Union Agency for Cybersecurity (ENISA) and to the Computer Security Incident Response Team (CSIRT) designated as coordinator. Early warning, within 24 hours of becoming aware of the actively exploited vulnerability. A short first alert that exploitation is happening. You are not expected to know the full scope of impact or the fix yet. Notification, within 72 hours. A fuller account, covering what is affect

## What it took to reach 1 billion build manifests

DevFeed: [What it took to reach 1 billion build manifests](<https://devfeed.tech/articles/what-it-took-to-reach-1-billion-build-manifests-13318.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/what-it-took-to-reach-1-billion-build-manifests>)

Published: 2026-09-03T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [chainguard os](<https://devfeed.tech/topics/chainguard-os.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [NumPy](<https://devfeed.tech/topics/numpy.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-factory](<https://devfeed.tech/tags/chainguard-factory.md>), [chainguard-os](<https://devfeed.tech/tags/chainguard-os.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [go](<https://devfeed.tech/tags/go.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>)

### AI overview

Chainguard describes how it doubled container build output from 500 million to more than 1 billion manifests in six months. The article explains how Chainguard Factory and Chainguard OS support continuous rebuilds, while using source builds, SLSA Level 3 provenance, Sigstore signatures, and full SBOMs.

### Source excerpt

Chainguard doubled its container build output in six months. Learn how Factory 2.0 uses AI and reconciliation to rebuild secure software at scale.

## Proven, not promised: Chainguard Containers achieves SLSA Build Level 3

DevFeed: [Proven, not promised: Chainguard Containers achieves SLSA Build Level 3](<https://devfeed.tech/articles/proven-not-promised-chainguard-containers-achieves-slsa-build-level-3-13206.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/proven-not-promised-chainguard-containers-achieves-slsa-build-level-3>)

Published: 2026-08-17T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [software bill of materials](<https://devfeed.tech/topics/software-bill-of-materials.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [security](<https://devfeed.tech/tags/security.md>), [signing](<https://devfeed.tech/tags/signing.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>)

### AI overview

Chainguard says Coalfire independently assessed the Chainguard Containers build and release system as meeting SLSA Build Level 3 requirements. The article describes hardened, isolated builds, separately managed signing, provenance generation, and signed SBOMs for releases.

### Source excerpt

Coalfire independently assessed Chainguard Containers at SLSA Build Level 3, validating hardened builds, provenance, and supply chain integrity.

## What's New in vcpkg (Jul 2026)

DevFeed: [What's New in vcpkg (Jul 2026)](<https://devfeed.tech/articles/what-s-new-in-vcpkg-jul-2026-2964.md>)

Original publisher: [Read original article](<https://devblogs.microsoft.com/cppblog/whats-new-in-vcpkg-jul-2026/>)

Author: Augustin Popa

Published: 2026-08-11T22:43:41Z

Content type: release

Language: en

Sources: [C++ Team Blog](<https://devfeed.tech/sources/c-team-blog.md>)

Topics: [releases](<https://devfeed.tech/topics/releases.md>), [C++](<https://devfeed.tech/topics/c-plus-plus.md>)

Tags: [bug](<https://devfeed.tech/tags/bug.md>), [c-plus-plus](<https://devfeed.tech/tags/c-plus-plus.md>), [changelog](<https://devfeed.tech/tags/changelog.md>), [releases](<https://devfeed.tech/tags/releases.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [vcpkg](<https://devfeed.tech/tags/vcpkg.md>)

### AI overview

The July 2026 vcpkg release adds SBOM metadata improvements, updates 302 ports, and includes deployment, compatibility, robustness, documentation, and bug-fix changes.

### Source excerpt

These updates include major SBOM improvements in vcpkg-tool, 302 updated ports including multiple major library upgrades, and other minor improvements and bug fixes. The post What's New in vcpkg (Jul 2026) appeared first on C++ Team Blog.

## A Forgotten Contributor Account Compromised the Entire Mastra npm Package Scope

DevFeed: [A Forgotten Contributor Account Compromised the Entire Mastra npm Package Scope](<https://devfeed.tech/articles/a-forgotten-contributor-account-compromised-the-entire-mastra-npm-package-scope-7788.md>)

Original publisher: [Read original article](<https://snyk.io/blog/a-forgotten-contributor-account-compromised-the-entire-mastra-npm-package-scope/>)

Author: Liran Tal; Marian Corneci

Published: 2026-06-16T21:00:00Z

Content type: news

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [incident](<https://devfeed.tech/topics/incident.md>)

Tags: [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [cross-platform](<https://devfeed.tech/tags/cross-platform.md>), [cryptocurrency](<https://devfeed.tech/tags/cryptocurrency.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [incident](<https://devfeed.tech/tags/incident.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [node-js](<https://devfeed.tech/tags/node-js.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [payload](<https://devfeed.tech/tags/payload.md>), [persistence](<https://devfeed.tech/tags/persistence.md>), [remote-access-trojan](<https://devfeed.tech/tags/remote-access-trojan.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [scm](<https://devfeed.tech/tags/scm.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [tech](<https://devfeed.tech/tags/tech.md>), [tls](<https://devfeed.tech/tags/tls.md>), [vulnerability-insights](<https://devfeed.tech/tags/vulnerability-insights.md>)

### AI overview

A dormant former-contributor npm account was compromised and used to republish the Mastra package scope with a malicious dependency that installs cryptocurrency-stealing malware and a persistent remote-access trojan. The article describes the stale access control that enabled the supply-chain incident and advises treating affected installations as credential and wallet exposure events.

### Source excerpt

A dormant contributor account was used to republish the entire @mastra npm scope, each injected with a single dependency, easy-day-js, that drops a cross-platform cryptocurrency stealer. Here is how the attack worked, how to check exposure, and how to remediate.

## Miasma supply chain attack: malicious code found in @redhat-cloud-services npm packages

DevFeed: [Miasma supply chain attack: malicious code found in @redhat-cloud-services npm packages](<https://devfeed.tech/articles/miasma-supply-chain-attack-malicious-code-found-in-redhat-cloud-services-npm-packages-8014.md>)

Original publisher: [Read original article](<https://snyk.io/blog/miasma-supply-chain-attack-malicious-code-redhat-cloud-services-npm-packages/>)

Author: Brian Clark

Published: 2026-06-01T00:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [npm packages](<https://devfeed.tech/topics/npm-packages.md>), [redhat](<https://devfeed.tech/topics/redhat.md>), [incident](<https://devfeed.tech/topics/incident.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [OpenID connect (OIDC)](<https://devfeed.tech/topics/oidc.md>), [API](<https://devfeed.tech/topics/api.md>), [React](<https://devfeed.tech/topics/react.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [article](<https://devfeed.tech/tags/article.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [cloud-security](<https://devfeed.tech/tags/cloud-security.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [enablement](<https://devfeed.tech/tags/enablement.md>), [github](<https://devfeed.tech/tags/github.md>), [incident](<https://devfeed.tech/tags/incident.md>), [interest](<https://devfeed.tech/tags/interest.md>), [npm-packages](<https://devfeed.tech/tags/npm-packages.md>), [oidc](<https://devfeed.tech/tags/oidc.md>), [payload](<https://devfeed.tech/tags/payload.md>), [react](<https://devfeed.tech/tags/react.md>), [redhat](<https://devfeed.tech/tags/redhat.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [scm](<https://devfeed.tech/tags/scm.md>), [scope](<https://devfeed.tech/tags/scope.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [snyk-security-intel](<https://devfeed.tech/tags/snyk-security-intel.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [tech](<https://devfeed.tech/tags/tech.md>), [vulnerability-insights](<https://devfeed.tech/tags/vulnerability-insights.md>)

### AI overview

The Miasma supply chain attack compromised at least 32 @redhat-cloud-services npm package releases used by the Red Hat Hybrid Cloud Console. The malicious installation script steals developer and cloud credentials, attempts to spread through packages victims can publish, and may expose secrets on affected workstations and CI runners.

### Source excerpt

A supply chain worm dubbed Miasma has been found in dozens of @redhat-cloud-services npm releases. The malicious preinstall hook steals credentials, probes cloud identities, and can republish other packages.

## TanStack Npm Packages Compromised Inside The Mini Shai Hulud Supply Chain Attack

DevFeed: [TanStack Npm Packages Compromised Inside The Mini Shai Hulud Supply Chain Attack](<https://devfeed.tech/articles/tanstack-npm-packages-compromised-inside-the-mini-shai-hulud-supply-chain-attack-8204.md>)

Original publisher: [Read original article](<https://snyk.io/blog/tanstack-npm-packages-compromised/>)

Author: Stephen Thoemmes

Published: 2026-05-11T05:00:00Z

Content type: news

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [incident](<https://devfeed.tech/topics/incident.md>)

Tags: [article](<https://devfeed.tech/tags/article.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [cache](<https://devfeed.tech/tags/cache.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [cryptographic](<https://devfeed.tech/tags/cryptographic.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [github](<https://devfeed.tech/tags/github.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [identity](<https://devfeed.tech/tags/identity.md>), [incident](<https://devfeed.tech/tags/incident.md>), [maintainers](<https://devfeed.tech/tags/maintainers.md>), [memory](<https://devfeed.tech/tags/memory.md>), [npm-packages](<https://devfeed.tech/tags/npm-packages.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [scm](<https://devfeed.tech/tags/scm.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [snyk-security-intel](<https://devfeed.tech/tags/snyk-security-intel.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [teampcp](<https://devfeed.tech/tags/teampcp.md>), [tech](<https://devfeed.tech/tags/tech.md>), [toolchain](<https://devfeed.tech/tags/toolchain.md>), [vulnerability-insights](<https://devfeed.tech/tags/vulnerability-insights.md>), [workflow](<https://devfeed.tech/tags/workflow.md>)

### AI overview

TanStack's legitimate release pipeline was hijacked to publish malicious npm packages with valid SLSA provenance. The article describes the Mini Shai-Hulud supply-chain attack, its impact, and remediation guidance to rotate secrets on affected install environments.

### Source excerpt

On May 11, 2026, the Mini Shai-Hulud worm compromised 84 npm package artifacts across 42 @tanstack/* packages (as well as @squawk/*, @mistralai/* packages, and others) by chaining a GitHub Actions "Pwn Request," cache poisoning, and OIDC token extraction from runner memory -- producing the first npm supply chain attack with valid SLSA Build Level 3 attestations. Here's what happened, what was stolen, and what you need to do right now.

## lightning PyPI Compromise: A Bun-Based Credential Stealer in Python

DevFeed: [lightning PyPI Compromise: A Bun-Based Credential Stealer in Python](<https://devfeed.tech/articles/lightning-pypi-compromise-a-bun-based-credential-stealer-in-python-8001.md>)

Original publisher: [Read original article](<https://snyk.io/blog/lightning-pypi-compromise-bun-based-credential-stealer/>)

Author: Stephen Thoemmes

Published: 2026-04-30T00:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Python](<https://devfeed.tech/topics/python.md>), [Bun](<https://devfeed.tech/topics/bun.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [snyk-learn](<https://devfeed.tech/topics/snyk-learn.md>), [npm](<https://devfeed.tech/topics/npm.md>), [releases](<https://devfeed.tech/topics/releases.md>)

Tags: [article](<https://devfeed.tech/tags/article.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [code](<https://devfeed.tech/tags/code.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [github](<https://devfeed.tech/tags/github.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [payload](<https://devfeed.tech/tags/payload.md>), [python](<https://devfeed.tech/tags/python.md>), [release](<https://devfeed.tech/tags/release.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [security](<https://devfeed.tech/tags/security.md>), [security-labs](<https://devfeed.tech/tags/security-labs.md>), [snyk-learn](<https://devfeed.tech/tags/snyk-learn.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [snyk-security-intel](<https://devfeed.tech/tags/snyk-security-intel.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [tech](<https://devfeed.tech/tags/tech.md>), [vulnerability-insights](<https://devfeed.tech/tags/vulnerability-insights.md>)

### AI overview

A compromised lightning PyPI release downloads the Bun JavaScript runtime at import time and executes an approximately 11 MB obfuscated credential stealer. The article covers the package compromise, Snyk advisory, remediation, and similarities to the preceding Mini Shai-Hulud npm campaign.

### Source excerpt

A malicious release of the lightning PyPI package ships a credential-stealing Bun payload that runs on import. Snyk has a live advisory. Here's what's in the package, what to rotate, and how the payload pattern connects to the Mini Shai-Hulud npm campaign one day earlier.

## JPMorgan Just Published a Cyber To-Do List and Snyk Covers 8 of the 10 Items. How do you stack up?

DevFeed: [JPMorgan Just Published a Cyber To-Do List and Snyk Covers 8 of the 10 Items. How do you stack up?](<https://devfeed.tech/articles/jpmorgan-just-published-a-cyber-to-do-list-and-snyk-covers-8-of-the-10-items-how-do-you-stack-up-8122.md>)

Original publisher: [Read original article](<https://snyk.io/blog/snyk-covers-jpmorgan-cyber-list/>)

Author: John Carione

Published: 2026-04-23T00:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Resilience](<https://devfeed.tech/topics/resilience.md>), [Security](<https://devfeed.tech/topics/security.md>), [snyk-iac](<https://devfeed.tech/topics/snyk-iac.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Infrastructure as code](<https://devfeed.tech/topics/infrastructure-as-code.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [AI Development](<https://devfeed.tech/topics/ai-development.md>), [releases](<https://devfeed.tech/topics/releases.md>), [pull-requests](<https://devfeed.tech/topics/pull-requests.md>), [Code](<https://devfeed.tech/topics/code.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-development](<https://devfeed.tech/tags/ai-development.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [cloud-security](<https://devfeed.tech/tags/cloud-security.md>), [code](<https://devfeed.tech/tags/code.md>), [contentlab](<https://devfeed.tech/tags/contentlab.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [executive](<https://devfeed.tech/tags/executive.md>), [iac-security](<https://devfeed.tech/tags/iac-security.md>), [interest](<https://devfeed.tech/tags/interest.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [pull-requests](<https://devfeed.tech/tags/pull-requests.md>), [releases](<https://devfeed.tech/tags/releases.md>), [resilience](<https://devfeed.tech/tags/resilience.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-cloud](<https://devfeed.tech/tags/snyk-cloud.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>), [snyk-container](<https://devfeed.tech/tags/snyk-container.md>), [snyk-iac](<https://devfeed.tech/tags/snyk-iac.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [snyk-security-intel](<https://devfeed.tech/tags/snyk-security-intel.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

JPMorganChase's 10-point cyber resilience checklist addresses enterprise security priorities spanning software versions, open-source dependencies, SBOMs, build pipelines, secrets, infrastructure as code, and AI development. The article explains how Snyk covers eight of the ten actions through developer workflows and its security platform.

### Source excerpt

JPMorganChase published a 10-point cyber resilience checklist. See how Snyk covers 8 of the 10 actions and where it fits in your security stack.

## I Read Cursor's Security Agent Prompts, So You Don't Have To

DevFeed: [I Read Cursor's Security Agent Prompts, So You Don't Have To](<https://devfeed.tech/articles/i-read-cursor-s-security-agent-prompts-so-you-don-t-have-to-7878.md>)

Original publisher: [Read original article](<https://snyk.io/blog/cursor-security-agent-prompts/>)

Author: Randall Degges

Published: 2026-03-17T04:00:00Z

Content type: opinion

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [cursor](<https://devfeed.tech/topics/cursor.md>), [Securing AI](<https://devfeed.tech/topics/securing-ai.md>), [ai security](<https://devfeed.tech/topics/ai-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [MCP Server](<https://devfeed.tech/topics/mcp-server.md>), [Orchestration](<https://devfeed.tech/topics/orchestration.md>), [Prompt Engineering](<https://devfeed.tech/topics/prompt-engineering.md>), [Terraform](<https://devfeed.tech/topics/terraform.md>), [Persistence](<https://devfeed.tech/topics/persistence.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [agentic](<https://devfeed.tech/tags/agentic.md>), [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-security](<https://devfeed.tech/tags/ai-security.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [automation](<https://devfeed.tech/tags/automation.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [cursor](<https://devfeed.tech/tags/cursor.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [executive](<https://devfeed.tech/tags/executive.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [interest](<https://devfeed.tech/tags/interest.md>), [mcp](<https://devfeed.tech/tags/mcp.md>), [mcp-server](<https://devfeed.tech/tags/mcp-server.md>), [orchestration](<https://devfeed.tech/tags/orchestration.md>), [persistence](<https://devfeed.tech/tags/persistence.md>), [related-content](<https://devfeed.tech/tags/related-content.md>), [review](<https://devfeed.tech/tags/review.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [scm](<https://devfeed.tech/tags/scm.md>), [secrel](<https://devfeed.tech/tags/secrel.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [terraform](<https://devfeed.tech/tags/terraform.md>), [vs-code](<https://devfeed.tech/tags/vs-code.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article examines Cursor's security review automation, which uses four autonomous agents to review more than 3,000 pull requests weekly, identify more than 200 vulnerabilities, and open fix pull requests. It argues that the concise prompts are only one part of the system; the larger achievement is the production infrastructure supporting persistence, deduplication, deployment, webhook orchestration, and state management.

### Source excerpt

Cursor built AI security agents that review 3,000+ PRs weekly and catch 200+ vulnerabilities. Here's what they get right--and what's missing for enterprise security.

## Introducing Chainguard Commercial Builds: Secure-by-default containers for commercial software

DevFeed: [Introducing Chainguard Commercial Builds: Secure-by-default containers for commercial software](<https://devfeed.tech/articles/introducing-chainguard-commercial-builds-secure-by-default-containers-for-commercial-software-13109.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/introducing-chainguard-commercial-builds>)

Published: 2026-03-17T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard commercial builds](<https://devfeed.tech/topics/chainguard-commercial-builds.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [azul](<https://devfeed.tech/tags/azul.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-commercial-builds](<https://devfeed.tech/tags/chainguard-commercial-builds.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [containers](<https://devfeed.tech/tags/containers.md>), [elastic](<https://devfeed.tech/tags/elastic.md>), [f5-nginx](<https://devfeed.tech/tags/f5-nginx.md>), [gitlab](<https://devfeed.tech/tags/gitlab.md>), [grafana-labs](<https://devfeed.tech/tags/grafana-labs.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [partnership](<https://devfeed.tech/tags/partnership.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Chainguard announces Commercial Builds, a partnership program with commercial and open source software providers. The program packages their software with the Chainguard Factory to provide hardened container images and support more consistent software supply chain security.

### Source excerpt

Chainguard Commercial Builds is a new partnership program with commercial and open source software providers to package software using the Chainguard Factory.

## RED DA Assessment Tool for ESP-IDF EN 18031 Self-Assessment

DevFeed: [RED DA Assessment Tool for ESP-IDF EN 18031 Self-Assessment](<https://devfeed.tech/articles/red-da-assessment-tool-streamline-your-esp32-cybersecurity-compliance-13758.md>)

Original publisher: [Read original article](<https://developer.espressif.com/blog/2026/03/red_da_assessment_tool_overview/>)

Author: John Lee

Published: 2026-03-17T00:00:00Z

Content type: tutorial

Language: en

Sources: [Blog on Developer Portal](<https://devfeed.tech/sources/blog-on-developer-portal.md>)

Topics: [EN 18031](<https://devfeed.tech/topics/en-18031.md>), [ESP32](<https://devfeed.tech/topics/esp32.md>), [ESP-IDF](<https://devfeed.tech/topics/esp-idf.md>), [Internet of things](<https://devfeed.tech/topics/iot.md>)

Tags: [blog](<https://devfeed.tech/tags/blog.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [en-18031](<https://devfeed.tech/tags/en-18031.md>), [esp-idf](<https://devfeed.tech/tags/esp-idf.md>), [esp32](<https://devfeed.tech/tags/esp32.md>), [iot](<https://devfeed.tech/tags/iot.md>), [red-directive](<https://devfeed.tech/tags/red-directive.md>), [regulatory](<https://devfeed.tech/tags/regulatory.md>), [sbom](<https://devfeed.tech/tags/sbom.md>)

### AI overview

This tutorial explains Espressif's RED DA Assessment Tool for ESP-IDF projects. The web application reads configuration files, scans an SBOM for known vulnerabilities, pre-fills a security questionnaire, and generates documentation for RED Delegated Act EN 18031 self-assessment.

### Source excerpt

The RED DA Assessment Tool simplifies the process of achieving cybersecurity compliance for ESP32 devices in line with the EU's EN 18031 standards. This article explains how the tool helps you gather, validate, and generate all necessary documentation for RED Delegated Act self-assessment, including uploading configuration and SBOM files, completing risk assessments, mapping technical requirements, and preparing a declaration of conformity--making self-declaration fast, accurate, and accessible for IoT developers.

## Staying Ahead with ESP32 Security Updates

DevFeed: [Staying Ahead with ESP32 Security Updates](<https://devfeed.tech/articles/staying-ahead-with-esp32-security-updates-13755.md>)

Original publisher: [Read original article](<https://developer.espressif.com/blog/2026/03/esp32-security-updates/>)

Author: John Lee

Published: 2026-03-05T00:00:00Z

Content type: article

Language: en

Sources: [Blog on Developer Portal](<https://devfeed.tech/sources/blog-on-developer-portal.md>)

Topics: [ESP32](<https://devfeed.tech/topics/esp32.md>), [Security](<https://devfeed.tech/topics/security.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [cyber resilience act](<https://devfeed.tech/topics/cyber-resilience-act.md>), [dashboards](<https://devfeed.tech/topics/dashboards.md>), [ESP-IDF](<https://devfeed.tech/topics/esp-idf.md>), [Espressif](<https://devfeed.tech/topics/espressif.md>), [software bill of materials](<https://devfeed.tech/topics/software-bill-of-materials.md>)

Tags: [blog](<https://devfeed.tech/tags/blog.md>), [cyber-resilience-act](<https://devfeed.tech/tags/cyber-resilience-act.md>), [dashboards](<https://devfeed.tech/tags/dashboards.md>), [esp-idf](<https://devfeed.tech/tags/esp-idf.md>), [esp32](<https://devfeed.tech/tags/esp32.md>), [espressif](<https://devfeed.tech/tags/espressif.md>), [iot](<https://devfeed.tech/tags/iot.md>), [lts](<https://devfeed.tech/tags/lts.md>), [ota](<https://devfeed.tech/tags/ota.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

This article explains how the ESP32 ecosystem supports long-term firmware security and compliance under regulations such as the EU Cyber Resilience Act. It covers vulnerability management, secure OTA updates, Long-Term Support branches, the ESP-IDF Security Dashboard, and SBOMs for tracking affected components and patched versions.

### Source excerpt

This article explains how manufacturers can use the ESP32 ecosystem to build and maintain secure firmware over time, especially in light of new regulations like the EU Cyber Resilience Act. It highlights tools such as vulnerability dashboards, Long-Term Support branches, and secure OTA updates to ensure ongoing compliance and device security.

## Snyk and uv, Better Together

DevFeed: [Snyk and uv, Better Together](<https://devfeed.tech/articles/snyk-and-uv-better-together-8177.md>)

Original publisher: [Read original article](<https://snyk.io/blog/snyk-uv-partnership/>)

Author: Ryan Searle

Published: 2026-02-24T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Package Management](<https://devfeed.tech/topics/package-management.md>), [Python](<https://devfeed.tech/topics/python.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [AI Development](<https://devfeed.tech/topics/ai-development.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [JSON](<https://devfeed.tech/topics/json.md>), [Maintainers](<https://devfeed.tech/topics/maintainers.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [toolchain](<https://devfeed.tech/topics/toolchain.md>), [pip](<https://devfeed.tech/topics/pip.md>), [Poetry](<https://devfeed.tech/topics/poetry.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-development](<https://devfeed.tech/tags/ai-development.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [developer](<https://devfeed.tech/tags/developer.md>), [development](<https://devfeed.tech/tags/development.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [enablement](<https://devfeed.tech/tags/enablement.md>), [executive](<https://devfeed.tech/tags/executive.md>), [github](<https://devfeed.tech/tags/github.md>), [interest](<https://devfeed.tech/tags/interest.md>), [json](<https://devfeed.tech/tags/json.md>), [maintainers](<https://devfeed.tech/tags/maintainers.md>), [package-management](<https://devfeed.tech/tags/package-management.md>), [pmm](<https://devfeed.tech/tags/pmm.md>), [python](<https://devfeed.tech/tags/python.md>), [related-content](<https://devfeed.tech/tags/related-content.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [toolchain](<https://devfeed.tech/tags/toolchain.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Snyk and uv have partnered to combine uv's high-performance Python package management with supply chain security. Their collaboration adds native CycloneDX SBOM export to uv, enabling Snyk vulnerability and license-compliance testing for uv-managed projects.

### Source excerpt

Snyk and uv have teamed up to provide high-performance package management with native security for Python-based AI development. Build, install, and secure your AI-native applications from inception with Snyk's native support for the uv ecosystem.

## Chainguard + Second Front: A faster, more secure path into government markets

DevFeed: [Chainguard + Second Front: A faster, more secure path into government markets](<https://devfeed.tech/articles/chainguard-second-front-a-faster-more-secure-path-into-government-markets-12980.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-second-front-a-faster-more-secure-path-into-government-markets>)

Published: 2026-02-20T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [DevSecOps](<https://devfeed.tech/topics/devsecops.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Deployment](<https://devfeed.tech/topics/deployment.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-for-compliance](<https://devfeed.tech/tags/chainguard-for-compliance.md>), [cmmc](<https://devfeed.tech/tags/cmmc.md>), [container-image-compliance](<https://devfeed.tech/tags/container-image-compliance.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve-remediation](<https://devfeed.tech/tags/cve-remediation.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [federal-compliance](<https://devfeed.tech/tags/federal-compliance.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [government](<https://devfeed.tech/tags/government.md>), [iso](<https://devfeed.tech/tags/iso.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [second-front-systems](<https://devfeed.tech/tags/second-front-systems.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [security](<https://devfeed.tech/tags/security.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>)

### AI overview

Chainguard and Second Front are partnering to help software companies pursue federal market requirements, including FedRAMP authorization and DoD impact-level accreditations. The article describes combining Chainguard's hardened container images with Second Front's Game Warden DevSecOps platform to support secure application delivery and vulnerability reduction.

### Source excerpt

Discover how Chainguard and Second Front are partnering to help build a secure path into government markets for your organization.

## Super SBOMs: See exactly what's inside

DevFeed: [Super SBOMs: See exactly what's inside](<https://devfeed.tech/articles/super-sboms-see-exactly-what-s-inside-13245.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/super-sboms-see-exactly-whats-inside>)

Published: 2026-01-29T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Security](<https://devfeed.tech/topics/security.md>), [spdx](<https://devfeed.tech/topics/spdx.md>)

Tags: [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-sboms](<https://devfeed.tech/tags/chainguard-sboms.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cyclonedx](<https://devfeed.tech/tags/cyclonedx.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [security](<https://devfeed.tech/tags/security.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [spdx](<https://devfeed.tech/tags/spdx.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

Chainguard Containers now provide richer SBOMs with binary-level details about embedded libraries and dependencies, along with CycloneDX support in addition to SPDX. The added visibility helps teams trace vulnerabilities and assess license compliance.

### Source excerpt

Chainguard Containers ship richer SBOMs with binary-level library details plus new CycloneDX support, making CVE impact and compliance tracing fast and clear.

## Evo Adds CycloneDX Support to Give Full AI Visibility

DevFeed: [Evo Adds CycloneDX Support to Give Full AI Visibility](<https://devfeed.tech/articles/evo-adds-cyclonedx-support-to-give-full-ai-visibility-7909.md>)

Original publisher: [Read original article](<https://snyk.io/blog/evo-adds-cyclonedx/>)

Author: John Carione

Published: 2025-12-19T05:00:00Z

Content type: release

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Security](<https://devfeed.tech/topics/security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [cyclonedx](<https://devfeed.tech/tags/cyclonedx.md>), [developer](<https://devfeed.tech/tags/developer.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [governance](<https://devfeed.tech/tags/governance.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>)

### AI overview

Evo's Discovery Agent now supports CycloneDX 1.6 AI ModelCards, enabling portable AI Bills of Materials that inventory models, dependencies, provenance, licensing, and related metadata within existing SBOM workflows. The integration addresses enterprise security, compliance, and visibility gaps across AI supply chains.

### Source excerpt

Enterprises face a critical visibility gap in AI models, creating security and compliance risks. Evo's new integration with CycloneDX 1.6 delivers intelligent, actionable AI-BOMs, providing complete oversight and robust governance for your entire AI supply chain.

## Run AutoMCP To Supercharge Your AI Agent with Libraries MCP Servers

DevFeed: [Run AutoMCP To Supercharge Your AI Agent with Libraries MCP Servers](<https://devfeed.tech/articles/run-automcp-to-supercharge-your-ai-agent-with-libraries-mcp-servers-8070.md>)

Original publisher: [Read original article](<https://snyk.io/blog/run-automcp-libraries-mcp-servers/>)

Author: Liran Tal

Published: 2025-12-03T05:00:00Z

Content type: tutorial

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [MSP MCP](<https://devfeed.tech/topics/msp-mcp.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [cursor](<https://devfeed.tech/topics/cursor.md>), [Node.js](<https://devfeed.tech/topics/node-js.md>)

Tags: [agentic-coding](<https://devfeed.tech/tags/agentic-coding.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-agent](<https://devfeed.tech/tags/ai-agent.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [mcp](<https://devfeed.tech/tags/mcp.md>), [mcp-server](<https://devfeed.tech/tags/mcp-server.md>), [node-js](<https://devfeed.tech/tags/node-js.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [scm](<https://devfeed.tech/tags/scm.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>), [snyk-container](<https://devfeed.tech/tags/snyk-container.md>), [snyk-iac](<https://devfeed.tech/tags/snyk-iac.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [vs-code](<https://devfeed.tech/tags/vs-code.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

A tutorial on using AutoMCP to configure Model Context Protocol servers for AI coding tools, connecting dependency context and Snyk scanning to AI-assisted development.

### Source excerpt

Supercharge your AI agent! Learn how AutoMCP integrates Model Context Protocol (MCP) servers and Snyk Studio for secure, context-aware AI-driven development.

## Expanding Chainguard VMs: Zero-CVE Application & Base Virtual Machine Images for Cloud and On-Prem

DevFeed: [Expanding Chainguard VMs: Zero-CVE Application & Base Virtual Machine Images for Cloud and On-Prem](<https://devfeed.tech/articles/expanding-chainguard-vms-zero-cve-application-base-virtual-machine-images-for-cloud-and-on-prem-13035.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/expanding-chainguard-vms-zero-cve-application-base-virtual-machine-images-for-cloud-and-on-prem>)

Published: 2025-09-03T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard vms](<https://devfeed.tech/topics/chainguard-vms.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [on-prem](<https://devfeed.tech/topics/on-prem.md>), [chainguard os](<https://devfeed.tech/topics/chainguard-os.md>), [Java](<https://devfeed.tech/topics/java.md>), [Jenkins](<https://devfeed.tech/topics/jenkins.md>), [nginx](<https://devfeed.tech/topics/nginx.md>), [Python](<https://devfeed.tech/topics/python.md>)

Tags: [chainguard-vms](<https://devfeed.tech/tags/chainguard-vms.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cloud-virtual-machines](<https://devfeed.tech/tags/cloud-virtual-machines.md>), [cve](<https://devfeed.tech/tags/cve.md>), [java](<https://devfeed.tech/tags/java.md>), [jenkins](<https://devfeed.tech/tags/jenkins.md>), [nginx](<https://devfeed.tech/tags/nginx.md>), [on-prem](<https://devfeed.tech/tags/on-prem.md>), [os](<https://devfeed.tech/tags/os.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [python](<https://devfeed.tech/tags/python.md>), [rebuilds](<https://devfeed.tech/tags/rebuilds.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [security-vm-images](<https://devfeed.tech/tags/security-vm-images.md>), [virtual-machine-images](<https://devfeed.tech/tags/virtual-machine-images.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

Chainguard VMs is expanding with zero-CVE application images for Jenkins, Nginx, and Squid Proxy, plus base images for Chainguard OS, Java, and Python. The virtual machine images support cloud and on-premises deployments and are continuously rebuilt from source with automated updates, CVE remediation, and SBOM-driven provenance attestations.

### Source excerpt

Chainguard VMs is expanding with new Application and Base VM Images -- giving teams a secure, zero-CVE foundation to build and innovate faster.

## Malware-Resistant Python without the Guesswork

DevFeed: [Malware-Resistant Python without the Guesswork](<https://devfeed.tech/articles/malware-resistant-python-without-the-guesswork-13146.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/malware-resistant-python-without-the-guesswork>)

Published: 2025-08-01T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard libraries for python](<https://devfeed.tech/topics/chainguard-libraries-for-python.md>), [chainguard libraries](<https://devfeed.tech/topics/chainguard-libraries.md>), [Security](<https://devfeed.tech/topics/security.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Malware](<https://devfeed.tech/topics/malware.md>)

Tags: [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [chainguard-libraries-for-python](<https://devfeed.tech/tags/chainguard-libraries-for-python.md>), [malicious-packages](<https://devfeed.tech/tags/malicious-packages.md>), [malware](<https://devfeed.tech/tags/malware.md>), [num2words](<https://devfeed.tech/tags/num2words.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [pypi](<https://devfeed.tech/tags/pypi.md>), [python](<https://devfeed.tech/tags/python.md>), [reproducibility](<https://devfeed.tech/tags/reproducibility.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [secure-packages](<https://devfeed.tech/tags/secure-packages.md>), [security](<https://devfeed.tech/tags/security.md>), [signing](<https://devfeed.tech/tags/signing.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>)

### AI overview

The article presents Chainguard Libraries for Python as a way to reduce malware and software supply chain risks in Python package consumption. It describes rebuilding packages from upstream source in an isolated, reproducible SLSA Level 2 environment, and publishing signed SBOMs and provenance information.

### Source excerpt

The recent compromise of the num2words package never made it into Chainguard Libraries for Python. Get the breakdown from the team on our packages you can trust.

## Why Golden Images still matter and how to secure them with Chainguard

DevFeed: [Why Golden Images still matter and how to secure them with Chainguard](<https://devfeed.tech/articles/why-golden-images-still-matter-and-how-to-secure-them-with-chainguard-13330.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/why-golden-images-still-matter-and-how-to-secure-them-with-chainguard>)

Published: 2025-05-22T00:00:00Z

Content type: tutorial

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [DevOps](<https://devfeed.tech/topics/devops.md>), [software bill of materials](<https://devfeed.tech/topics/software-bill-of-materials.md>), [Software](<https://devfeed.tech/topics/software.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [aws](<https://devfeed.tech/tags/aws.md>), [azure](<https://devfeed.tech/tags/azure.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [container-image](<https://devfeed.tech/tags/container-image.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [devops](<https://devfeed.tech/tags/devops.md>), [golden-image](<https://devfeed.tech/tags/golden-image.md>), [golden-images](<https://devfeed.tech/tags/golden-images.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [security](<https://devfeed.tech/tags/security.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

This article explains why well-managed golden image programs remain important for modern software delivery. It describes how continuously rebuilt, patched, signed, scanned, and versioned images--with SBOMs, attestations, provenance, and policy compliance--can improve security and streamline development workflows, while presenting Chainguard as an alternative to homegrown programs.

### Source excerpt

Golden container image programs can be a great way to increase efficiency and security for your engineering team. Learn how to do it right with Chainguard.

## Creating SBOMs with the Snyk CLI

DevFeed: [Creating SBOMs with the Snyk CLI](<https://devfeed.tech/articles/creating-sboms-with-the-snyk-cli-7873.md>)

Original publisher: [Read original article](<https://snyk.io/blog/creating-sboms-snyk-cli/>)

Author: Brian Vermeer

Published: 2025-02-05T06:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Software](<https://devfeed.tech/topics/software.md>), [DevOps](<https://devfeed.tech/topics/devops.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [acquisition](<https://devfeed.tech/tags/acquisition.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [blog](<https://devfeed.tech/tags/blog.md>), [cli](<https://devfeed.tech/tags/cli.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [java](<https://devfeed.tech/tags/java.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This article explains software bills of materials (SBOMs), their importance for open source security and compliance, and how the Snyk CLI can help create them. It describes SBOMs as inventories of software components, dependencies, versions, and licensing information, and explains how they help assess vulnerability exposure.

### Source excerpt

In this post, we'll delve into what SBOMs are, why they're necessary, and their role in open source security.

## Understanding the EU's Cyber Resilience Act (CRA)

DevFeed: [Understanding the EU's Cyber Resilience Act (CRA)](<https://devfeed.tech/articles/understanding-the-eu-s-cyber-resilience-act-cra-8226.md>)

Original publisher: [Read original article](<https://snyk.io/blog/understanding-the-eus-cyber-resilience-act-cra/>)

Author: Ben Desjardins

Published: 2025-01-22T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [cyber resilience act](<https://devfeed.tech/topics/cyber-resilience-act.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [sdlc](<https://devfeed.tech/topics/sdlc.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [snyk](<https://devfeed.tech/topics/snyk.md>)

Tags: [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [cyber-resilience-act](<https://devfeed.tech/tags/cyber-resilience-act.md>), [eu](<https://devfeed.tech/tags/eu.md>), [executive](<https://devfeed.tech/tags/executive.md>), [megawatt](<https://devfeed.tech/tags/megawatt.md>), [sast](<https://devfeed.tech/tags/sast.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [sca](<https://devfeed.tech/tags/sca.md>), [sdlc](<https://devfeed.tech/tags/sdlc.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>)

### AI overview

The article explains how the EU Cyber Resilience Act (CRA) establishes cybersecurity requirements for products with digital elements. It discusses secure-by-design practices, vulnerability handling throughout the product lifecycle, upcoming reporting and compliance deadlines, and the role of SAST, SCA, and software supply chain security.

### Source excerpt

Find out how the Cyber Resilience Act (CRA) sets new security standards for the EU and how Snyk can help simplify compliance with its developer-friendly tools.

## Software Bill of Materials (SBOM) for your Spin Apps

DevFeed: [Software Bill of Materials (SBOM) for your Spin Apps](<https://devfeed.tech/articles/software-bill-of-materials-sbom-for-your-spin-apps-15336.md>)

Original publisher: [Read original article](<https://www.fermyon.com/blog/sbom-for-your-spin-apps>)

Author: Thorsten Hans

Published: 2025-01-16T12:00:00Z

Content type: tutorial

Language: en

Sources: [Fermyon - Experience the next wave of cloud computing.](<https://devfeed.tech/sources/fermyon-experience-the-next-wave-of-cloud-computing.md>)

Topics: [software bill of materials](<https://devfeed.tech/topics/software-bill-of-materials.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [trivy](<https://devfeed.tech/topics/trivy.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Requirements](<https://devfeed.tech/topics/requirements.md>), [Software](<https://devfeed.tech/topics/software.md>)

Tags: [open-source](<https://devfeed.tech/tags/open-source.md>), [regulatory](<https://devfeed.tech/tags/regulatory.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [trivy](<https://devfeed.tech/tags/trivy.md>)

### AI overview

A tutorial on creating Software Bills of Materials for Spin apps, addressing regulatory requirements and software supply chain security with open-source tools such as Trivy.

### Source excerpt

Learn how to create SBOMs for Spin apps, meet regulatory requirements, and secure your software supply chain with open-source tools like Trivy

[Next page](<https://devfeed.tech/tags/sbom.md?cursor=WyIyMDI1LTAxLTE2VDEyOjAwOjAwKzAwOjAwIiwgImU3NGM5ZmY4LWJiOGUtNGZiYi05ZmZjLTFmMGIyNmJhMmViNSJd>)