# scanners

Published articles for scanners.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Human judgment doesn't leave the software factory. It relocates.

DevFeed: [Human judgment doesn't leave the software factory. It relocates.](<https://devfeed.tech/articles/human-judgment-doesn-t-leave-the-software-factory-it-relocates-28497.md>)

Original publisher: [Read original article](<https://addyosmani.com/blog/human-judgment-doesnt-leave-the-software/>)

Author: Addy Osmani

Published: 2026-08-21T00:00:00Z

Content type: article

Language: en

Sources: [Addy Osmani](<https://devfeed.tech/sources/addy-osmani.md>)

Topics: [Software](<https://devfeed.tech/topics/software.md>), [coding](<https://devfeed.tech/topics/coding.md>), [event driven](<https://devfeed.tech/topics/event-driven.md>), [implementation](<https://devfeed.tech/topics/implementation.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [Claude Code](<https://devfeed.tech/topics/claude-code.md>), [codex](<https://devfeed.tech/topics/codex.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [architecture](<https://devfeed.tech/tags/architecture.md>), [automated](<https://devfeed.tech/tags/automated.md>), [batch](<https://devfeed.tech/tags/batch.md>), [build](<https://devfeed.tech/tags/build.md>), [claude-code](<https://devfeed.tech/tags/claude-code.md>), [codex](<https://devfeed.tech/tags/codex.md>), [event-driven](<https://devfeed.tech/tags/event-driven.md>), [github](<https://devfeed.tech/tags/github.md>), [linear](<https://devfeed.tech/tags/linear.md>), [maintainability](<https://devfeed.tech/tags/maintainability.md>), [mutation-testing](<https://devfeed.tech/tags/mutation-testing.md>), [pull-requests](<https://devfeed.tech/tags/pull-requests.md>), [quality](<https://devfeed.tech/tags/quality.md>), [scanners](<https://devfeed.tech/tags/scanners.md>), [slack](<https://devfeed.tech/tags/slack.md>), [software](<https://devfeed.tech/tags/software.md>), [testing](<https://devfeed.tech/tags/testing.md>), [verification](<https://devfeed.tech/tags/verification.md>)

### AI overview

A field guide to building a repeatable software factory while keeping humans responsible for product intent, system design, quality standards, code review, and final merge decisions. It recommends early and continuous quality checks, deliberate constraints, and event-driven automation when ordinary coding workflows are no longer sufficient.

### Source excerpt

A field guide to building a software factory that still has an owner.

## Introducing Our Newest Ecosystem Integration: Anchore Enterprise

DevFeed: [Introducing Our Newest Ecosystem Integration: Anchore Enterprise](<https://devfeed.tech/articles/introducing-our-newest-ecosystem-integration-anchore-enterprise-13119.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/introducing-our-newest-ecosystem-integration-anchore-enterprise>)

Published: 2025-09-23T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [anchore](<https://devfeed.tech/topics/anchore.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Security](<https://devfeed.tech/topics/security.md>), [vulnerability scanning](<https://devfeed.tech/topics/vulnerability-scanning.md>)

Tags: [anchore](<https://devfeed.tech/tags/anchore.md>), [anchore-enterprise](<https://devfeed.tech/tags/anchore-enterprise.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-partners](<https://devfeed.tech/tags/chainguard-partners.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [integration](<https://devfeed.tech/tags/integration.md>), [scanners](<https://devfeed.tech/tags/scanners.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>)

### AI overview

Chainguard announces a new integration with Anchore Enterprise. The integration combines Chainguard's secure-by-default container images with Anchore's SBOM management, vulnerability scanning, and automated compliance policy enforcement to support continuous software security and compliance.

### Source excerpt

Discover more about Chainguard's new integration with Anchore Enterprise.

## The year so far: How Burp Suite DAST is leveling up enterprise security in 2025

DevFeed: [The year so far: How Burp Suite DAST is leveling up enterprise security in 2025](<https://devfeed.tech/articles/the-year-so-far-how-burp-suite-dast-is-leveling-up-enterprise-security-in-2025-7745.md>)

Original publisher: [Read original article](<https://portswigger.net/blog/the-year-so-far-how-burp-suite-dast-is-leveling-up-enterprise-security-in-2025>)

Author: Andrzej Matykiewicz

Published: 2025-08-28T12:07:45Z

Content type: article

Language: en

Sources: [PortSwigger Blog](<https://devfeed.tech/sources/portswigger-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Automation](<https://devfeed.tech/topics/automation.md>), [API](<https://devfeed.tech/topics/api.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [OpenAPI Specification](<https://devfeed.tech/topics/openapi.md>), [Postman](<https://devfeed.tech/topics/postman.md>), [Web](<https://devfeed.tech/topics/web.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [api](<https://devfeed.tech/tags/api.md>), [apis](<https://devfeed.tech/tags/apis.md>), [automation](<https://devfeed.tech/tags/automation.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [openapi](<https://devfeed.tech/tags/openapi.md>), [qa](<https://devfeed.tech/tags/qa.md>), [scale](<https://devfeed.tech/tags/scale.md>), [scanners](<https://devfeed.tech/tags/scanners.md>), [security](<https://devfeed.tech/tags/security.md>), [speed](<https://devfeed.tech/tags/speed.md>), [web](<https://devfeed.tech/tags/web.md>), [workflows](<https://devfeed.tech/tags/workflows.md>)

### AI overview

This article recaps Burp Suite DAST improvements delivered during the first half of 2025 for enterprise security teams. It describes recurring portfolio scans, custom asset tags, continuous authenticated API scanning with automatic token refresh, and scan triggers from Postman Collections alongside OpenAPI and SOAP WSDL imports.

### Source excerpt

Enterprise security teams are under more pressure than ever to secure sprawling application estates, without slowing down delivery. That's why, over the first half of 2025, we've delivered some of our

## Understanding CRA Compliance: Overcoming Challenges with an Integrated Security Testing Approach

DevFeed: [Understanding CRA Compliance: Overcoming Challenges with an Integrated Security Testing Approach](<https://devfeed.tech/articles/understanding-cra-compliance-overcoming-challenges-with-an-integrated-security-testing-approach-8224.md>)

Original publisher: [Read original article](<https://snyk.io/blog/understanding-cra-compliance/>)

Author: Snyk Team

Published: 2025-06-25T23:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Testing](<https://devfeed.tech/topics/testing.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [DevOps](<https://devfeed.tech/topics/devops.md>), [Tooling](<https://devfeed.tech/topics/tooling.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Development](<https://devfeed.tech/topics/development.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [awareness](<https://devfeed.tech/tags/awareness.md>), [best-practices](<https://devfeed.tech/tags/best-practices.md>), [blog](<https://devfeed.tech/tags/blog.md>), [community](<https://devfeed.tech/tags/community.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [cra-requirements](<https://devfeed.tech/tags/cra-requirements.md>), [cyber-resilience-act](<https://devfeed.tech/tags/cyber-resilience-act.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [developer](<https://devfeed.tech/tags/developer.md>), [developers](<https://devfeed.tech/tags/developers.md>), [development](<https://devfeed.tech/tags/development.md>), [devops](<https://devfeed.tech/tags/devops.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [eu](<https://devfeed.tech/tags/eu.md>), [scanners](<https://devfeed.tech/tags/scanners.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>), [snyk-iac](<https://devfeed.tech/tags/snyk-iac.md>), [snyk-learn](<https://devfeed.tech/tags/snyk-learn.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [testing](<https://devfeed.tech/tags/testing.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>), [workflows](<https://devfeed.tech/tags/workflows.md>)

### AI overview

This article explains how the Cyber Resilience Act (CRA) changes software delivery expectations for organizations serving the EU. It highlights continuous security validation across proprietary code, open source libraries, and third-party dependencies, and recommends integrated security testing, secure-by-design practices, aligned teams, modern tooling, and security embedded in daily development workflows.

### Source excerpt

Learn how to meet CRA requirements with integrated security testing, secure-by-design workflows, and scalable practices for modern dev teams.

## Trusted Open Source Means Compatibility: New Integration with Orca Security

DevFeed: [Trusted Open Source Means Compatibility: New Integration with Orca Security](<https://devfeed.tech/articles/trusted-open-source-means-compatibility-new-integration-with-orca-security-13298.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/trusted-open-source-means-compatibility-new-integration-with-orca-security>)

Published: 2025-06-17T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [orca security](<https://devfeed.tech/topics/orca-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Containers](<https://devfeed.tech/topics/containers.md>)

Tags: [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-os](<https://devfeed.tech/tags/chainguard-os.md>), [compatibility](<https://devfeed.tech/tags/compatibility.md>), [false-positives](<https://devfeed.tech/tags/false-positives.md>), [open-source-scanners](<https://devfeed.tech/tags/open-source-scanners.md>), [orca-security](<https://devfeed.tech/tags/orca-security.md>), [partnership](<https://devfeed.tech/tags/partnership.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [scanner](<https://devfeed.tech/tags/scanner.md>), [scanners](<https://devfeed.tech/tags/scanners.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Chainguard announces an integration with Orca Security that adds visibility for Chainguard OS and Chainguard Containers images in the Orca Platform. The integration exposes image metadata, scans images and installed packages for vulnerabilities against Chainguard Security Advisories, and provides additional security context for remediation.

### Source excerpt

Chainguard now has an integration with Orca Security. Discover more about our new partnership.

## Updates on CVE for End-of-Life Versions

DevFeed: [Updates on CVE for End-of-Life Versions](<https://devfeed.tech/articles/updates-on-cve-for-end-of-life-versions-2914.md>)

Original publisher: [Read original article](<https://nodejs.org/en/blog/vulnerability/updates-cve-for-end-of-life>)

Published: 2025-03-07T16:00:00Z

Content type: news

Language: en

Sources: [Node.js Blog](<https://devfeed.tech/sources/node-js-blog.md>)

Topics: [Node.js](<https://devfeed.tech/topics/node-js.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [releases](<https://devfeed.tech/topics/releases.md>)

Tags: [cve](<https://devfeed.tech/tags/cve.md>), [end-of-life](<https://devfeed.tech/tags/end-of-life.md>), [node-js](<https://devfeed.tech/tags/node-js.md>), [scanners](<https://devfeed.tech/tags/scanners.md>), [security](<https://devfeed.tech/tags/security.md>), [updates](<https://devfeed.tech/tags/updates.md>), [upgrade](<https://devfeed.tech/tags/upgrade.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The Node.js team updated its CVE policy for end-of-life releases after CVE-2025-23087, CVE-2025-23088, and CVE-2025-23089 were rejected by the CVE Program. New CVEs will include EOL releases unless specific information shows that a vulnerability does not apply. Node.js does not routinely assess EOL versions because of limited resources and their differing dependencies, build processes, and platform support.

### Source excerpt

Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.

## Shifting Cyber Norms: Microsoft security POST-ing to you

DevFeed: [Shifting Cyber Norms: Microsoft security POST-ing to you](<https://devfeed.tech/articles/shifting-cyber-norms-microsoft-security-post-ing-to-you-36538.md>)

Original publisher: [Read original article](<https://berthub.eu/articles/posts/shifting-cyber-norms-microsoft-post/>)

Published: 2025-01-23T11:42:25Z

Content type: opinion

Language: en

Sources: [Bert Hubert's writings](<https://devfeed.tech/sources/bert-hubert-s-writings.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [email](<https://devfeed.tech/topics/email.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [Single-page application (SPA)](<https://devfeed.tech/topics/spa.md>)

Tags: [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [email](<https://devfeed.tech/tags/email.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [programming](<https://devfeed.tech/tags/programming.md>), [scanners](<https://devfeed.tech/tags/scanners.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

The article argues that Microsoft and other email security scanners now visit links in transmitted email and execute their JavaScript, including requests that trigger POST actions. It reports that this behavior can invalidate single-use passwordless sign-on and email-confirmation links, and discusses changing norms around email inspection and software behavior.

### Source excerpt

tl;dr: Microsoft and other email security scanners will visit the links in email you transmit, and run the JavaScript in those links, including calls that lead to POSTs going out. This used to be unacceptable, since POSTs have side effects. Yet here we are. This breaks even somewhat sophisticated single-use sign-on / email confirmation messages. Read on for how to deal with this, and some thoughts on how we should treat gatekeepers like Microsoft that can randomly break things & get away with it.

## Panic! At The Distro: A Study of Malware Prevention in Linux Distributions

DevFeed: [Panic! At The Distro: A Study of Malware Prevention in Linux Distributions](<https://devfeed.tech/articles/panic-at-the-distro-a-study-of-malware-prevention-in-linux-distributions-13202.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/panic-at-the-distro-a-study-of-malware-prevention-in-linux-distributions>)

Published: 2024-12-17T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Linux](<https://devfeed.tech/topics/linux.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Maintainers](<https://devfeed.tech/topics/maintainers.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Benchmark](<https://devfeed.tech/topics/benchmark.md>), [dataset](<https://devfeed.tech/topics/dataset.md>)

Tags: [alpine](<https://devfeed.tech/tags/alpine.md>), [benchmark](<https://devfeed.tech/tags/benchmark.md>), [dataset](<https://devfeed.tech/tags/dataset.md>), [debian](<https://devfeed.tech/tags/debian.md>), [distribution](<https://devfeed.tech/tags/distribution.md>), [false-positives](<https://devfeed.tech/tags/false-positives.md>), [linux](<https://devfeed.tech/tags/linux.md>), [maintainers](<https://devfeed.tech/tags/maintainers.md>), [malware](<https://devfeed.tech/tags/malware.md>), [malware-prevention](<https://devfeed.tech/tags/malware-prevention.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [reproducible-builds](<https://devfeed.tech/tags/reproducible-builds.md>), [research](<https://devfeed.tech/tags/research.md>), [scanners](<https://devfeed.tech/tags/scanners.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Chainguard studies malware prevention in Linux distributions through maintainer interviews and a Linux package malware benchmark dataset. The study reports that most interviewed distributions do not proactively scan repositories, while existing open-source malware scanners often produce false positives.

### Source excerpt

Chainguard wanted to know more about malware prevention in Linux distributions. So we did a study to see what maintainers are doing about it. See the results.

## Get Smart in 5 Minutes: Vulnerability remediation unveiled

DevFeed: [Get Smart in 5 Minutes: Vulnerability remediation unveiled](<https://devfeed.tech/articles/get-smart-in-5-minutes-vulnerability-remediation-unveiled-13060.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/get-smart-in-5-minutes-vulnerability-remediation-unveiled>)

Published: 2024-08-16T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [software bill of materials](<https://devfeed.tech/topics/software-bill-of-materials.md>), [Security](<https://devfeed.tech/topics/security.md>), [Software](<https://devfeed.tech/topics/software.md>)

Tags: [developer](<https://devfeed.tech/tags/developer.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [scanners](<https://devfeed.tech/tags/scanners.md>), [security](<https://devfeed.tech/tags/security.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This introductory article explains vulnerability remediation as the process of fixing flaws identified by software scanners. It describes common obstacles, including triage, uncertainty about the affected code, and unclear ownership. It presents software bills of materials (SBOMs) as a way to identify software components, while noting that outdated or inaccurate SBOMs may miss vulnerabilities or malware. The article emphasizes that software vulnerabilities can affect everyone through data breaches, service disruptions, and physical harm.

### Source excerpt

Learn the basics of vulnerability remediation from this teaser of Chainguard's Get Smart in Five Minutes series on Youtube.

## Improving Laravel Application Security with Aikido

DevFeed: [Improving Laravel Application Security with Aikido](<https://devfeed.tech/articles/improving-laravel-application-security-with-aikido-3720.md>)

Original publisher: [Read original article](<https://laravel.com/blog/improving-laravel-application-security-with-aikido>)

Author: James Brooks

Published: 2024-07-08T14:30:00Z

Content type: news

Language: en

Sources: [Laravel Blog](<https://devfeed.tech/sources/laravel-blog.md>)

Topics: [Laravel](<https://devfeed.tech/topics/laravel.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [PHP](<https://devfeed.tech/topics/php.md>), [cloud security](<https://devfeed.tech/topics/cloud-security.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [cloud-security](<https://devfeed.tech/tags/cloud-security.md>), [hipaa](<https://devfeed.tech/tags/hipaa.md>), [integration](<https://devfeed.tech/tags/integration.md>), [iso-27001](<https://devfeed.tech/tags/iso-27001.md>), [laravel](<https://devfeed.tech/tags/laravel.md>), [php](<https://devfeed.tech/tags/php.md>), [scanners](<https://devfeed.tech/tags/scanners.md>), [security](<https://devfeed.tech/tags/security.md>), [security-vulnerabilities](<https://devfeed.tech/tags/security-vulnerabilities.md>), [soc2](<https://devfeed.tech/tags/soc2.md>)

### AI overview

Laravel has partnered with Aikido to add security scanning for Laravel applications using Forge. The integration identifies potential vulnerabilities and security flags, surfaces findings within Forge, and combines code and cloud security scanners to help developers manage application security and compliance requirements.

### Source excerpt

As your Laravel application grows, managing security objectives becomes more challenging, especially for small teams or solo developers. Today, Laravel has teamed up with Aikido to provide a seamless solution for securing your Laravel application. With Aikido, Laravel developers using Forge can effortlessly scan for and identify potential security vulnerabilities, all in less than 1 minute.

## Hardened Container Images: Images for a Secure Supply Chain

DevFeed: [Hardened Container Images: Images for a Secure Supply Chain](<https://devfeed.tech/articles/hardened-container-images-images-for-a-secure-supply-chain-13079.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/hardened-container-images-images-for-a-secure-supply-chain>)

Published: 2024-04-30T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [grype](<https://devfeed.tech/topics/grype.md>), [snyk](<https://devfeed.tech/topics/snyk.md>)

Tags: [canonical](<https://devfeed.tech/tags/canonical.md>), [canonical-chiselled-image](<https://devfeed.tech/tags/canonical-chiselled-image.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container](<https://devfeed.tech/tags/container.md>), [container-image](<https://devfeed.tech/tags/container-image.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cve](<https://devfeed.tech/tags/cve.md>), [debian](<https://devfeed.tech/tags/debian.md>), [dockerhub](<https://devfeed.tech/tags/dockerhub.md>), [false-positives](<https://devfeed.tech/tags/false-positives.md>), [grype](<https://devfeed.tech/tags/grype.md>), [hardened-container-image](<https://devfeed.tech/tags/hardened-container-image.md>), [iron-bank](<https://devfeed.tech/tags/iron-bank.md>), [redhat](<https://devfeed.tech/tags/redhat.md>), [scanners](<https://devfeed.tech/tags/scanners.md>), [security](<https://devfeed.tech/tags/security.md>), [shift-left](<https://devfeed.tech/tags/shift-left.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Chainguard introduces its inaugural State of Hardened Container Images report, examining the security of hardened container images from providers including Red Hat, Iron Bank, and Chainguard. The article argues that hardened container images deserve distinct consideration from container vulnerability scanning and describes the report as addressing secure software supply chains.

### Source excerpt

Check out our analysis of the hardened container image landscape, including offerings from Red Hat, Iron Bank, and others.

## Improving product reliability by imposing constraints as a part of CI/CD process

DevFeed: [Improving product reliability by imposing constraints as a part of CI/CD process](<https://devfeed.tech/articles/improving-product-reliability-by-imposing-constraints-as-a-part-of-ci-cd-process-26344.md>)

Original publisher: [Read original article](<https://medium.com/revolut/improving-product-reliability-by-imposing-constraints-as-a-part-of-ci-cd-process-597cf2307224?source=rss----44c5ac415e14---4>)

Author: Pedro Moura

Published: 2023-11-03T14:26:59Z

Content type: article

Language: en

Sources: [Revolut Engineering](<https://devfeed.tech/sources/revolut-engineering.md>)

Topics: [CI/CD](<https://devfeed.tech/topics/cicd.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Data analysis](<https://devfeed.tech/topics/data-analysis.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [blocking](<https://devfeed.tech/tags/blocking.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [data-analysis](<https://devfeed.tech/tags/data-analysis.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [sast](<https://devfeed.tech/tags/sast.md>), [sca](<https://devfeed.tech/tags/sca.md>), [scanners](<https://devfeed.tech/tags/scanners.md>), [security](<https://devfeed.tech/tags/security.md>), [security-vulnerabilities](<https://devfeed.tech/tags/security-vulnerabilities.md>), [software-development](<https://devfeed.tech/tags/software-development.md>)

### AI overview

Revolut describes a CI/CD approach that uses automated risk calculation, data analysis, security scanning, and deployment constraints to improve product reliability. The approach aims to identify vulnerabilities and bugs early, mitigate them, and potentially block high-risk applications from reaching production.

### Source excerpt

At Revolut, we always aim to consistently provide efficient, high-quality, and secure services. Our primary goals are to enhance product quality, increase customer satisfaction, and reduce business risk. To achieve those goals, we should aim to be as proactive -- rather than reactive -- as possible. This means fixing any point of failure before it reaches production by identifying, reporting, and potentially blocking deployments that can impact the reliability of our products. In this article, we'll explain how we achieve those goals using automated risk calculation, data analysis, and imposing constraints to push for the mitigation of open vulnerabilities and the fix of reported bugs identified in our products. Challenges faced by Revolut Each application/service has its own specifications, with different technology stacks and architectures, bringing a diversity of security challenges and different vulnerabilities. That being said, application risk cannot be based only on the reported security vulnerabilities but also in the context of that specific application. Continuous scanning, reporting, visibility, and risk evaluation are essential to providing the best security advice and automated security controls. Nowadays there are several types of security scanners (SAST, SCA, DAST, IaC, etc.) that help security professionals to identify and report vulnerabilities, where each of them can belong to a different third-party provider. For further information on these, read our article on continuous security. Data scraped from different sources creates friction when it's needed to group findings and provide mitigations. This can also decrease mean time to identify vulnerabilities and mean time to provide mitigations. Also, to avoid such negative workflow impact, security must be shifted left. Without a centralised source of truth for security-related application data, most of the time is wasted on searching for information/findings in segmented platforms and finding the corre

## A growing ecosystem of vulnerability scanners that now support Chainguard Images and Wolfi

DevFeed: [A growing ecosystem of vulnerability scanners that now support Chainguard Images and Wolfi](<https://devfeed.tech/articles/a-growing-ecosystem-of-vulnerability-scanners-that-now-support-chainguard-images-and-wolfi-12857.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/a-growing-ecosystem-of-vulnerability-scanners-that-now-support-chainguard-images-and-wolfi>)

Published: 2023-09-21T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Security](<https://devfeed.tech/topics/security.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [trivy](<https://devfeed.tech/topics/trivy.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container](<https://devfeed.tech/tags/container.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve](<https://devfeed.tech/tags/cve.md>), [false-positives](<https://devfeed.tech/tags/false-positives.md>), [grype](<https://devfeed.tech/tags/grype.md>), [prisma-cloud](<https://devfeed.tech/tags/prisma-cloud.md>), [sca](<https://devfeed.tech/tags/sca.md>), [scanners](<https://devfeed.tech/tags/scanners.md>), [secure-images](<https://devfeed.tech/tags/secure-images.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [trivy](<https://devfeed.tech/tags/trivy.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [wiz](<https://devfeed.tech/tags/wiz.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Chainguard Images and the Wolfi distribution are now supported by a growing ecosystem of open-source and enterprise vulnerability scanners, including Docker Scout, Grype, Snyk, Trivy, and Wiz. The broader integration helps users monitor and prioritize scan results, verify vulnerabilities, reduce scanner noise and false positives, and build more secure software.

### Source excerpt

Secure your software with Chainguard & Wolfi, now recognized by leading vulnerability scanners.

## Announcing a Chainguard Image for OpenTF

DevFeed: [Announcing a Chainguard Image for OpenTF](<https://devfeed.tech/articles/announcing-a-chainguard-image-for-opentf-12873.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/announcing-a-chainguard-image-for-opentf>)

Published: 2023-09-06T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [foss](<https://devfeed.tech/topics/foss.md>), [Terraform](<https://devfeed.tech/topics/terraform.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container](<https://devfeed.tech/tags/container.md>), [foss](<https://devfeed.tech/tags/foss.md>), [linux](<https://devfeed.tech/tags/linux.md>), [oci-registry](<https://devfeed.tech/tags/oci-registry.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [opentf](<https://devfeed.tech/tags/opentf.md>), [scanners](<https://devfeed.tech/tags/scanners.md>), [security](<https://devfeed.tech/tags/security.md>), [state](<https://devfeed.tech/tags/state.md>), [terraform](<https://devfeed.tech/tags/terraform.md>)

### AI overview

Chainguard announces a Chainguard Image for OpenTF, the open-source fork of Terraform created after HashiCorp's license changes. The image is available through Wolfi and Chainguard Images for Linux amd64 and arm64, with a 65 MB size and zero known CVEs according to supported scanners. The article also discusses planned state encryption and OCI registry support, plus future testing and Terraform plugin availability for OpenTF.

### Source excerpt

Discover how Chainguard for OpenTF bridges the open-source community, ensuring secure and efficient container ecosystem transitions.

## Fuzzy CVEs, tarfiles, and untrusted input

DevFeed: [Fuzzy CVEs, tarfiles, and untrusted input](<https://devfeed.tech/articles/fuzzy-cves-tarfiles-and-untrusted-input-13056.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/fuzzy-cves-tarfiles-and-untrusted-input>)

Published: 2023-07-27T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [common vulnerabilities and exposures](<https://devfeed.tech/topics/common-vulnerabilities-and-exposures.md>), [Python](<https://devfeed.tech/topics/python.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Maintainers](<https://devfeed.tech/topics/maintainers.md>), [NVD](<https://devfeed.tech/topics/nvd.md>)

Tags: [common-vulnerabilities-and-exposures](<https://devfeed.tech/tags/common-vulnerabilities-and-exposures.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cves](<https://devfeed.tech/tags/cves.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [go](<https://devfeed.tech/tags/go.md>), [maintainers](<https://devfeed.tech/tags/maintainers.md>), [nvd](<https://devfeed.tech/tags/nvd.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [python](<https://devfeed.tech/tags/python.md>), [scanner](<https://devfeed.tech/tags/scanner.md>), [scanners](<https://devfeed.tech/tags/scanners.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [vulnerability-scanner](<https://devfeed.tech/tags/vulnerability-scanner.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

This article examines CVE-2007-4559 in Python's tarfile module, why the 15-year-old issue may still appear in security scanners, and why its classification as a vulnerability is disputed. It discusses CVE processes, NVD entries, open-source maintainer constraints, and the risks of extracting untrusted tarfile inputs.

### Source excerpt

Navigate fuzzy CVEs, tarfiles, and untrusted input with Chainguard, paving the way to secure coding practices.

## How Chainguard fixes vulnerabilities before they're detected

DevFeed: [How Chainguard fixes vulnerabilities before they're detected](<https://devfeed.tech/articles/how-chainguard-fixes-vulnerabilities-before-they-re-detected-13083.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/how-chainguard-fixes-vulnerabilities-before-theyre-detected>)

Published: 2023-07-14T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Go](<https://devfeed.tech/topics/go.md>), [Security](<https://devfeed.tech/topics/security.md>), [Software](<https://devfeed.tech/topics/software.md>), [Pull Request](<https://devfeed.tech/topics/pull-request.md>), [HTTP](<https://devfeed.tech/topics/http.md>), [releases](<https://devfeed.tech/topics/releases.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>), [OAI-PMH](<https://devfeed.tech/topics/oai-pmh.md>)

Tags: [automated](<https://devfeed.tech/tags/automated.md>), [base-images](<https://devfeed.tech/tags/base-images.md>), [build](<https://devfeed.tech/tags/build.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [cve](<https://devfeed.tech/tags/cve.md>), [go](<https://devfeed.tech/tags/go.md>), [http](<https://devfeed.tech/tags/http.md>), [image-cves](<https://devfeed.tech/tags/image-cves.md>), [library](<https://devfeed.tech/tags/library.md>), [net](<https://devfeed.tech/tags/net.md>), [repo](<https://devfeed.tech/tags/repo.md>), [scanner](<https://devfeed.tech/tags/scanner.md>), [scanners](<https://devfeed.tech/tags/scanners.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Chainguard describes how Wolfi rapidly remediated CVE-2023-29406 in Go by automating upstream release monitoring, package rebuilding, testing, review, and release. The article explains that the fix reached Wolfi-packaged Go applications before vulnerability scanners had the information needed to detect it, and that the updated Go image and dependent packages were rebuilt to include the fix.

### Source excerpt

Uncover Chainguard's strategic vulnerability remediation, enhancing your software's security posture.

## Chainguard to accelerate VEX adoption through OpenVEX specification

DevFeed: [Chainguard to accelerate VEX adoption through OpenVEX specification](<https://devfeed.tech/articles/chainguard-to-accelerate-vex-adoption-through-openvex-specification-12985.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-to-accelerate-vex-adoption-through-openvex-specification>)

Published: 2023-01-31T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [openvex](<https://devfeed.tech/topics/openvex.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [anchore](<https://devfeed.tech/topics/anchore.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [anchore](<https://devfeed.tech/tags/anchore.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [cyclonedx](<https://devfeed.tech/tags/cyclonedx.md>), [false-positives](<https://devfeed.tech/tags/false-positives.md>), [google](<https://devfeed.tech/tags/google.md>), [images](<https://devfeed.tech/tags/images.md>), [linux-foundation](<https://devfeed.tech/tags/linux-foundation.md>), [openvex](<https://devfeed.tech/tags/openvex.md>), [sbom-vex](<https://devfeed.tech/tags/sbom-vex.md>), [scanners](<https://devfeed.tech/tags/scanners.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [spdx](<https://devfeed.tech/tags/spdx.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [vex](<https://devfeed.tech/tags/vex.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-tool](<https://devfeed.tech/tags/vulnerability-tool.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Chainguard announces the OpenVEX specification and reference toolchain, developed with industry and CISA VEX Working Group collaboration. OpenVEX helps software producers describe vulnerability exploitability and enables consumers to filter false positives, complementing SBOMs.

### Source excerpt

VEX needs the industry to come together to build formats that integrate into existing practices. OpenVEX enables organizations to put VEX into practice.

## SSL scanners

DevFeed: [SSL scanners](<https://devfeed.tech/articles/ssl-scanners-38914.md>)

Original publisher: [Read original article](<https://idea.popcount.org/2012-11-12-ssl-scanners>)

Author: Marek

Published: 2012-11-11T23:00:00Z

Content type: opinion

Language: en

Sources: [Marek Majkowski](<https://devfeed.tech/sources/marek-majkowski.md>)

Topics: [SSL](<https://devfeed.tech/topics/ssl.md>), [TLS (Transport Layer Security)](<https://devfeed.tech/topics/tls.md>), [client](<https://devfeed.tech/topics/client.md>), [browser](<https://devfeed.tech/topics/browser.md>)

Tags: [browser](<https://devfeed.tech/tags/browser.md>), [client](<https://devfeed.tech/tags/client.md>), [scanners](<https://devfeed.tech/tags/scanners.md>), [ssl](<https://devfeed.tech/tags/ssl.md>), [tls](<https://devfeed.tech/tags/tls.md>), [traffic](<https://devfeed.tech/tags/traffic.md>)

### AI overview

The author analyzes unusual SSL client requests observed while recording traffic on port 443 to build a database of SSL fingerprints. The article compares scans associated with SSL Labs, Netco Solutions, Johns Hopkins University, Amazon, and Opera, and discusses possible purposes and suspicious protocol probes.

### Source excerpt

SSL scanners In June I started playing with fingerprinting SSL client requests. For example, an SSL fingerprint of my browser is: Read the docs of fingerprint format, or even more detailed description. I wanted to prepare a database of popular fingerprints, so I started recording traffic on port 443. I quickly noticed that apart from normal traffic there are some hosts sending weird SSL requests that make no practical sense and look like scanning.