# Secure by design

Published articles for Secure by design.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Why the CVE doom cycle cannot be solved by working harder

DevFeed: [Why the CVE doom cycle cannot be solved by working harder](<https://devfeed.tech/articles/why-the-cve-doom-cycle-cannot-be-solved-by-working-harder-12284.md>)

Original publisher: [Read original article](<https://platformengineering.org/blog/why-the-cve-doom-cycle-can-not-be-solved-by-working-harder>)

Author: Sam Barlien

Published: 2026-07-23T05:40:01Z

Content type: article

Language: en

Sources: [Platform Engineering Blog](<https://devfeed.tech/sources/platform-engineering-blog.md>)

Topics: [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [Automation](<https://devfeed.tech/topics/automation.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [configuration](<https://devfeed.tech/topics/configuration.md>)

Tags: [automation](<https://devfeed.tech/tags/automation.md>), [container-image-security](<https://devfeed.tech/tags/container-image-security.md>), [cve](<https://devfeed.tech/tags/cve.md>), [false-positives](<https://devfeed.tech/tags/false-positives.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

The article argues that the recurring cycle of scanning, triaging, patching, and redeploying container images cannot be solved by working harder or using faster scanners. Because vulnerability findings and CVEs accumulate faster than manual remediation can handle, it recommends embedding vulnerability management into the platform through secure-by-design practices, golden paths, and automation.

### Source excerpt

Manual CVE triage doesn't scale. Break the CVE doom cycle by shifting vulnerability management into the platform with golden paths and automation

## How Teleport Operationalizes the EU Cyber Resilience Act's Secure-by-Design Mandate

DevFeed: [How Teleport Operationalizes the EU Cyber Resilience Act's Secure-by-Design Mandate](<https://devfeed.tech/articles/how-teleport-operationalizes-the-eu-cyber-resilience-act-s-secure-by-design-mandate-29639.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/eu-cra-secure-by-design/>)

Author: info@goteleport.com (Maximilian Heck, Waldemar Kindler)

Published: 2026-07-16T00:00:00Z

Content type: article

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [cyber resilience act](<https://devfeed.tech/topics/cyber-resilience-act.md>), [Security](<https://devfeed.tech/topics/security.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [audit trail](<https://devfeed.tech/topics/audit-trail.md>), [Monitoring & Alerting](<https://devfeed.tech/topics/monitoring-alerting.md>)

Tags: [audit-trail](<https://devfeed.tech/tags/audit-trail.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [cra-requirements](<https://devfeed.tech/tags/cra-requirements.md>), [cryptographic](<https://devfeed.tech/tags/cryptographic.md>), [cyber-resilience-act](<https://devfeed.tech/tags/cyber-resilience-act.md>), [eu](<https://devfeed.tech/tags/eu.md>), [monitoring-alerting](<https://devfeed.tech/tags/monitoring-alerting.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

The article explains how Teleport maps its infrastructure identity, access, policy, logging, monitoring, and audit controls to ENISA's Secure by Design and Default Playbook and the EU Cyber Resilience Act. It highlights cryptographic identity, least privilege, secure communication, supply-chain controls, and default protection of device identities and secrets.

### Source excerpt

See how Teleport features map to ENISA's Secure-by-Design specification for CRA.

## Chainguard + Second Front: A faster, more secure path into government markets

DevFeed: [Chainguard + Second Front: A faster, more secure path into government markets](<https://devfeed.tech/articles/chainguard-second-front-a-faster-more-secure-path-into-government-markets-12980.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-second-front-a-faster-more-secure-path-into-government-markets>)

Published: 2026-02-20T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [DevSecOps](<https://devfeed.tech/topics/devsecops.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Deployment](<https://devfeed.tech/topics/deployment.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-for-compliance](<https://devfeed.tech/tags/chainguard-for-compliance.md>), [cmmc](<https://devfeed.tech/tags/cmmc.md>), [container-image-compliance](<https://devfeed.tech/tags/container-image-compliance.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve-remediation](<https://devfeed.tech/tags/cve-remediation.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [federal-compliance](<https://devfeed.tech/tags/federal-compliance.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [government](<https://devfeed.tech/tags/government.md>), [iso](<https://devfeed.tech/tags/iso.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [second-front-systems](<https://devfeed.tech/tags/second-front-systems.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [security](<https://devfeed.tech/tags/security.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>)

### AI overview

Chainguard and Second Front are partnering to help software companies pursue federal market requirements, including FedRAMP authorization and DoD impact-level accreditations. The article describes combining Chainguard's hardened container images with Second Front's Game Warden DevSecOps platform to support secure application delivery and vulnerability reduction.

### Source excerpt

Discover how Chainguard and Second Front are partnering to help build a secure path into government markets for your organization.

## Android Quick Share Support for AirDrop: A Secure Approach to Cross-Platform File Sharing

DevFeed: [Android Quick Share Support for AirDrop: A Secure Approach to Cross-Platform File Sharing](<https://devfeed.tech/articles/android-quick-share-support-for-airdrop-a-secure-approach-to-cross-platform-file-sharing-19805.md>)

Original publisher: [Read original article](<http://security.googleblog.com/2025/11/android-quick-share-support-for-airdrop-security.html>)

Author: Edward Fernandez (noreply@blogger.com)

Published: 2025-11-20T17:00:00Z

Content type: release

Language: en

Sources: [Google Online Security](<https://devfeed.tech/sources/google-online-security.md>)

Topics: [Android](<https://devfeed.tech/topics/android.md>), [cross-platform](<https://devfeed.tech/topics/cross-platform.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>), [interoperability](<https://devfeed.tech/topics/interoperability.md>), [iOS](<https://devfeed.tech/topics/ios.md>), [Google](<https://devfeed.tech/topics/google.md>), [Rust](<https://devfeed.tech/topics/rust.md>)

Tags: [android](<https://devfeed.tech/tags/android.md>), [android-security](<https://devfeed.tech/tags/android-security.md>), [cross-platform](<https://devfeed.tech/tags/cross-platform.md>), [google](<https://devfeed.tech/tags/google.md>), [interoperability](<https://devfeed.tech/tags/interoperability.md>), [ios](<https://devfeed.tech/tags/ios.md>), [none](<https://devfeed.tech/tags/none.md>), [rust](<https://devfeed.tech/tags/rust.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [security-privacy](<https://devfeed.tech/tags/security-privacy.md>)

### AI overview

Google describes Quick Share interoperability with AirDrop, enabling two-way file sharing between Android and iOS devices starting with the Pixel 10 Family. The article explains the security measures used in the feature, including threat modeling, privacy reviews, penetration testing, and a Rust-based communication channel.

### Source excerpt

Posted by Dave Kleidermacher, VP, Platforms Security & Privacy, Google Technology should bring people closer together, not create walls. Being able to communicate and connect with friends and family should be easy regardless of the phone they use. That's why Android has been building experiences that help you stay connected across platforms. As part of our efforts to continue to make cross-platform communication more seamless for users, we've made Quick Share interoperable with AirDrop, allowing for two-way file sharing between Android and iOS devices, starting with the Pixel 10 Family. This new feature makes it possible to quickly share your photos, videos, and files with people you choose to communicate with, without worrying about the kind of phone they use. Most importantly, when you share personal files and content, you need to trust that it stays secure. You can share across devices with confidence knowing we built this feature with security at its core, protecting your data with strong safeguards that have been tested by independent security experts. Secure by Design We built Quick Share's interoperability support for AirDrop with the same rigorous security standards that we apply to all Google products. Our approach to security is proactive and deeply integrated into every stage of the development process. This includes: Threat Modeling: We identify and address potential security risks before they can become a problem. Internal Security Design and Privacy Reviews: Our dedicated security and privacy teams thoroughly review the design to ensure it meets our high standards. Internal Penetration Testing: We conduct extensive in-house testing to identify and fix vulnerabilities. This Secure by Design philosophy ensures that all of our products are not just functional but also fundamentally secure. This feature is also protected by a multi-layered security approach to ensure a safe sharing experience from end-to-end, regardless of what platform you're on. Secure S

## Introducing New Updates to the Chainguard Images Directory

DevFeed: [Introducing New Updates to the Chainguard Images Directory](<https://devfeed.tech/articles/introducing-new-updates-to-the-chainguard-images-directory-13118.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/introducing-new-updates-to-the-chainguard-images-directory>)

Published: 2025-11-12T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Deployment](<https://devfeed.tech/topics/deployment.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [bitnami-helm-charts](<https://devfeed.tech/tags/bitnami-helm-charts.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-catalog](<https://devfeed.tech/tags/chainguard-catalog.md>), [chainguard-console](<https://devfeed.tech/tags/chainguard-console.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-helm-charts](<https://devfeed.tech/tags/chainguard-helm-charts.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [chainguard-images-directory](<https://devfeed.tech/tags/chainguard-images-directory.md>), [compare](<https://devfeed.tech/tags/compare.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cost](<https://devfeed.tech/tags/cost.md>), [cve](<https://devfeed.tech/tags/cve.md>), [demo](<https://devfeed.tech/tags/demo.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [helm](<https://devfeed.tech/tags/helm.md>), [helm-charts](<https://devfeed.tech/tags/helm-charts.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [oci](<https://devfeed.tech/tags/oci.md>), [registry](<https://devfeed.tech/tags/registry.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [updates](<https://devfeed.tech/tags/updates.md>), [zero-cve-containers](<https://devfeed.tech/tags/zero-cve-containers.md>)

### AI overview

Chainguard has updated its Images Directory with an embedded ROI calculator, Helm Charts for Kubernetes deployments, and refreshed data about the Chainguard Factory. The calculator compares CVE counts and remediation costs, while the Helm Charts provide drop-in replacements for popular open source applications using Chainguard Containers and OCI delivery.

### Source excerpt

We've improved the Chainguard Images Directory with Helm charts for faster deployments, an ROI calculator, and more refreshed data to improve your experience.

## Secure by Design: The Future of Threat Modeling for AI-Native Applications

DevFeed: [Secure by Design: The Future of Threat Modeling for AI-Native Applications](<https://devfeed.tech/articles/secure-by-design-the-future-of-threat-modeling-for-ai-native-applications-7936.md>)

Original publisher: [Read original article](<https://snyk.io/blog/future-threat-modeling-ai-native-apps/>)

Author: John Carione

Published: 2025-11-11T05:00:00Z

Content type: opinion

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Security for AI](<https://devfeed.tech/topics/security-for-ai.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [snyk](<https://devfeed.tech/topics/snyk.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [prompt injection](<https://devfeed.tech/topics/prompt-injection.md>)

Tags: [agentic](<https://devfeed.tech/tags/agentic.md>), [ai](<https://devfeed.tech/tags/ai.md>), [prompt-injection](<https://devfeed.tech/tags/prompt-injection.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [security](<https://devfeed.tech/tags/security.md>), [security-for-ai](<https://devfeed.tech/tags/security-for-ai.md>), [snyk](<https://devfeed.tech/tags/snyk.md>)

### AI overview

This Snyk article argues that traditional, manual threat modeling cannot keep pace with AI-native applications built from large language models, autonomous agents, APIs, and changing data flows. It presents continuous, automated, AI-assisted threat modeling as a way to maintain secure-by-design systems and address risks such as prompt injection, data exfiltration, data poisoning, and agentic vulnerabilities.

### Source excerpt

Explore how Snyk's Evo Threat Modeling Agent automates and contextualizes security for AI-native applications, addressing prompt injection, data exfiltration, data poisoning, and agentic vulnerabilities.

## Meeting the AI Mandates with Confidence: Why Federal Teams Trust Snyk

DevFeed: [Meeting the AI Mandates with Confidence: Why Federal Teams Trust Snyk](<https://devfeed.tech/articles/meeting-the-ai-mandates-with-confidence-why-federal-teams-trust-snyk-8251.md>)

Original publisher: [Read original article](<https://snyk.io/blog/why-federal-teams-trust-snyk/>)

Author: Phoebe Nerdahl

Published: 2025-08-07T04:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [snyk](<https://devfeed.tech/topics/snyk.md>), [ai security](<https://devfeed.tech/topics/ai-security.md>), [AI Strategy](<https://devfeed.tech/topics/ai-strategy.md>), [AI Development](<https://devfeed.tech/topics/ai-development.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [AI Platform](<https://devfeed.tech/topics/ai-platform.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [Terraform](<https://devfeed.tech/topics/terraform.md>)

Tags: [agentic-ai-security](<https://devfeed.tech/tags/agentic-ai-security.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-adoption](<https://devfeed.tech/tags/ai-adoption.md>), [ai-infrastructure](<https://devfeed.tech/tags/ai-infrastructure.md>), [ai-security](<https://devfeed.tech/tags/ai-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [devops](<https://devfeed.tech/tags/devops.md>), [executive](<https://devfeed.tech/tags/executive.md>), [github](<https://devfeed.tech/tags/github.md>), [government](<https://devfeed.tech/tags/government.md>), [nist](<https://devfeed.tech/tags/nist.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [security](<https://devfeed.tech/tags/security.md>), [self-hosted](<https://devfeed.tech/tags/self-hosted.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [terraform](<https://devfeed.tech/tags/terraform.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This article explains how Snyk for Government helps federal agencies adopt AI securely through secure-by-design development, continuous vulnerability management, compliance support, automation, and governance. It highlights integrations across developer workflows, FedRAMP authorization, standards-aligned practices, and the Snyk AI Trust Platform.

### Source excerpt

Learn how Snyk for Government helps federal agencies meet AI mandates with confidence. Snyk's AI Trust Platform ensures secure-by-design development, compliance, and transparent AI systems.

## From Ideas to Impact: How the Bay Area Is Shaping the Future of Secure AI

DevFeed: [From Ideas to Impact: How the Bay Area Is Shaping the Future of Secure AI](<https://devfeed.tech/articles/from-ideas-to-impact-how-the-bay-area-is-shaping-the-future-of-secure-ai-7930.md>)

Original publisher: [Read original article](<https://snyk.io/blog/from-ideas-to-impact/>)

Author: Manoj Nair

Published: 2025-08-06T04:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Trustworthy AI](<https://devfeed.tech/topics/trustworthy-ai.md>), [ai security](<https://devfeed.tech/topics/ai-security.md>), [Securing AI](<https://devfeed.tech/topics/securing-ai.md>), [Generative AI](<https://devfeed.tech/topics/generative-ai.md>), [MCP Server](<https://devfeed.tech/topics/mcp-server.md>), [Responsibility & Safety](<https://devfeed.tech/topics/responsibility-safety.md>), [cursor](<https://devfeed.tech/topics/cursor.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [sdlc](<https://devfeed.tech/topics/sdlc.md>), [Development](<https://devfeed.tech/topics/development.md>), [AWS Transform](<https://devfeed.tech/topics/aws-transform.md>)

Tags: [agentic-ai](<https://devfeed.tech/tags/agentic-ai.md>), [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-security](<https://devfeed.tech/tags/ai-security.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [cursor](<https://devfeed.tech/tags/cursor.md>), [development](<https://devfeed.tech/tags/development.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [executive](<https://devfeed.tech/tags/executive.md>), [mcp-server](<https://devfeed.tech/tags/mcp-server.md>), [sdlc](<https://devfeed.tech/tags/sdlc.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [trust](<https://devfeed.tech/tags/trust.md>), [updates](<https://devfeed.tech/tags/updates.md>)

### AI overview

This article reports insights from Snyk's Silicon Valley Lighthouse event on building secure, trustworthy AI systems. It examines agentic applications, evolving development workflows, real-time security feedback, and a culture of shared responsibility across development, platform, and security teams.

### Source excerpt

Insights from Snyk's Silicon Valley Lighthouse event on building secure, trustworthy AI. Learn how to secure agentic apps, embrace a "secure by everyone" culture, and use guardrails for AI innovation.

## Snyk Joins CISA's Secure by Design Pledge

DevFeed: [Snyk Joins CISA's Secure by Design Pledge](<https://devfeed.tech/articles/snyk-joins-cisa-s-secure-by-design-pledge-8141.md>)

Original publisher: [Read original article](<https://snyk.io/blog/snyk-joins-cisas-secure-by-design-pledge/>)

Author: Brian Campbell

Published: 2025-08-05T04:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>), [MFA](<https://devfeed.tech/topics/mfa.md>), [cybersecurity and infrastructure security agency](<https://devfeed.tech/topics/cybersecurity-and-infrastructure-security-agency.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [Security](<https://devfeed.tech/topics/security.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [cisa](<https://devfeed.tech/tags/cisa.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [customer](<https://devfeed.tech/tags/customer.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [devops](<https://devfeed.tech/tags/devops.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [executive](<https://devfeed.tech/tags/executive.md>), [mfa](<https://devfeed.tech/tags/mfa.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [secure-by-design-pledge](<https://devfeed.tech/tags/secure-by-design-pledge.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [software](<https://devfeed.tech/tags/software.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Snyk's CISO describes the company's decision to join CISA's Secure by Design pledge. The article presents the pledge as a set of measurable goals for improving product security, including secure-by-default practices, MFA, eliminating default passwords, and reducing vulnerabilities before software reaches users.

### Source excerpt

Snyk's CISO explains why we've joined CISA's Secure by Design pledge. Learn about the 7 key goals for a safer digital world, including MFA, no default passwords, and vulnerability reduction.

## Guarding Azure Functions: Serverless Meets Secure-by-Design Containers

DevFeed: [Guarding Azure Functions: Serverless Meets Secure-by-Design Containers](<https://devfeed.tech/articles/guarding-azure-functions-serverless-meets-secure-by-design-containers-13074.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/guarding-azure-functions-serverless-meets-secure-by-design-containers>)

Published: 2025-07-17T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [azure functions](<https://devfeed.tech/topics/azure-functions.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [azure container apps](<https://devfeed.tech/topics/azure-container-apps.md>), [Serverless](<https://devfeed.tech/topics/serverless.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Node.js](<https://devfeed.tech/topics/node-js.md>), [Security](<https://devfeed.tech/topics/security.md>), [event driven](<https://devfeed.tech/topics/event-driven.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>)

Tags: [azure](<https://devfeed.tech/tags/azure.md>), [azure-functions](<https://devfeed.tech/tags/azure-functions.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [event-driven](<https://devfeed.tech/tags/event-driven.md>), [node-js](<https://devfeed.tech/tags/node-js.md>), [safe-source-for-open-source](<https://devfeed.tech/tags/safe-source-for-open-source.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [security](<https://devfeed.tech/tags/security.md>), [serverless](<https://devfeed.tech/tags/serverless.md>)

### AI overview

The article presents Chainguard Containers for Azure Functions, combining serverless deployment with secure-by-design, traceable container images. It describes a customized Node.js base image containing the Azure Functions Host, Node.js Worker for Functions, compatibility support, and extension bundles.

### Source excerpt

Chainguard Containers with Azure Functions offers the convenience of serverless and the confidence of a trusted, traceable image built for security.

## Understanding CRA Compliance: Overcoming Challenges with an Integrated Security Testing Approach

DevFeed: [Understanding CRA Compliance: Overcoming Challenges with an Integrated Security Testing Approach](<https://devfeed.tech/articles/understanding-cra-compliance-overcoming-challenges-with-an-integrated-security-testing-approach-8224.md>)

Original publisher: [Read original article](<https://snyk.io/blog/understanding-cra-compliance/>)

Author: Snyk Team

Published: 2025-06-25T23:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Testing](<https://devfeed.tech/topics/testing.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [DevOps](<https://devfeed.tech/topics/devops.md>), [Tooling](<https://devfeed.tech/topics/tooling.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Development](<https://devfeed.tech/topics/development.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [awareness](<https://devfeed.tech/tags/awareness.md>), [best-practices](<https://devfeed.tech/tags/best-practices.md>), [blog](<https://devfeed.tech/tags/blog.md>), [community](<https://devfeed.tech/tags/community.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [cra-requirements](<https://devfeed.tech/tags/cra-requirements.md>), [cyber-resilience-act](<https://devfeed.tech/tags/cyber-resilience-act.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [developer](<https://devfeed.tech/tags/developer.md>), [developers](<https://devfeed.tech/tags/developers.md>), [development](<https://devfeed.tech/tags/development.md>), [devops](<https://devfeed.tech/tags/devops.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [eu](<https://devfeed.tech/tags/eu.md>), [scanners](<https://devfeed.tech/tags/scanners.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>), [snyk-iac](<https://devfeed.tech/tags/snyk-iac.md>), [snyk-learn](<https://devfeed.tech/tags/snyk-learn.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [testing](<https://devfeed.tech/tags/testing.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>), [workflows](<https://devfeed.tech/tags/workflows.md>)

### AI overview

This article explains how the Cyber Resilience Act (CRA) changes software delivery expectations for organizations serving the EU. It highlights continuous security validation across proprietary code, open source libraries, and third-party dependencies, and recommends integrated security testing, secure-by-design practices, aligned teams, modern tooling, and security embedded in daily development workflows.

### Source excerpt

Learn how to meet CRA requirements with integrated security testing, secure-by-design workflows, and scalable practices for modern dev teams.

## BYOC: Secure by design, proper controls by default

DevFeed: [BYOC: Secure by design, proper controls by default](<https://devfeed.tech/articles/byoc-secure-by-design-proper-controls-by-default-12766.md>)

Original publisher: [Read original article](<https://www.redpanda.com/blog/response-jpmc-open-letter-software-byoc>)

Author: Bipin Singh

Published: 2025-06-18T00:00:00Z

Content type: article

Language: en

Sources: [Redpanda](<https://devfeed.tech/sources/redpanda.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Software as a service](<https://devfeed.tech/topics/saas.md>), [Self-hosted](<https://devfeed.tech/topics/self-hosted.md>), [VPC](<https://devfeed.tech/topics/vpc.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [IAM](<https://devfeed.tech/topics/iam.md>), [Deployment](<https://devfeed.tech/topics/deployment.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>)

Tags: [byoc-deployment](<https://devfeed.tech/tags/byoc-deployment.md>), [cloud-vpc-security](<https://devfeed.tech/tags/cloud-vpc-security.md>), [compliance-in-cloud-services](<https://devfeed.tech/tags/compliance-in-cloud-services.md>), [data-control-and-governance](<https://devfeed.tech/tags/data-control-and-governance.md>), [data-streaming-security](<https://devfeed.tech/tags/data-streaming-security.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [iam](<https://devfeed.tech/tags/iam.md>), [jpmc-software-suppliers-letter](<https://devfeed.tech/tags/jpmc-software-suppliers-letter.md>), [product](<https://devfeed.tech/tags/product.md>), [redpanda-byoc](<https://devfeed.tech/tags/redpanda-byoc.md>), [redpanda-cloud-features](<https://devfeed.tech/tags/redpanda-cloud-features.md>), [saas](<https://devfeed.tech/tags/saas.md>), [saas-operational-simplicity](<https://devfeed.tech/tags/saas-operational-simplicity.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [secure-saas-solutions](<https://devfeed.tech/tags/secure-saas-solutions.md>), [security](<https://devfeed.tech/tags/security.md>), [self-hosted](<https://devfeed.tech/tags/self-hosted.md>), [self-hosted-vs-saas-security](<https://devfeed.tech/tags/self-hosted-vs-saas-security.md>), [streaming-data-compliance](<https://devfeed.tech/tags/streaming-data-compliance.md>), [vpc](<https://devfeed.tech/tags/vpc.md>)

### AI overview

Redpanda argues that JPMorgan Chase's security requirements make secure-by-default design, continuous control validation, governance, and flexible deployment essential for enterprise software. Its Redpanda Cloud BYOC model places the data plane in the customer's VPC while Redpanda operates the control plane, preserving data ownership and operational convenience.

### Source excerpt

JPMorgan Chase warns: no governance, no deal. Luckily, Redpanda BYOC provides the security of self-hosted with the convenience of SaaS. Read more.

## Trusted Container Images: A Better Way to Build and Deploy Software

DevFeed: [Trusted Container Images: A Better Way to Build and Deploy Software](<https://devfeed.tech/articles/trusted-container-images-a-better-way-to-build-and-deploy-software-13297.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/trusted-container-images-a-better-way-to-build-and-deploy-software>)

Published: 2025-06-11T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Docker Hardened Images](<https://devfeed.tech/topics/docker-hardened-images.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Security](<https://devfeed.tech/topics/security.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [buyers-guide](<https://devfeed.tech/tags/buyers-guide.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [chainguard-vms](<https://devfeed.tech/tags/chainguard-vms.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [open-source-artifacts](<https://devfeed.tech/tags/open-source-artifacts.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [secure-container-images](<https://devfeed.tech/tags/secure-container-images.md>), [secure-open-source-artifacts](<https://devfeed.tech/tags/secure-open-source-artifacts.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>)

### AI overview

Chainguard's Buyer's Guide presents trusted container images and other open source artifacts as a way for enterprise engineering and security teams to reduce maintenance work, address supply-chain risks, and simplify compliance. It highlights Chainguard Containers as minimal, hardened images continuously built from source.

### Source excerpt

Chainguard's Trusted Container Images and Open Source Artifacts Buyer's Guide helps you improve supply chain security and reduce costly engineering toil.

## One Year Later: Signing CISA's Secure by Design Pledge

DevFeed: [One Year Later: Signing CISA's Secure by Design Pledge](<https://devfeed.tech/articles/one-year-later-signing-cisa-s-secure-by-design-pledge-13194.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/one-year-update-to-signing-cisas-secure-by-design-pledge>)

Published: 2025-06-10T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [cisa](<https://devfeed.tech/topics/cisa.md>), [cve remediation](<https://devfeed.tech/topics/cve-remediation.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [MFA](<https://devfeed.tech/topics/mfa.md>), [Security](<https://devfeed.tech/topics/security.md>), [Single sign-on (SSO)](<https://devfeed.tech/topics/sso.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [chainguard vms](<https://devfeed.tech/topics/chainguard-vms.md>), [ssh](<https://devfeed.tech/topics/ssh.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-vms](<https://devfeed.tech/tags/chainguard-vms.md>), [cisa](<https://devfeed.tech/tags/cisa.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-remediation](<https://devfeed.tech/tags/cve-remediation.md>), [mfa](<https://devfeed.tech/tags/mfa.md>), [okta](<https://devfeed.tech/tags/okta.md>), [password](<https://devfeed.tech/tags/password.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [secure-by-design-pledge](<https://devfeed.tech/tags/secure-by-design-pledge.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [security](<https://devfeed.tech/tags/security.md>), [shift-left](<https://devfeed.tech/tags/shift-left.md>), [ssh](<https://devfeed.tech/tags/ssh.md>), [sso](<https://devfeed.tech/tags/sso.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

Chainguard reviews its progress one year after signing CISA's Secure by Design pledge, including CVE remediation across its container images, company-wide MFA through Okta SSO, and password-free access with automated SSH key provisioning for Chainguard VMs.

### Source excerpt

Chainguard signed CISA's Secure by Design pledge in 2024. One year later, we look at progress we've made in key areas like CVE remediation and disclosures.

## Have We Reached a Distroless Tipping Point?

DevFeed: [Have We Reached a Distroless Tipping Point?](<https://devfeed.tech/articles/have-we-reached-a-distroless-tipping-point-13080.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/have-we-reached-a-distroless-tipping-point>)

Published: 2025-03-18T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [distroless](<https://devfeed.tech/topics/distroless.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Cloud Native Ecosystem](<https://devfeed.tech/topics/cloud-native-ecosystem.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Linux](<https://devfeed.tech/topics/linux.md>)

Tags: [beyond-distro](<https://devfeed.tech/tags/beyond-distro.md>), [cgroups](<https://devfeed.tech/tags/cgroups.md>), [chainguard-os](<https://devfeed.tech/tags/chainguard-os.md>), [chainguard-your-os](<https://devfeed.tech/tags/chainguard-your-os.md>), [cloud-native](<https://devfeed.tech/tags/cloud-native.md>), [containers](<https://devfeed.tech/tags/containers.md>), [distroless](<https://devfeed.tech/tags/distroless.md>), [kernel](<https://devfeed.tech/tags/kernel.md>), [linux](<https://devfeed.tech/tags/linux.md>), [oci](<https://devfeed.tech/tags/oci.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

The article argues that containerization and cloud-native software development have created an inflection point in open source software delivery. It presents the evolution from Linux Containers to Docker and the Open Container Initiative as milestones supporting a shift from traditional Linux distributions toward distroless, secure-by-design, continuously updated software.

### Source excerpt

The world is at an inflection point in open source software delivery. See where the software distribution status quo is at, and what is next.

## AI Risk Management: Benefits, Challenges, and Best Practices

DevFeed: [AI Risk Management: Benefits, Challenges, and Best Practices](<https://devfeed.tech/articles/ai-risk-management-benefits-challenges-and-best-practices-7810.md>)

Original publisher: [Read original article](<https://snyk.io/blog/ai-risk-management-benefits-challenges-and-best-practices/>)

Author: Stephen Thoemmes

Published: 2025-03-13T04:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [AI Strategy](<https://devfeed.tech/topics/ai-strategy.md>), [AI Development](<https://devfeed.tech/topics/ai-development.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [threat detection](<https://devfeed.tech/topics/threat-detection.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-adoption](<https://devfeed.tech/tags/ai-adoption.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [best-practices](<https://devfeed.tech/tags/best-practices.md>), [blog](<https://devfeed.tech/tags/blog.md>), [code-generation](<https://devfeed.tech/tags/code-generation.md>), [developer](<https://devfeed.tech/tags/developer.md>), [megawatt](<https://devfeed.tech/tags/megawatt.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [security](<https://devfeed.tech/tags/security.md>), [security-vulnerabilities](<https://devfeed.tech/tags/security-vulnerabilities.md>), [snyk-apprisk](<https://devfeed.tech/tags/snyk-apprisk.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>), [standards](<https://devfeed.tech/tags/standards.md>)

### AI overview

This article explains how organizations can manage risks introduced by AI development tools while still benefiting from faster coding and reduced manual work. It covers hidden vulnerabilities in generated code, outdated libraries, logic errors, compliance concerns, automated threat detection, and the use of NIST and ISO guidance to support secure-by-design AI adoption.

### Source excerpt

Learn how to manage AI risks effectively with best practices, frameworks, and strategies to ensure secure AI adoption while mitigating vulnerabilities.

## Incorporating security by design: Managing risk in DevSecOps

DevFeed: [Incorporating security by design: Managing risk in DevSecOps](<https://devfeed.tech/articles/incorporating-security-by-design-managing-risk-in-devsecops-7972.md>)

Original publisher: [Read original article](<https://snyk.io/blog/incorporating-security-by-design-managing-risk-in-devsecops/>)

Author: Ben Desjardins

Published: 2025-02-25T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [DevSecOps](<https://devfeed.tech/topics/devsecops.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [sdlc](<https://devfeed.tech/topics/sdlc.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Agile](<https://devfeed.tech/topics/agile.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [devops](<https://devfeed.tech/tags/devops.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [megawatt](<https://devfeed.tech/tags/megawatt.md>), [pmm](<https://devfeed.tech/tags/pmm.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [security](<https://devfeed.tech/tags/security.md>), [shift-left](<https://devfeed.tech/tags/shift-left.md>), [software-development](<https://devfeed.tech/tags/software-development.md>), [strategy](<https://devfeed.tech/tags/strategy.md>), [testing](<https://devfeed.tech/tags/testing.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This article explains why security should be embedded throughout the application lifecycle, from design and coding through testing and deployment. It presents secure-by-design and DevSecOps practices as ways to mitigate threats early, reduce remediation costs, and integrate security more effectively with developer workflows.

### Source excerpt

Explore the business value of mitigating security threats early in the development process and embedding security at every stage throughout the entire application lifecycle, and some of the most effective ways to adopt a secure-by-design approach.

## Announcing Chainguard Custom Assembly: Image Customization Without Complexity

DevFeed: [Announcing Chainguard Custom Assembly: Image Customization Without Complexity](<https://devfeed.tech/articles/announcing-chainguard-custom-assembly-image-customization-without-complexity-12877.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/announcing-chainguard-custom-assembly-image-customization-without-complexity>)

Published: 2025-02-20T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Security](<https://devfeed.tech/topics/security.md>), [Development](<https://devfeed.tech/topics/development.md>)

Tags: [bash](<https://devfeed.tech/tags/bash.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-custom-assembly](<https://devfeed.tech/tags/chainguard-custom-assembly.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [complexity](<https://devfeed.tech/tags/complexity.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [curl](<https://devfeed.tech/tags/curl.md>), [custom-assembly](<https://devfeed.tech/tags/custom-assembly.md>), [customization](<https://devfeed.tech/tags/customization.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-remediation](<https://devfeed.tech/tags/cve-remediation.md>), [development](<https://devfeed.tech/tags/development.md>), [docker](<https://devfeed.tech/tags/docker.md>), [image](<https://devfeed.tech/tags/image.md>), [integrity](<https://devfeed.tech/tags/integrity.md>), [maintenance](<https://devfeed.tech/tags/maintenance.md>), [no-vulnerabilities](<https://devfeed.tech/tags/no-vulnerabilities.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [security](<https://devfeed.tech/tags/security.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

Chainguard announces the beta release of Custom Assembly, a product for tailoring Chainguard Images with required packages while preserving hardened builds, security practices, and CVE remediation coverage. The article explains that the product addresses complex, maintenance-heavy customization workflows involving manual image changes, Docker builds, and proprietary pipelines.

### Source excerpt

Custom Assembly is Chainguard's new image customization product that enables companies to consume zero-CVE open source software tailored to unique requirements.

## Understanding the EU's Cyber Resilience Act (CRA)

DevFeed: [Understanding the EU's Cyber Resilience Act (CRA)](<https://devfeed.tech/articles/understanding-the-eu-s-cyber-resilience-act-cra-8226.md>)

Original publisher: [Read original article](<https://snyk.io/blog/understanding-the-eus-cyber-resilience-act-cra/>)

Author: Ben Desjardins

Published: 2025-01-22T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [cyber resilience act](<https://devfeed.tech/topics/cyber-resilience-act.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [sdlc](<https://devfeed.tech/topics/sdlc.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [snyk](<https://devfeed.tech/topics/snyk.md>)

Tags: [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [cyber-resilience-act](<https://devfeed.tech/tags/cyber-resilience-act.md>), [eu](<https://devfeed.tech/tags/eu.md>), [executive](<https://devfeed.tech/tags/executive.md>), [megawatt](<https://devfeed.tech/tags/megawatt.md>), [sast](<https://devfeed.tech/tags/sast.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [sca](<https://devfeed.tech/tags/sca.md>), [sdlc](<https://devfeed.tech/tags/sdlc.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>)

### AI overview

The article explains how the EU Cyber Resilience Act (CRA) establishes cybersecurity requirements for products with digital elements. It discusses secure-by-design practices, vulnerability handling throughout the product lifecycle, upcoming reporting and compliance deadlines, and the role of SAST, SCA, and software supply chain security.

### Source excerpt

Find out how the Cyber Resilience Act (CRA) sets new security standards for the EU and how Snyk can help simplify compliance with its developer-friendly tools.

## The principle of immutability

DevFeed: [The principle of immutability](<https://devfeed.tech/articles/the-principle-of-immutability-13266.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/the-principle-of-immutability>)

Published: 2024-08-20T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Programming](<https://devfeed.tech/topics/programming.md>), [Rust](<https://devfeed.tech/topics/rust.md>), [Functional programming](<https://devfeed.tech/topics/functional-programming.md>), [C++](<https://devfeed.tech/topics/c-plus-plus.md>), [Programming language](<https://devfeed.tech/topics/programming-language.md>)

Tags: [c-plus-plus](<https://devfeed.tech/tags/c-plus-plus.md>), [functional-programming](<https://devfeed.tech/tags/functional-programming.md>), [immutability](<https://devfeed.tech/tags/immutability.md>), [rust](<https://devfeed.tech/tags/rust.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>)

### AI overview

The article argues that immutability is about intentionally controlling change rather than preventing change. It presents immutability by default as part of secure-by-design software and compares approaches in functional programming, C++, and Rust.

### Source excerpt

Secure by default starts with immutability. Discover how to control change and minimize risks.

## Chainguard joins Coalition for Secure AI with OpenAI, Google, Anthropic

DevFeed: [Chainguard joins Coalition for Secure AI with OpenAI, Google, Anthropic](<https://devfeed.tech/articles/chainguard-joins-coalition-for-secure-ai-with-openai-google-anthropic-12963.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-joins-coalition-for-secure-ai-with-openai-google-anthropic>)

Published: 2024-07-18T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [ai security](<https://devfeed.tech/topics/ai-security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Security for AI](<https://devfeed.tech/topics/security-for-ai.md>), [Security](<https://devfeed.tech/topics/security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [ai-security](<https://devfeed.tech/tags/ai-security.md>), [amazon](<https://devfeed.tech/tags/amazon.md>), [anthropic](<https://devfeed.tech/tags/anthropic.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [cisco](<https://devfeed.tech/tags/cisco.md>), [coalition-for-secure-ai](<https://devfeed.tech/tags/coalition-for-secure-ai.md>), [cohere](<https://devfeed.tech/tags/cohere.md>), [cosai](<https://devfeed.tech/tags/cosai.md>), [google](<https://devfeed.tech/tags/google.md>), [ibm](<https://devfeed.tech/tags/ibm.md>), [intel](<https://devfeed.tech/tags/intel.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [nvidia](<https://devfeed.tech/tags/nvidia.md>), [oasis-open](<https://devfeed.tech/tags/oasis-open.md>), [openai](<https://devfeed.tech/tags/openai.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [standards](<https://devfeed.tech/tags/standards.md>), [wiz](<https://devfeed.tech/tags/wiz.md>)

### AI overview

Chainguard joins the Coalition for Secure AI (CoSAI) as a founding member alongside major technology companies. The coalition aims to develop open-source methodologies, standardized frameworks, and practical tools for Secure-by-Design AI systems, with initial workstreams covering AI software supply-chain security, cybersecurity integration, and AI security governance.

### Source excerpt

Chainguard joins the Coalition for Secure AI with OpenAI, Google, and Anthropic, enhancing AI security. Discover our commitment to safeguarding AI technologies.

## Signing CISA's Secure by Design pledge

DevFeed: [Signing CISA's Secure by Design pledge](<https://devfeed.tech/articles/signing-cisa-s-secure-by-design-pledge-13231.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/signing-cisas-secure-by-design-pledge>)

Published: 2024-05-08T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [cisa](<https://devfeed.tech/topics/cisa.md>), [MFA](<https://devfeed.tech/topics/mfa.md>), [Security](<https://devfeed.tech/topics/security.md>), [Single sign-on (SSO)](<https://devfeed.tech/topics/sso.md>), [OpenID connect (OIDC)](<https://devfeed.tech/topics/oidc.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [Auth0](<https://devfeed.tech/topics/auth0.md>), [Web](<https://devfeed.tech/topics/web.md>)

Tags: [auth0](<https://devfeed.tech/tags/auth0.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [best-practices](<https://devfeed.tech/tags/best-practices.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [cisa](<https://devfeed.tech/tags/cisa.md>), [cve](<https://devfeed.tech/tags/cve.md>), [mfa](<https://devfeed.tech/tags/mfa.md>), [oidc](<https://devfeed.tech/tags/oidc.md>), [password](<https://devfeed.tech/tags/password.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [secure-by-design-pledge](<https://devfeed.tech/tags/secure-by-design-pledge.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [security](<https://devfeed.tech/tags/security.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>), [sso](<https://devfeed.tech/tags/sso.md>)

### AI overview

Chainguard describes signing CISA's Secure by Design pledge and explains how its products and internal systems address the pledge's goals. The article discusses passwordless human login through SSO, MFA requirements, phishing-resistant security keys, and limitations in provider support for OIDC MFA claims.

### Source excerpt

Chainguard proudly signs CISA's Secure by Design pledge. Learn why we support this critical software security initiative.

## Lessons in logging: chopping down security risks using audit trails

DevFeed: [Lessons in logging: chopping down security risks using audit trails](<https://devfeed.tech/articles/lessons-in-logging-chopping-down-security-risks-using-audit-trails-29178.md>)

Original publisher: [Read original article](<https://www.latacora.com/blog/2023/11/28/lessons-in-logging-chopping-down-security-risks-using-audit-trails/>)

Published: 2023-11-28T15:30:00Z

Content type: tutorial

Language: en

Sources: [Latacora](<https://devfeed.tech/sources/latacora.md>)

Topics: [Logging](<https://devfeed.tech/topics/logging.md>), [audit](<https://devfeed.tech/topics/audit.md>), [Security](<https://devfeed.tech/topics/security.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>)

Tags: [audit](<https://devfeed.tech/tags/audit.md>), [logging](<https://devfeed.tech/tags/logging.md>), [logs](<https://devfeed.tech/tags/logs.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

This first post in a series explains logging and audit trails from a security perspective. It introduces secure logging requirements and describes how logs can support threat identification, incident investigation, remediation, and tracking user access or changes over defined time windows.

### Source excerpt

This post is the first in a series about logging and audit trails from a security perspective. For the next post in the series, see Lessons in Logging, Part 2: Mapping Your Path to a Mature Security Program with Logs and Audit Trails At Latacora, we bootstrap security practices. We partner with companies that frequently have minimally developed security programs, work with them to figure out the right security practices for their current size, and then help them evolve and scale those practices as their business matures.

## Threat Modeling and Secure by Design

DevFeed: [Threat Modeling and Secure by Design](<https://devfeed.tech/articles/threat-modeling-and-secure-by-design-36728.md>)

Original publisher: [Read original article](<https://shostack.org/blog/cisa-secure-by-design-feedback/>)

Author: Adam

Published: 2023-07-19T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [cisa](<https://devfeed.tech/topics/cisa.md>)

Tags: [complex](<https://devfeed.tech/tags/complex.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>)

### AI overview

The Threat Modeling Manifesto team published feedback to CISA responding to its Secure by Design Guidance. The feedback takes the form of a detailed letter, which was also covered by Infosecurity Magazine.

### Source excerpt

Our feedback to CISA is now public

[Next page](<https://devfeed.tech/tags/secure-by-design.md?cursor=WyIyMDIzLTA3LTE5VDAwOjAwOjAwKzAwOjAwIiwgIjE3MjgzMWMwLTkyNzQtNDRmOS1hN2ZmLTU0NWQ3OGRhM2IxYSJd>)