# secure software

Published articles for secure software.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Understanding platform engineering's role in staying compliant with the EU's CRA

DevFeed: [Understanding platform engineering's role in staying compliant with the EU's CRA](<https://devfeed.tech/articles/understanding-platform-engineering-s-role-in-staying-compliant-with-the-eu-s-cra-12256.md>)

Original publisher: [Read original article](<https://platformengineering.org/blog/understanding-platform-engineering-s-role-in-staying-compliant-with-the-eus-cra>)

Author: Nigel Douglas

Published: 2026-07-23T05:40:01Z

Content type: article

Language: en

Sources: [Platform Engineering Blog](<https://devfeed.tech/sources/platform-engineering-blog.md>)

Topics: [Platform Engineering](<https://devfeed.tech/topics/platform-engineering.md>), [Security](<https://devfeed.tech/topics/security.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [incident](<https://devfeed.tech/topics/incident.md>)

Tags: [compliance](<https://devfeed.tech/tags/compliance.md>), [cyber-resilience-act](<https://devfeed.tech/tags/cyber-resilience-act.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [eu](<https://devfeed.tech/tags/eu.md>), [idp](<https://devfeed.tech/tags/idp.md>), [incident](<https://devfeed.tech/tags/incident.md>), [platform](<https://devfeed.tech/tags/platform.md>), [platform-engineering](<https://devfeed.tech/tags/platform-engineering.md>), [policy](<https://devfeed.tech/tags/policy.md>), [regulatory](<https://devfeed.tech/tags/regulatory.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

The article explains how platform engineering can operationalize compliance with the EU's Cyber Resilience Act by embedding secure-by-default practices, automated SBOMs, and rapid incident reporting into an Internal Development Platform. It also outlines CRA compliance milestones and manufacturer responsibilities, including vulnerability management and security updates.

### Source excerpt

The EU's Cyber Resilience Act (CRA) mandates secure software by design. Discover how platform engineering operationalizes compliance by embedding secure-by-default standards, automated SBOMs, and rapid incident reporting into your Internal Development Platform (IDP). This approach transforms compliance into a frictionless golden path

## Why Backporting Python Security Fixes Is Complex and Risky

DevFeed: [Why Backporting Python Security Fixes Is Complex and Risky](<https://devfeed.tech/articles/this-shit-is-hard-the-complexities-of-fixing-python-library-security-issues-at-scale-13290.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/this-shit-is-hard-the-complexities-of-fixing-python-library-security-issues-at-scale>)

Published: 2026-02-27T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Python](<https://devfeed.tech/topics/python.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [chainguard libraries](<https://devfeed.tech/topics/chainguard-libraries.md>)

Tags: [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [cve](<https://devfeed.tech/tags/cve.md>), [dependency](<https://devfeed.tech/tags/dependency.md>), [machine-learning](<https://devfeed.tech/tags/machine-learning.md>), [python](<https://devfeed.tech/tags/python.md>), [python-dependencies](<https://devfeed.tech/tags/python-dependencies.md>), [python-libraries](<https://devfeed.tech/tags/python-libraries.md>), [python-packages](<https://devfeed.tech/tags/python-packages.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [zero-cve-python-libraries](<https://devfeed.tech/tags/zero-cve-python-libraries.md>)

### AI overview

The article explains why updating vulnerable Python dependencies can be difficult when compatibility constraints prevent immediate upgrades. It argues that manually backporting security patches is complex, time-consuming, and risky, and presents Chainguard Libraries as a source of tested and verified patched packages.

### Source excerpt

Backporting Python CVE fixes is complex and risky. Chainguard Libraries delivers source-built, tested, and verified patched packages you can trust.

## Introducing Fulfillment Dashboard: New artifact requests are now self-serve

DevFeed: [Introducing Fulfillment Dashboard: New artifact requests are now self-serve](<https://devfeed.tech/articles/introducing-fulfillment-dashboard-new-artifact-requests-are-now-self-serve-13116.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/introducing-fulfillment-dashboard-new-artifact-requests-are-now-self-serve>)

Published: 2026-02-12T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [dashboards](<https://devfeed.tech/topics/dashboards.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Development](<https://devfeed.tech/topics/development.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-factory](<https://devfeed.tech/tags/chainguard-factory.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [console](<https://devfeed.tech/tags/console.md>), [customers](<https://devfeed.tech/tags/customers.md>), [fulfillment-dashboard](<https://devfeed.tech/tags/fulfillment-dashboard.md>), [real-time](<https://devfeed.tech/tags/real-time.md>), [scale](<https://devfeed.tech/tags/scale.md>), [search](<https://devfeed.tech/tags/search.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [self-service](<https://devfeed.tech/tags/self-service.md>), [self-service-container-images](<https://devfeed.tech/tags/self-service-container-images.md>), [visibility](<https://devfeed.tech/tags/visibility.md>), [workflows](<https://devfeed.tech/tags/workflows.md>)

### AI overview

Chainguard introduces Fulfillment Dashboard, a self-service console for submitting, tracking, searching, and voting on secure container image requests. It provides lifecycle visibility, target delivery dates, deduplication, and community upvoting to help prioritize fulfillment.

### Source excerpt

Fulfillment Dashboard gives Chainguard customers real-time visibility, tracking, and community voting for new secure container image requests.

## DevSecCon 2025 Recap: Securing the AI Revolution Together

DevFeed: [DevSecCon 2025 Recap: Securing the AI Revolution Together](<https://devfeed.tech/articles/devseccon-2025-recap-securing-the-ai-revolution-together-7892.md>)

Original publisher: [Read original article](<https://snyk.io/blog/devseccon-2025-recap-securing-the-ai-revolution-together/>)

Author: Ben Desjardins

Published: 2025-10-22T23:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [DevSecOps](<https://devfeed.tech/topics/devsecops.md>), [snyk](<https://devfeed.tech/topics/snyk.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [ide](<https://devfeed.tech/topics/ide.md>), [Pull Request](<https://devfeed.tech/topics/pull-request.md>), [snyk-code](<https://devfeed.tech/topics/snyk-code.md>), [Development](<https://devfeed.tech/topics/development.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [ai](<https://devfeed.tech/tags/ai.md>), [also](<https://devfeed.tech/tags/also.md>), [blog](<https://devfeed.tech/tags/blog.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [ide](<https://devfeed.tech/tags/ide.md>), [interest](<https://devfeed.tech/tags/interest.md>), [pmm](<https://devfeed.tech/tags/pmm.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>)

### AI overview

This DevSecCon 2025 recap examines how AI is changing software development and security. It covers AI-accelerated DevSecOps, securing code from the first prompt, and managing AI-native application chaos with Evo by Snyk. The article also highlights Snyk capabilities for IDEs, pull requests, Snyk Code, and AppSec governance.

### Source excerpt

AI is changing development. Our DevSecCon 2025 recap covers the 3 critical stages: AI-Accelerated DevSecOps, securing code at the first prompt, and taming AI-native app chaos with Evo by Snyk.

## Chainguard + Booz Allen: Delivering Trusted Open-Source Software to U.S. Government Agencies

DevFeed: [Chainguard + Booz Allen: Delivering Trusted Open-Source Software to U.S. Government Agencies](<https://devfeed.tech/articles/chainguard-booz-allen-delivering-trusted-open-source-software-to-u-s-government-agencies-12931.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-booz-allen-delivering-trusted-open-source-software-to-u-s-government-agencies>)

Published: 2025-10-15T00:00:00Z

Content type: news

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [announce](<https://devfeed.tech/tags/announce.md>), [ato](<https://devfeed.tech/tags/ato.md>), [booz-allen-hamilton](<https://devfeed.tech/tags/booz-allen-hamilton.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-booz-partnership](<https://devfeed.tech/tags/chainguard-booz-partnership.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-dod-partnership](<https://devfeed.tech/tags/chainguard-dod-partnership.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [common-vulnerabilities-and-exposures](<https://devfeed.tech/tags/common-vulnerabilities-and-exposures.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [fips](<https://devfeed.tech/tags/fips.md>), [government](<https://devfeed.tech/tags/government.md>), [hardened-containers](<https://devfeed.tech/tags/hardened-containers.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [security](<https://devfeed.tech/tags/security.md>), [stateramp](<https://devfeed.tech/tags/stateramp.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [zero-cve-container-images](<https://devfeed.tech/tags/zero-cve-container-images.md>)

### AI overview

Chainguard and Booz Allen announced a partnership to help U.S. government agencies and defense programs secure software supply chains, reduce vulnerabilities, and accelerate compliance. The partnership combines Booz Allen's mission expertise with Chainguard's secure-by-default open-source software, including hardened containers that helped one defense-related program obtain authorization to operate in eight weeks.

### Source excerpt

Chainguard and Booz Allen partner to help federal programs eliminate vulnerabilities, save engineering time, and accelerate compliance timelines.

## Engineers Want to Build, Not Maintain: Key Findings From Our 2026 Engineering Reality Report

DevFeed: [Engineers Want to Build, Not Maintain: Key Findings From Our 2026 Engineering Reality Report](<https://devfeed.tech/articles/engineers-want-to-build-not-maintain-key-findings-from-our-2026-engineering-reality-report-13029.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/engineers-want-to-build-not-maintain-key-findings-from-our-2026-engineering-reality-report>)

Published: 2025-10-08T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Developer experience](<https://devfeed.tech/topics/developer-experience.md>), [code productivity](<https://devfeed.tech/topics/code-productivity.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Automation](<https://devfeed.tech/topics/automation.md>), [toolchains](<https://devfeed.tech/topics/toolchains.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [ai](<https://devfeed.tech/tags/ai.md>), [automation](<https://devfeed.tech/tags/automation.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers-report](<https://devfeed.tech/tags/chainguard-containers-report.md>), [chainguard-report](<https://devfeed.tech/tags/chainguard-report.md>), [developer-experience](<https://devfeed.tech/tags/developer-experience.md>), [developer-experience-report](<https://devfeed.tech/tags/developer-experience-report.md>), [engineering-reality](<https://devfeed.tech/tags/engineering-reality.md>), [engineering-reality-2025](<https://devfeed.tech/tags/engineering-reality-2025.md>), [productivity](<https://devfeed.tech/tags/productivity.md>), [report](<https://devfeed.tech/tags/report.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [security](<https://devfeed.tech/tags/security.md>), [software-engineer](<https://devfeed.tech/tags/software-engineer.md>), [toolchains](<https://devfeed.tech/tags/toolchains.md>)

### AI overview

Chainguard's 2026 Engineering Reality Report, based on a survey of 1,200 engineers and technology leaders, examines the modern developer experience. It finds that automation and AI are reducing repetitive work, while technical debt, maintenance, fragmented tooling, workflow disruption, burnout, and limited trust continue to constrain productivity. Engineers consistently want more time to build, and the article connects secure, integrated tools with innovation and business growth.

### Source excerpt

Chainguard surveyed 1,200 engineers and technology leaders to better understand the state of the developer experience today and where teams can improve.

## Meeting the Zero-CVE Mandate: How Chainguard Helps Businesses Ship Secure Software That Customers Trust

DevFeed: [Meeting the Zero-CVE Mandate: How Chainguard Helps Businesses Ship Secure Software That Customers Trust](<https://devfeed.tech/articles/meeting-the-zero-cve-mandate-how-chainguard-helps-businesses-ship-secure-software-that-customers-trust-13155.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/meeting-the-zero-cve-mandate-how-chainguard-helps-businesses-ship-secure-software-that-customers-trust>)

Published: 2025-10-06T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [software bill of materials](<https://devfeed.tech/topics/software-bill-of-materials.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-custom-assembly](<https://devfeed.tech/tags/chainguard-custom-assembly.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cves](<https://devfeed.tech/tags/cves.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

The article explains how Chainguard helps businesses meet stricter software security requirements for self-hosted, cloud, packaged-agent, and embedded software. It focuses on zero known CVEs at delivery, verifiable SBOMs, provenance attestations, compatibility with security tooling, and the challenges of open source dependencies and container images.

### Source excerpt

Chainguard's zero-CVE containers come with broad compatibility, custom assembly, verifiable provenance and SBOMs, and more to help you ship secure software.

## Using Tech to Tackle Homelessness. The Artisan of the Day Is Kevin McKee.

DevFeed: [Using Tech to Tackle Homelessness. The Artisan of the Day Is Kevin McKee.](<https://devfeed.tech/articles/using-tech-to-tackle-homelessness-the-artisan-of-the-day-is-kevin-mckee-3930.md>)

Original publisher: [Read original article](<https://laravel.com/blog/using-tech-to-tackle-homelessness-the-artisan-of-the-day-is-kevin-mckee>)

Author: Ana Tavares

Published: 2025-09-17T15:16:18Z

Content type: article

Language: en

Sources: [Laravel Blog](<https://devfeed.tech/sources/laravel-blog.md>)

Topics: [Laravel](<https://devfeed.tech/topics/laravel.md>), [Software as a service](<https://devfeed.tech/topics/saas.md>), [Software](<https://devfeed.tech/topics/software.md>), [Framework](<https://devfeed.tech/topics/framework.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [cto](<https://devfeed.tech/tags/cto.md>), [developers](<https://devfeed.tech/tags/developers.md>), [laravel](<https://devfeed.tech/tags/laravel.md>), [platform](<https://devfeed.tech/tags/platform.md>), [saas](<https://devfeed.tech/tags/saas.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [software](<https://devfeed.tech/tags/software.md>)

### AI overview

Kevin McKee, CTO of Padmission, describes how Laravel powers the company's SaaS platform for government agencies, nonprofits, and case managers addressing homelessness. Laravel's speed, productivity, and security help a small team deliver affordable, scalable tools for housing services.

### Source excerpt

Kevin McKee, CTO of Padmission, explains how he uses Laravel to power the SaaS platform helping communities fight homelessness with secure software solutions.

## Why Chainguard's Full-Stack Approach to Secure Software Supply Chain Is Built to Scale

DevFeed: [Why Chainguard's Full-Stack Approach to Secure Software Supply Chain Is Built to Scale](<https://devfeed.tech/articles/why-chainguard-s-full-stack-approach-to-secure-software-supply-chain-is-built-to-scale-13328.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/why-chainguards-full-stack-approach-to-secure-software-supply-chain-is-built-to-scale>)

Published: 2025-07-09T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard os](<https://devfeed.tech/topics/chainguard-os.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [automated](<https://devfeed.tech/tags/automated.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-factory](<https://devfeed.tech/tags/chainguard-factory.md>), [chainguard-os](<https://devfeed.tech/tags/chainguard-os.md>), [cve](<https://devfeed.tech/tags/cve.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [open-source-artifacts](<https://devfeed.tech/tags/open-source-artifacts.md>), [open-source-software-security](<https://devfeed.tech/tags/open-source-software-security.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [reproducibility](<https://devfeed.tech/tags/reproducibility.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [secure-software-supply-chain](<https://devfeed.tech/tags/secure-software-supply-chain.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>)

### AI overview

The article presents Chainguard's integrated approach to software supply chain security, combining Chainguard OS with the Chainguard Factory. It describes reproducible source builds, incremental updates, traceable contents, verifiable metadata, and automated maintenance of open source artifacts.

### Source excerpt

Learn how Chainguard OS and the Chainguard Factory delivers the only scalable path to secure, reliable software artifacts.

## Finding Software Flaws Early in the Development Process Provides Clear ROI

DevFeed: [Finding Software Flaws Early in the Development Process Provides Clear ROI](<https://devfeed.tech/articles/finding-software-flaws-early-in-the-development-process-provides-clear-roi-7923.md>)

Original publisher: [Read original article](<https://snyk.io/blog/finding-software-flaws-early-in-the-development-process-provides-clear-roi/>)

Author: Nuno Loureiro

Published: 2025-06-11T23:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Development](<https://devfeed.tech/topics/development.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [sdlc](<https://devfeed.tech/topics/sdlc.md>), [Security](<https://devfeed.tech/topics/security.md>), [Software](<https://devfeed.tech/topics/software.md>), [Software Engineering](<https://devfeed.tech/topics/software-engineering.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [business](<https://devfeed.tech/tags/business.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [cost](<https://devfeed.tech/tags/cost.md>), [development](<https://devfeed.tech/tags/development.md>), [devops](<https://devfeed.tech/tags/devops.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [executive](<https://devfeed.tech/tags/executive.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [sdlc](<https://devfeed.tech/tags/sdlc.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [software](<https://devfeed.tech/tags/software.md>), [software-development](<https://devfeed.tech/tags/software-development.md>), [us](<https://devfeed.tech/tags/us.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article explains that poor and insecure software creates substantial costs and security risks, while finding software flaws early in the software development life cycle provides a clear return on investment. It describes how vulnerabilities that reach production can expose organizations to breaches, data theft, lateral movement, and ransomware, and argues that organizations should improve software quality and identify security flaws during development.

### Source excerpt

The Consortium for Information and Software Quality estimated that the cost of poor software quality in the United States reached $2.41 trillion in 2022. As we will show, it makes sense that the cost of poor software quality is so high. It's also completely avoidable, and software flaws must be avoided with the world's increased dependency on software.

## One Year Later: Signing CISA's Secure by Design Pledge

DevFeed: [One Year Later: Signing CISA's Secure by Design Pledge](<https://devfeed.tech/articles/one-year-later-signing-cisa-s-secure-by-design-pledge-13194.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/one-year-update-to-signing-cisas-secure-by-design-pledge>)

Published: 2025-06-10T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [cisa](<https://devfeed.tech/topics/cisa.md>), [cve remediation](<https://devfeed.tech/topics/cve-remediation.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [MFA](<https://devfeed.tech/topics/mfa.md>), [Security](<https://devfeed.tech/topics/security.md>), [Single sign-on (SSO)](<https://devfeed.tech/topics/sso.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [chainguard vms](<https://devfeed.tech/topics/chainguard-vms.md>), [ssh](<https://devfeed.tech/topics/ssh.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-vms](<https://devfeed.tech/tags/chainguard-vms.md>), [cisa](<https://devfeed.tech/tags/cisa.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-remediation](<https://devfeed.tech/tags/cve-remediation.md>), [mfa](<https://devfeed.tech/tags/mfa.md>), [okta](<https://devfeed.tech/tags/okta.md>), [password](<https://devfeed.tech/tags/password.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [secure-by-design-pledge](<https://devfeed.tech/tags/secure-by-design-pledge.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [security](<https://devfeed.tech/tags/security.md>), [shift-left](<https://devfeed.tech/tags/shift-left.md>), [ssh](<https://devfeed.tech/tags/ssh.md>), [sso](<https://devfeed.tech/tags/sso.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

Chainguard reviews its progress one year after signing CISA's Secure by Design pledge, including CVE remediation across its container images, company-wide MFA through Okta SSO, and password-free access with automated SSH key provisioning for Chainguard VMs.

### Source excerpt

Chainguard signed CISA's Secure by Design pledge in 2024. One year later, we look at progress we've made in key areas like CVE remediation and disclosures.

## Demonstrably Secure Software Supply Chains with Nix

DevFeed: [Demonstrably Secure Software Supply Chains with Nix](<https://devfeed.tech/articles/demonstrably-secure-software-supply-chains-with-nix-32452.md>)

Original publisher: [Read original article](<https://nixcademy.com/posts/secure-supply-chain-with-nix/>)

Author: Jacek Galowicz

Published: 2025-05-12T00:00:00Z

Content type: article

Language: en

Sources: [Nixcademy Blog](<https://devfeed.tech/sources/nixcademy-blog.md>)

Topics: [Nix](<https://devfeed.tech/topics/nix.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [integrity](<https://devfeed.tech/topics/integrity.md>), [Security](<https://devfeed.tech/topics/security.md>), [toolchains](<https://devfeed.tech/topics/toolchains.md>), [audit](<https://devfeed.tech/topics/audit.md>)

Tags: [audit](<https://devfeed.tech/tags/audit.md>), [audits](<https://devfeed.tech/tags/audits.md>), [builds](<https://devfeed.tech/tags/builds.md>), [capabilities](<https://devfeed.tech/tags/capabilities.md>), [compilers](<https://devfeed.tech/tags/compilers.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [environments](<https://devfeed.tech/tags/environments.md>), [government](<https://devfeed.tech/tags/government.md>), [integrity](<https://devfeed.tech/tags/integrity.md>), [local](<https://devfeed.tech/tags/local.md>), [offline](<https://devfeed.tech/tags/offline.md>), [organizations](<https://devfeed.tech/tags/organizations.md>), [rebuilds](<https://devfeed.tech/tags/rebuilds.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [security](<https://devfeed.tech/tags/security.md>), [software](<https://devfeed.tech/tags/software.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>)

### AI overview

This article explains how Nix can support verifiable software supply chain integrity. It describes tracing sources and toolchains, enabling hermetic offline rebuilds, and exporting release sources for audits to help meet regulatory requirements.

### Source excerpt

Discover how Nix can revolutionize your software supply chain security, enabling verifiable integrity and offline rebuilds from source.

## Key Takeaways from Chainguard Assemble 2025

DevFeed: [Key Takeaways from Chainguard Assemble 2025](<https://devfeed.tech/articles/key-takeaways-from-chainguard-assemble-2025-13137.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/key-takeaways-from-chainguard-assemble-2025>)

Published: 2025-03-27T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard libraries](<https://devfeed.tech/topics/chainguard-libraries.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [chainguard os](<https://devfeed.tech/topics/chainguard-os.md>), [chainguard vms](<https://devfeed.tech/topics/chainguard-vms.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [assemble-2025](<https://devfeed.tech/tags/assemble-2025.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-assemble](<https://devfeed.tech/tags/chainguard-assemble.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [chainguard-os](<https://devfeed.tech/tags/chainguard-os.md>), [chainguard-vms](<https://devfeed.tech/tags/chainguard-vms.md>), [datadog](<https://devfeed.tech/tags/datadog.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [oz-pearlman](<https://devfeed.tech/tags/oz-pearlman.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [software-development](<https://devfeed.tech/tags/software-development.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>)

### AI overview

Chainguard Assemble 2025 brought together security and engineering professionals to discuss secure software development, software supply chain security, and open source software. Chainguard highlighted Chainguard Containers, Chainguard Libraries, Chainguard VMs, and Chainguard OS, while also announcing partnerships and providing access to keynote and selected session recordings.

### Source excerpt

Chainguard announced Chainguard Libraries, Chainguard VMs, and a new partnership with Datadog at Assemble, our inaugural event for security and developer pros.

## Chainguard Starter Images Now Available in Iron Bank: Minimal, Secure, and Reliable

DevFeed: [Chainguard Starter Images Now Available in Iron Bank: Minimal, Secure, and Reliable](<https://devfeed.tech/articles/chainguard-starter-images-now-available-in-iron-bank-minimal-secure-and-reliable-12983.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-starter-images-now-available-in-iron-bank-minimal-secure-and-reliable>)

Published: 2025-03-06T00:00:00Z

Content type: news

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-starter-images](<https://devfeed.tech/tags/chainguard-starter-images.md>), [container](<https://devfeed.tech/tags/container.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [iron-bank](<https://devfeed.tech/tags/iron-bank.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [zero-cve-container-images](<https://devfeed.tech/tags/zero-cve-container-images.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

Chainguard Starter Images are now available in the Iron Bank image repository. The images are designed to reduce vulnerability findings, simplify VAT remediation, and streamline the path to Authorization to Operate. Chainguard describes them as secure-by-default images built from source with signed and attested artifacts, build-time SBOMs, hardened compiler settings, and reduced attack surfaces.

### Source excerpt

Chainguard Starter Images are zero CVE container images that are now available in the Iron Bank image repository.

## NIS2: Understanding key software security requirements

DevFeed: [NIS2: Understanding key software security requirements](<https://devfeed.tech/articles/nis2-understanding-key-software-security-requirements-13185.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/nis2-understanding-key-software-security-requirements>)

Published: 2025-02-25T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Critical Infrastructure](<https://devfeed.tech/topics/critical-infrastructure.md>), [Development](<https://devfeed.tech/topics/development.md>)

Tags: [compliance](<https://devfeed.tech/tags/compliance.md>), [cve-management](<https://devfeed.tech/tags/cve-management.md>), [cve-reporting](<https://devfeed.tech/tags/cve-reporting.md>), [energy](<https://devfeed.tech/tags/energy.md>), [eu](<https://devfeed.tech/tags/eu.md>), [europe](<https://devfeed.tech/tags/europe.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [manufacturing](<https://devfeed.tech/tags/manufacturing.md>), [nis2](<https://devfeed.tech/tags/nis2.md>), [risk-management](<https://devfeed.tech/tags/risk-management.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [transportation](<https://devfeed.tech/tags/transportation.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

This article explains how the European Union's NIS2 directive expands software security and vulnerability management requirements, shifts accountability to management and boards, and affects organizations operating in the EU. It discusses software supply chain security, open source development, SBOMs, CVE reporting, risk management, and the workload these requirements may create for security and developer teams.

### Source excerpt

The European Union's Network and Information Systems 2 is a compliance framework with strict requirements around vulnerability management.

## Chainguard Signs CISA's Secure Software Development Attestation Form

DevFeed: [Chainguard Signs CISA's Secure Software Development Attestation Form](<https://devfeed.tech/articles/chainguard-signs-cisa-s-secure-software-development-attestation-form-12982.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-signs-cisas-secure-software-development-attestation-form>)

Published: 2025-02-24T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>)

Tags: [announce](<https://devfeed.tech/tags/announce.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [cisa](<https://devfeed.tech/tags/cisa.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [government](<https://devfeed.tech/tags/government.md>), [nist](<https://devfeed.tech/tags/nist.md>), [product-security](<https://devfeed.tech/tags/product-security.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [standards](<https://devfeed.tech/tags/standards.md>), [supply-chain-attacks](<https://devfeed.tech/tags/supply-chain-attacks.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>)

### AI overview

Chainguard announces that it has signed CISA's Secure Software Development Attestation Form. The attestation states that Chainguard products align with NIST's Secure Software Development Framework and federal software supply chain security requirements, including secure development environments, trusted source code supply chains, automated controls, and provenance data.

### Source excerpt

Chainguard has recently signed CISA's Secure Software Development Attestation Form, attesting to the security of Chainguard and its products.

## Snyk named a Customer Favorite in The Forrester Wave™: Software Composition Analysis Software, Q4 2024 Report

DevFeed: [Snyk named a Customer Favorite in The Forrester Wave™: Software Composition Analysis Software, Q4 2024 Report](<https://devfeed.tech/articles/snyk-named-a-customer-favorite-in-the-forrester-wavetm-software-composition-analysis-software-q4-2024-report-8135.md>)

Original publisher: [Read original article](<https://snyk.io/blog/snyk-forrester-wave-2024/>)

Author: Peter McKay

Published: 2024-11-13T05:00:00Z

Content type: news

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [snyk-open-source](<https://devfeed.tech/topics/snyk-open-source.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [DevSecOps](<https://devfeed.tech/topics/devsecops.md>), [Automation](<https://devfeed.tech/topics/automation.md>), [Security](<https://devfeed.tech/topics/security.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [acquisition](<https://devfeed.tech/tags/acquisition.md>), [analytics](<https://devfeed.tech/tags/analytics.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [aspm](<https://devfeed.tech/tags/aspm.md>), [automation](<https://devfeed.tech/tags/automation.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [component](<https://devfeed.tech/tags/component.md>), [customer](<https://devfeed.tech/tags/customer.md>), [developer-security-platform](<https://devfeed.tech/tags/developer-security-platform.md>), [devops](<https://devfeed.tech/tags/devops.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [executive](<https://devfeed.tech/tags/executive.md>), [innovation](<https://devfeed.tech/tags/innovation.md>), [integration](<https://devfeed.tech/tags/integration.md>), [megawatt](<https://devfeed.tech/tags/megawatt.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [pmm](<https://devfeed.tech/tags/pmm.md>), [recognition](<https://devfeed.tech/tags/recognition.md>), [report](<https://devfeed.tech/tags/report.md>), [sca](<https://devfeed.tech/tags/sca.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [shift-left](<https://devfeed.tech/tags/shift-left.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [software-composition-analysis](<https://devfeed.tech/tags/software-composition-analysis.md>), [software-development](<https://devfeed.tech/tags/software-development.md>), [strategy](<https://devfeed.tech/tags/strategy.md>), [support](<https://devfeed.tech/tags/support.md>)

### AI overview

Snyk announces that it was recognized as a Leader and a Customer Favorite in The Forrester Wave: Software Composition Analysis Software, Q4 2024. The article highlights Snyk's scores for strategy, risk intelligence, remediation and automation, reporting and analytics, toolchain integration, and component health, along with its developer-first approach to application security and DevSecOps.

### Source excerpt

Snyk's developer-first approach secures recognition as a Customer Favorite and a Leader in The Forrester Wave™: Software Composition Analysis (SCA) Software, Q4 2024 report.

## Meet Snyk for Government: Our developer security solution with FedRAMP ATO

DevFeed: [Meet Snyk for Government: Our developer security solution with FedRAMP ATO](<https://devfeed.tech/articles/meet-snyk-for-government-our-developer-security-solution-with-fedramp-ato-8134.md>)

Original publisher: [Read original article](<https://snyk.io/blog/snyk-for-government-developer-security-solution-with-fedramp-ato/>)

Author: Danny Allan

Published: 2024-09-17T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [aspm](<https://devfeed.tech/tags/aspm.md>), [ato](<https://devfeed.tech/tags/ato.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [executive](<https://devfeed.tech/tags/executive.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [fedramp-ato](<https://devfeed.tech/tags/fedramp-ato.md>), [government](<https://devfeed.tech/tags/government.md>), [public-sector](<https://devfeed.tech/tags/public-sector.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [security](<https://devfeed.tech/tags/security.md>), [shift-left](<https://devfeed.tech/tags/shift-left.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-apprisk](<https://devfeed.tech/tags/snyk-apprisk.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

Snyk announces that Snyk for Government has received an authorization to operate from its FedRAMP sponsor, enabling public sector teams to use the offering while formal FedRAMP authorization progresses. The article describes application security, software supply chain protection, vulnerability and compliance intelligence, inline code scanning, and SBOM creation for government agencies.

### Source excerpt

Discover how Snyk's FedRAMP-authorized platform empowers developers to build secure applications. Learn about our comprehensive solutions for vulnerability management, supply chain security, and AI code scanning.

## 3 ways AppSec modernization is a game-changer for financial services

DevFeed: [3 ways AppSec modernization is a game-changer for financial services](<https://devfeed.tech/articles/3-ways-appsec-modernization-is-a-game-changer-for-financial-services-7827.md>)

Original publisher: [Read original article](<https://snyk.io/blog/appsec-modernization-for-financial-services/>)

Author: Katie DeMatteis

Published: 2024-09-03T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [software-development](<https://devfeed.tech/topics/software-development.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [development](<https://devfeed.tech/tags/development.md>), [devops](<https://devfeed.tech/tags/devops.md>), [executive](<https://devfeed.tech/tags/executive.md>), [financial-services](<https://devfeed.tech/tags/financial-services.md>), [finserv](<https://devfeed.tech/tags/finserv.md>), [fintech](<https://devfeed.tech/tags/fintech.md>), [interest](<https://devfeed.tech/tags/interest.md>), [megawatt](<https://devfeed.tech/tags/megawatt.md>), [modernization](<https://devfeed.tech/tags/modernization.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [security](<https://devfeed.tech/tags/security.md>), [shift-left](<https://devfeed.tech/tags/shift-left.md>), [software-development](<https://devfeed.tech/tags/software-development.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>)

### AI overview

The article explains why financial services companies need to modernize application security as development becomes faster and more complex. It highlights developer adoption, shift-left security, regulatory compliance, and software supply-chain risks as central concerns.

### Source excerpt

Learn why modernizing application security is essential for today's financial services companies.

## Chainguard enhances security with OSV advisory feed

DevFeed: [Chainguard enhances security with OSV advisory feed](<https://devfeed.tech/articles/chainguard-enhances-security-with-osv-advisory-feed-12943.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-enhances-security-with-osv-advisory-feed>)

Published: 2024-07-02T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Maintainers](<https://devfeed.tech/topics/maintainers.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [data](<https://devfeed.tech/topics/data.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Google](<https://devfeed.tech/topics/google.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [google](<https://devfeed.tech/tags/google.md>), [maintainers](<https://devfeed.tech/tags/maintainers.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-vulnerabilities](<https://devfeed.tech/tags/open-source-vulnerabilities.md>), [openssf](<https://devfeed.tech/tags/openssf.md>), [osv](<https://devfeed.tech/tags/osv.md>), [secure-open-source](<https://devfeed.tech/tags/secure-open-source.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-data](<https://devfeed.tech/tags/vulnerability-data.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Chainguard is publishing its security advisory feed in the OSV format, improving the precision and usability of vulnerability information for open source maintainers and downstream consumers.

### Source excerpt

Explore Chainguard's new OSV advisory feed, delivering comprehensive and up-to-date vulnerability information to enhance your security posture.

## How to secure a REST API?

DevFeed: [How to secure a REST API?](<https://devfeed.tech/articles/how-to-secure-a-rest-api-7963.md>)

Original publisher: [Read original article](<https://snyk.io/blog/how-to-secure-rest-api/>)

Author: Liran Tal

Published: 2024-06-27T13:00:00Z

Content type: tutorial

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [REST API](<https://devfeed.tech/topics/rest-api.md>), [Security](<https://devfeed.tech/topics/security.md>), [API](<https://devfeed.tech/topics/api.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [web applications](<https://devfeed.tech/topics/web-applications.md>), [CRUD](<https://devfeed.tech/topics/crud.md>), [Databases](<https://devfeed.tech/topics/databases.md>), [SQL](<https://devfeed.tech/topics/sql.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [backend](<https://devfeed.tech/tags/backend.md>), [blog](<https://devfeed.tech/tags/blog.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [data](<https://devfeed.tech/tags/data.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [http](<https://devfeed.tech/tags/http.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [rest](<https://devfeed.tech/tags/rest.md>), [rest-api](<https://devfeed.tech/tags/rest-api.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [web-applications](<https://devfeed.tech/tags/web-applications.md>), [web-development](<https://devfeed.tech/tags/web-development.md>)

### AI overview

This tutorial explains what REST APIs are, how they use HTTP to exchange data, and why their versatility creates security risks. It covers injection attacks, broken authentication, sensitive data exposure, and missing rate limiting, with examples including SQL injection, the 2018 Reddit breach, and the 2016 Dyn attack.

### Source excerpt

In this post, we'll discuss what REST APIs are and how to secure them.

## Signing CISA's Secure by Design pledge

DevFeed: [Signing CISA's Secure by Design pledge](<https://devfeed.tech/articles/signing-cisa-s-secure-by-design-pledge-13231.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/signing-cisas-secure-by-design-pledge>)

Published: 2024-05-08T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [cisa](<https://devfeed.tech/topics/cisa.md>), [MFA](<https://devfeed.tech/topics/mfa.md>), [Security](<https://devfeed.tech/topics/security.md>), [Single sign-on (SSO)](<https://devfeed.tech/topics/sso.md>), [OpenID connect (OIDC)](<https://devfeed.tech/topics/oidc.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [Auth0](<https://devfeed.tech/topics/auth0.md>), [Web](<https://devfeed.tech/topics/web.md>)

Tags: [auth0](<https://devfeed.tech/tags/auth0.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [best-practices](<https://devfeed.tech/tags/best-practices.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [cisa](<https://devfeed.tech/tags/cisa.md>), [cve](<https://devfeed.tech/tags/cve.md>), [mfa](<https://devfeed.tech/tags/mfa.md>), [oidc](<https://devfeed.tech/tags/oidc.md>), [password](<https://devfeed.tech/tags/password.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [secure-by-design-pledge](<https://devfeed.tech/tags/secure-by-design-pledge.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [security](<https://devfeed.tech/tags/security.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>), [sso](<https://devfeed.tech/tags/sso.md>)

### AI overview

Chainguard describes signing CISA's Secure by Design pledge and explains how its products and internal systems address the pledge's goals. The article discusses passwordless human login through SSO, MFA requirements, phishing-resistant security keys, and limitations in provider support for OIDC MFA claims.

### Source excerpt

Chainguard proudly signs CISA's Secure by Design pledge. Learn why we support this critical software security initiative.

## New Chainguard Academy course: Painless Vulnerability Management

DevFeed: [New Chainguard Academy course: Painless Vulnerability Management](<https://devfeed.tech/articles/new-chainguard-academy-course-painless-vulnerability-management-13171.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/new-chainguard-academy-course-painless-vulnerability-management>)

Published: 2024-02-14T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Security](<https://devfeed.tech/topics/security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Learning](<https://devfeed.tech/topics/learning.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-academy](<https://devfeed.tech/tags/chainguard-academy.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-image](<https://devfeed.tech/tags/container-image.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [course](<https://devfeed.tech/tags/course.md>), [cve](<https://devfeed.tech/tags/cve.md>), [image-security](<https://devfeed.tech/tags/image-security.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [security](<https://devfeed.tech/tags/security.md>), [software](<https://devfeed.tech/tags/software.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

Chainguard announces a free-to-early-adopters Chainguard Academy course on vulnerability management. The course covers understanding, triaging, and mitigating vulnerabilities, standard tools and practices, and how Chainguard Images can support secure-by-default software development.

### Source excerpt

Enroll in Chainguard Academy's new course on Painless Vulnerability Management to master security practices and use Chainguard Images for safer software.

## Announcing Bazel rules for extending Chainguard Images

DevFeed: [Announcing Bazel rules for extending Chainguard Images](<https://devfeed.tech/articles/announcing-bazel-rules-for-extending-chainguard-images-12875.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/announcing-bazel-rules-for-extending-chainguard-images>)

Published: 2023-10-24T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [distroless](<https://devfeed.tech/topics/distroless.md>), [Package manager](<https://devfeed.tech/topics/package-manager.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [apk](<https://devfeed.tech/tags/apk.md>), [apko](<https://devfeed.tech/tags/apko.md>), [bazel](<https://devfeed.tech/tags/bazel.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [distroless](<https://devfeed.tech/tags/distroless.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [secure-software-supply-chain](<https://devfeed.tech/tags/secure-software-supply-chain.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Chainguard and Aspect.Dev announce the general availability of rules_apko, an open source Bazel plugin for building secure, minimal Wolfi-based OCI container images. The article explains how rules_apko integrates APK packages and Wolfi-base images into existing Bazel workflows, supports reproducible builds, and provides dependency locking, integrity verification, and SBOM generation.

### Source excerpt

Explore Bazel rules for Chainguard Images, your pathway to secure, effortless image extension.

[Next page](<https://devfeed.tech/tags/secure-software.md?cursor=WyIyMDIzLTEwLTI0VDAwOjAwOjAwKzAwOjAwIiwgImRkZDVmY2M0LWYxOWEtNDkyYy05ZjZjLTQ5MzNhZTJkMjdjOSJd>)