# secure software development frameworks

Published articles for secure software development frameworks.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## What every CISO should know about the new SSDF security self-attestation form

DevFeed: [What every CISO should know about the new SSDF security self-attestation form](<https://devfeed.tech/articles/what-every-ciso-should-know-about-the-new-ssdf-security-self-attestation-form-13316.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/what-every-ciso-should-know-about-the-new-ssdf-security-self-attestation-form>)

Published: 2023-08-08T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [cisa](<https://devfeed.tech/topics/cisa.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [cisa](<https://devfeed.tech/tags/cisa.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [regulatory](<https://devfeed.tech/tags/regulatory.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [secure-software-development-frameworks](<https://devfeed.tech/tags/secure-software-development-frameworks.md>), [self-attestation](<https://devfeed.tech/tags/self-attestation.md>), [software-security-audit](<https://devfeed.tech/tags/software-security-audit.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [ssdf](<https://devfeed.tech/tags/ssdf.md>), [standards](<https://devfeed.tech/tags/standards.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

This joint blog post explains a proposed Secure Software Self-Attestation Form published by CISA and its implications for CISOs. It describes how organizations selling software for government use may need to attest to their best efforts to follow NIST's Secure Software Development Framework, while highlighting related software supply chain security practices and regulatory developments.

### Source excerpt

Explore the pivotal SSDF Security Self-Attestation Form, a key resource for CISOs to navigate and enhance security compliance.

## Strengthening CI/CD Environments: Insights from NSA and DHS CISA guidance

DevFeed: [Strengthening CI/CD Environments: Insights from NSA and DHS CISA guidance](<https://devfeed.tech/articles/strengthening-ci-cd-environments-insights-from-nsa-and-dhs-cisa-guidance-13241.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/strengthening-ci-cd-environments-insights-from-nsa-and-dhs-cisa-guidance>)

Published: 2023-06-30T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [CI/CD](<https://devfeed.tech/topics/cicd.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [DevSecOps](<https://devfeed.tech/topics/devsecops.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [cisa](<https://devfeed.tech/topics/cisa.md>)

Tags: [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [cicd](<https://devfeed.tech/tags/cicd.md>), [cisa](<https://devfeed.tech/tags/cisa.md>), [continuous-verification](<https://devfeed.tech/tags/continuous-verification.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [secure-software-development-frameworks](<https://devfeed.tech/tags/secure-software-development-frameworks.md>), [security](<https://devfeed.tech/tags/security.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [ssdf](<https://devfeed.tech/tags/ssdf.md>)

### AI overview

This commentary explains NSA and DHS CISA guidance for securing CI/CD environments. It highlights risks to downstream environments and software consumers, including compromised developer credentials and application libraries, and recommends established software supply chain security frameworks such as SLSA and CNCF best practices.

### Source excerpt

Fortify your CI/CD environments with insights from NSA and DHS CISA guidance, presented by Chainguard.

## New SLSA++ Survey reveals real-world developer approaches to software supply chain security

DevFeed: [New SLSA++ Survey reveals real-world developer approaches to software supply chain security](<https://devfeed.tech/articles/new-slsa-survey-reveals-real-world-developer-approaches-to-software-supply-chain-security-13183.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/new-slsa-survey-reveals-real-world-developer-approaches-to-software-supply-chain-security>)

Published: 2023-03-15T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [openssf](<https://devfeed.tech/topics/openssf.md>)

Tags: [best-practices](<https://devfeed.tech/tags/best-practices.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [digital-signatures](<https://devfeed.tech/tags/digital-signatures.md>), [integrity](<https://devfeed.tech/tags/integrity.md>), [maintainers](<https://devfeed.tech/tags/maintainers.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [openssf](<https://devfeed.tech/tags/openssf.md>), [report](<https://devfeed.tech/tags/report.md>), [rust](<https://devfeed.tech/tags/rust.md>), [secure-software-development-frameworks](<https://devfeed.tech/tags/secure-software-development-frameworks.md>), [security](<https://devfeed.tech/tags/security.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [software-development](<https://devfeed.tech/tags/software-development.md>), [software-security-practices](<https://devfeed.tech/tags/software-security-practices.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [supply-chain-integrity](<https://devfeed.tech/tags/supply-chain-integrity.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [survey](<https://devfeed.tech/tags/survey.md>)

### AI overview

A joint survey by Chainguard, the Eclipse Foundation, the Rust Foundation, and OpenSSF examined how developers, open source maintainers, and security practitioners adopt software supply chain security practices. Among nearly 170 respondents, centralized build services showed relatively strong adoption, while consistently signing built artifacts was less common, with 25% reporting that their team always did so. Respondents generally considered the surveyed practices helpful.

### Source excerpt

Findings on software supply chain security practice adoption from our joint survey with OpenSSF, Rust, and Eclipse with questions derived from SLSA requirements.