# secure software supply chain

Published articles for secure software supply chain.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Chainguard Joins IBM PDE Factory to Advance Trusted Open Source Software for Public Sector Missions

DevFeed: [Chainguard Joins IBM PDE Factory to Advance Trusted Open Source Software for Public Sector Missions](<https://devfeed.tech/articles/chainguard-joins-ibm-pde-factory-to-advance-trusted-open-source-software-for-public-sector-missions-12965.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-joins-ibm-pde-factory-to-advance-trusted-open-source-software-for-public-sector-missions>)

Published: 2025-11-04T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [ibm](<https://devfeed.tech/topics/ibm.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-ibm-partnership](<https://devfeed.tech/tags/chainguard-ibm-partnership.md>), [chainguard-x-ibm](<https://devfeed.tech/tags/chainguard-x-ibm.md>), [containers](<https://devfeed.tech/tags/containers.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [government](<https://devfeed.tech/tags/government.md>), [ibm](<https://devfeed.tech/tags/ibm.md>), [ibm-containers](<https://devfeed.tech/tags/ibm-containers.md>), [ibm-factory](<https://devfeed.tech/tags/ibm-factory.md>), [ibm-pde-factory](<https://devfeed.tech/tags/ibm-pde-factory.md>), [modernization](<https://devfeed.tech/tags/modernization.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [public-sector](<https://devfeed.tech/tags/public-sector.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [secure-software-supply-chain](<https://devfeed.tech/tags/secure-software-supply-chain.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [zero-cve-containers](<https://devfeed.tech/tags/zero-cve-containers.md>)

### AI overview

Chainguard has joined IBM's PDE Factory, an open source-powered secure software development platform for government agencies and regulated enterprises. The integration provides access to Chainguard container images as agencies modernize while addressing security, compliance, and software supply chain requirements.

### Source excerpt

Chainguard joins IBM's PDE Factory to deliver secure, zero-CVE containers for government agencies, accelerating compliance, modernization, and innovation.

## Building a Secure Software Supply Chain: 5 Key Insights from GitLab's Field CTO

DevFeed: [Building a Secure Software Supply Chain: 5 Key Insights from GitLab's Field CTO](<https://devfeed.tech/articles/building-a-secure-software-supply-chain-5-key-insights-from-gitlab-s-field-cto-12902.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/building-a-secure-software-supply-chain-5-key-insights-from-gitlabs-field-cto>)

Published: 2025-08-08T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [GitLab](<https://devfeed.tech/topics/gitlab.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [toolchain](<https://devfeed.tech/topics/toolchain.md>), [Developer experience](<https://devfeed.tech/topics/developer-experience.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cto](<https://devfeed.tech/tags/cto.md>), [developer-experience](<https://devfeed.tech/tags/developer-experience.md>), [gitlab](<https://devfeed.tech/tags/gitlab.md>), [head-of-engineering](<https://devfeed.tech/tags/head-of-engineering.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [secure-software-supply-chain](<https://devfeed.tech/tags/secure-software-supply-chain.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [tooling](<https://devfeed.tech/tags/tooling.md>)

### AI overview

This article presents takeaways from a Chainguard webinar with GitLab Field CTO George Kichukov about building a secure software supply chain. It highlights the need to move from security awareness to action, reduce toolchain sprawl, embed security into developer workflows, and maintain transparency when using open source. The supplied text ends before the fifth takeaway is provided.

### Source excerpt

Chainguard and GitLab recently recorded a webinar discussing challenges organizations face in building a secure software supply chain. Get the key takeaways.

## Why Chainguard's Full-Stack Approach to Secure Software Supply Chain Is Built to Scale

DevFeed: [Why Chainguard's Full-Stack Approach to Secure Software Supply Chain Is Built to Scale](<https://devfeed.tech/articles/why-chainguard-s-full-stack-approach-to-secure-software-supply-chain-is-built-to-scale-13328.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/why-chainguards-full-stack-approach-to-secure-software-supply-chain-is-built-to-scale>)

Published: 2025-07-09T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard os](<https://devfeed.tech/topics/chainguard-os.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [automated](<https://devfeed.tech/tags/automated.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-factory](<https://devfeed.tech/tags/chainguard-factory.md>), [chainguard-os](<https://devfeed.tech/tags/chainguard-os.md>), [cve](<https://devfeed.tech/tags/cve.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [open-source-artifacts](<https://devfeed.tech/tags/open-source-artifacts.md>), [open-source-software-security](<https://devfeed.tech/tags/open-source-software-security.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [reproducibility](<https://devfeed.tech/tags/reproducibility.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [secure-software-supply-chain](<https://devfeed.tech/tags/secure-software-supply-chain.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>)

### AI overview

The article presents Chainguard's integrated approach to software supply chain security, combining Chainguard OS with the Chainguard Factory. It describes reproducible source builds, incremental updates, traceable contents, verifiable metadata, and automated maintenance of open source artifacts.

### Source excerpt

Learn how Chainguard OS and the Chainguard Factory delivers the only scalable path to secure, reliable software artifacts.

## Wolfi's approach to container security and CVE management

DevFeed: [Wolfi's approach to container security and CVE management](<https://devfeed.tech/articles/revolutionizing-container-security-and-cve-management-13213.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/revolutionizing-container-security-and-cve-management>)

Published: 2024-02-08T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [container-security](<https://devfeed.tech/topics/container-security.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [apko](<https://devfeed.tech/tags/apko.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-management](<https://devfeed.tech/tags/cve-management.md>), [melange](<https://devfeed.tech/tags/melange.md>), [oci](<https://devfeed.tech/tags/oci.md>), [secure-images](<https://devfeed.tech/tags/secure-images.md>), [secure-software-supply-chain](<https://devfeed.tech/tags/secure-software-supply-chain.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

The article explains how Wolfi, a secure-by-default undistro, supports container security by helping create minimal, reproducible OCI-compliant images and reducing software supply chain risks. It also describes how Wolfi powers Chainguard Images.

### Source excerpt

Discover Wolfi, the 'secure-by-default' undistro for container security, enhancing open-source software with minimal CVE counts and robust protection.

## Announcing Bazel rules for extending Chainguard Images

DevFeed: [Announcing Bazel rules for extending Chainguard Images](<https://devfeed.tech/articles/announcing-bazel-rules-for-extending-chainguard-images-12875.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/announcing-bazel-rules-for-extending-chainguard-images>)

Published: 2023-10-24T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [distroless](<https://devfeed.tech/topics/distroless.md>), [Package manager](<https://devfeed.tech/topics/package-manager.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [apk](<https://devfeed.tech/tags/apk.md>), [apko](<https://devfeed.tech/tags/apko.md>), [bazel](<https://devfeed.tech/tags/bazel.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [distroless](<https://devfeed.tech/tags/distroless.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [secure-software-supply-chain](<https://devfeed.tech/tags/secure-software-supply-chain.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Chainguard and Aspect.Dev announce the general availability of rules_apko, an open source Bazel plugin for building secure, minimal Wolfi-based OCI container images. The article explains how rules_apko integrates APK packages and Wolfi-base images into existing Bazel workflows, supports reproducible builds, and provides dependency locking, integrity verification, and SBOM generation.

### Source excerpt

Explore Bazel rules for Chainguard Images, your pathway to secure, effortless image extension.

## The role of attestations in a secure software supply chain

DevFeed: [The role of attestations in a secure software supply chain](<https://devfeed.tech/articles/the-role-of-attestations-in-a-secure-software-supply-chain-13269.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/the-role-of-attestations-in-a-secure-software-supply-chain>)

Published: 2023-04-04T00:00:00Z

Content type: tutorial

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard enforce](<https://devfeed.tech/topics/chainguard-enforce.md>), [Docker Verified Publisher](<https://devfeed.tech/topics/docker-verified-publisher.md>)

Tags: [attestation](<https://devfeed.tech/tags/attestation.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-enforce](<https://devfeed.tech/tags/chainguard-enforce.md>), [digital-signatures](<https://devfeed.tech/tags/digital-signatures.md>), [integrity](<https://devfeed.tech/tags/integrity.md>), [policy](<https://devfeed.tech/tags/policy.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [secure-software-supply-chain](<https://devfeed.tech/tags/secure-software-supply-chain.md>), [security-policies](<https://devfeed.tech/tags/security-policies.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [software-attestations](<https://devfeed.tech/tags/software-attestations.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>)

### AI overview

This article explains how attestations support software supply-chain policy enforcement. It describes attestations as signed claims from identified speakers about code or build results, allowing deployment systems to verify policy requirements without repeating expensive or impractical checks.

### Source excerpt

Chainguard Enforce enables policy enforcement using attestations. Learn how to use these principles to create and enforce secure supply chain policies.

## apko: a year later

DevFeed: [apko: a year later](<https://devfeed.tech/articles/apko-a-year-later-12887.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/apko-a-year-later>)

Published: 2023-02-28T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Development](<https://devfeed.tech/topics/development.md>), [Package manager](<https://devfeed.tech/topics/package-manager.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Unix](<https://devfeed.tech/topics/unix.md>), [YAML](<https://devfeed.tech/topics/yaml.md>), [Terraform](<https://devfeed.tech/topics/terraform.md>)

Tags: [alpine](<https://devfeed.tech/tags/alpine.md>), [apk](<https://devfeed.tech/tags/apk.md>), [apko](<https://devfeed.tech/tags/apko.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-enforce](<https://devfeed.tech/tags/chainguard-enforce.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [cloud-native](<https://devfeed.tech/tags/cloud-native.md>), [development](<https://devfeed.tech/tags/development.md>), [distroless](<https://devfeed.tech/tags/distroless.md>), [golang](<https://devfeed.tech/tags/golang.md>), [linux](<https://devfeed.tech/tags/linux.md>), [macos](<https://devfeed.tech/tags/macos.md>), [melange](<https://devfeed.tech/tags/melange.md>), [secure-software-supply-chain](<https://devfeed.tech/tags/secure-software-supply-chain.md>), [terraform-provider](<https://devfeed.tech/tags/terraform-provider.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>), [yaml](<https://devfeed.tech/tags/yaml.md>)

### AI overview

This article reviews apko one year after its public release. It describes apko's native Go implementation of the apk package manager, which runs on UNIX-like systems including macOS and BSDs, and explains how its declarative YAML interface helped support an ecosystem that includes Chainguard Images, Melange, Wolfi, and a Terraform provider. The article presents apko as a foundation for secure software supply chains through images-as-code and frequent image rebuilds.

### Source excerpt

Dive in to apko and learn more about the project; where it's been in the past year, and where it's going.