# slsa

Published articles for slsa.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Proven, not promised: Chainguard Containers achieves SLSA Build Level 3

DevFeed: [Proven, not promised: Chainguard Containers achieves SLSA Build Level 3](<https://devfeed.tech/articles/proven-not-promised-chainguard-containers-achieves-slsa-build-level-3-13206.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/proven-not-promised-chainguard-containers-achieves-slsa-build-level-3>)

Published: 2026-08-17T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [software bill of materials](<https://devfeed.tech/topics/software-bill-of-materials.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [security](<https://devfeed.tech/tags/security.md>), [signing](<https://devfeed.tech/tags/signing.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>)

### AI overview

Chainguard says Coalfire independently assessed the Chainguard Containers build and release system as meeting SLSA Build Level 3 requirements. The article describes hardened, isolated builds, separately managed signing, provenance generation, and signed SBOMs for releases.

### Source excerpt

Coalfire independently assessed Chainguard Containers at SLSA Build Level 3, validating hardened builds, provenance, and supply chain integrity.

## ChainDrop npm Worm: Why SLSA Provenance Wasn't Enough

DevFeed: [ChainDrop npm Worm: Why SLSA Provenance Wasn't Enough](<https://devfeed.tech/articles/chaindrop-npm-worm-why-slsa-provenance-wasn-t-enough-13377.md>)

Original publisher: [Read original article](<https://www.harness.io/blog/chaindrop-npm-worm-valid-provenance>)

Author: Harness Team

Published: 2026-08-10T00:00:00Z

Content type: article

Language: en

Sources: [Harness Blog](<https://devfeed.tech/sources/harness-blog.md>)

Topics: [ChainDrop](<https://devfeed.tech/topics/chaindrop.md>), [npm](<https://devfeed.tech/topics/npm.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [npm packages](<https://devfeed.tech/topics/npm-packages.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [chaindrop](<https://devfeed.tech/tags/chaindrop.md>), [ci](<https://devfeed.tech/tags/ci.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [github](<https://devfeed.tech/tags/github.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [integrity](<https://devfeed.tech/tags/integrity.md>), [least-privilege](<https://devfeed.tech/tags/least-privilege.md>), [malware](<https://devfeed.tech/tags/malware.md>), [npm](<https://devfeed.tech/tags/npm.md>), [npm-worm](<https://devfeed.tech/tags/npm-worm.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [security](<https://devfeed.tech/tags/security.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [worm](<https://devfeed.tech/tags/worm.md>)

### AI overview

The ChainDrop npm worm compromised hundreds of packages while retaining valid SLSA provenance, demonstrating that build attestations do not guarantee source integrity. The article explains the worm's propagation, credential theft, persistence mechanisms, and recommended defenses, including source governance, dependency controls, least-privilege identities, policy gates, and runtime evidence.

### Source excerpt

ChainDrop poisoned hundreds of npm packages while retaining valid provenance. Learn why signed builds need source governance, policy gates, and runtime evidence | Blog

## Chainguard is named a Leader in the 2026 Gartner® Magic Quadrant™ for Software Supply Chain Security

DevFeed: [Chainguard is named a Leader in the 2026 Gartner® Magic Quadrant™ for Software Supply Chain Security](<https://devfeed.tech/articles/chainguard-is-named-a-leader-in-the-2026-gartner-magic-quadranttm-for-software-supply-chain-security-12961.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-is-named-a-leader-in-the-2026-gartner-magic-quadrant-for-software-supply-chain-security>)

Published: 2026-06-18T00:00:00Z

Content type: news

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-gartner](<https://devfeed.tech/tags/chainguard-gartner.md>), [chainguard-gartner-magic-quadrant](<https://devfeed.tech/tags/chainguard-gartner-magic-quadrant.md>), [cyber-resilience-act](<https://devfeed.tech/tags/cyber-resilience-act.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [gartner](<https://devfeed.tech/tags/gartner.md>), [gartner-mq-software-supply-chain](<https://devfeed.tech/tags/gartner-mq-software-supply-chain.md>), [nis2](<https://devfeed.tech/tags/nis2.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [security](<https://devfeed.tech/tags/security.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [software-supply-chain-security-gartner](<https://devfeed.tech/tags/software-supply-chain-security-gartner.md>)

### AI overview

Chainguard announces that it has been recognized as a Leader in the 2026 Gartner Magic Quadrant for Software Supply Chain Security. The article highlights Chainguard's secure-by-default approach, hardened open source artifacts, cryptographic signatures, signed SBOMs, and SLSA-aligned provenance, along with support for regulatory requirements.

### Source excerpt

Chainguard named a Leader in the 2026 Gartner® Magic Quadrant™ for Software Supply Chain Security, recognized for vision and secure-by-default innovation.

## Anchore Enterprise now validates Chainguard Libraries: prevent 98% of Python malware and eliminate high-severity CVE toil

DevFeed: [Anchore Enterprise now validates Chainguard Libraries: prevent 98% of Python malware and eliminate high-severity CVE toil](<https://devfeed.tech/articles/anchore-enterprise-now-validates-chainguard-libraries-prevent-98-of-python-malware-and-eliminate-high-severity-cve-toil-12872.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/anchore-enterprise-now-validates-chainguard-libraries>)

Published: 2025-12-04T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard libraries](<https://devfeed.tech/topics/chainguard-libraries.md>), [Python](<https://devfeed.tech/topics/python.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [anchore](<https://devfeed.tech/tags/anchore.md>), [anchore-chainguard](<https://devfeed.tech/tags/anchore-chainguard.md>), [anchore-chainguard-partnership](<https://devfeed.tech/tags/anchore-chainguard-partnership.md>), [anchore-enterprise](<https://devfeed.tech/tags/anchore-enterprise.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [chainguard-libraries-for-python](<https://devfeed.tech/tags/chainguard-libraries-for-python.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [malware](<https://devfeed.tech/tags/malware.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [python](<https://devfeed.tech/tags/python.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>)

### AI overview

Anchore Enterprise now supports scanning and validating Chainguard Libraries for Python. The integration combines Anchore's supply-chain security enforcement with Python libraries built from source in a tamper-proof, SLSA L2-certified environment with provenance and signed SBOMs, aiming to prevent malware introduced during build or distribution and reduce high-severity CVE remediation effort.

### Source excerpt

Customers can now leverage Anchore Enterprise's scanning capabilities for Chainguard Libraries for Python.

## Applying Zero Trust Principles to Open Source Software Supply Chain Security

DevFeed: [Applying Zero Trust Principles to Open Source Software Supply Chain Security](<https://devfeed.tech/articles/this-shit-is-hard-applying-zero-trust-to-open-source-software-13299.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/unchained-this-shit-is-hard-applying-zero-trust-to-open-source-software>)

Published: 2025-09-29T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Zero Trust](<https://devfeed.tech/topics/zero-trust.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Git](<https://devfeed.tech/topics/git.md>)

Tags: [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [chainguard-security](<https://devfeed.tech/tags/chainguard-security.md>), [git](<https://devfeed.tech/tags/git.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [security](<https://devfeed.tech/tags/security.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [this-shit-is-hard](<https://devfeed.tech/tags/this-shit-is-hard.md>), [zero-trust](<https://devfeed.tech/tags/zero-trust.md>)

### AI overview

This article explains how Chainguard applies Zero Trust principles to open source software supply chain security. It discusses weaknesses in Git identity and long-lived credentials, including risks from impersonation, credential theft, and compromised package publishing.

### Source excerpt

Chainguard implements Zero Trust principles into everything we do to protect critical infrastructure in the age of open source. See how we do it.

## Announcing Chainguard Libraries for JavaScript: Malware-Resistant Dependencies Built Securely from Source

DevFeed: [Announcing Chainguard Libraries for JavaScript: Malware-Resistant Dependencies Built Securely from Source](<https://devfeed.tech/articles/announcing-chainguard-libraries-for-javascript-malware-resistant-dependencies-built-securely-from-source-12879.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/announcing-chainguard-libraries-for-javascript-malware-resistant-dependencies-built-securely-from-source>)

Published: 2025-09-25T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard libraries](<https://devfeed.tech/topics/chainguard-libraries.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [npm packages](<https://devfeed.tech/topics/npm-packages.md>), [npm](<https://devfeed.tech/topics/npm.md>)

Tags: [attacks](<https://devfeed.tech/tags/attacks.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [chainguard-libraries-for-javascript](<https://devfeed.tech/tags/chainguard-libraries-for-javascript.md>), [javacript](<https://devfeed.tech/tags/javacript.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [language-library-security](<https://devfeed.tech/tags/language-library-security.md>), [malware](<https://devfeed.tech/tags/malware.md>), [npm](<https://devfeed.tech/tags/npm.md>), [npm-packages](<https://devfeed.tech/tags/npm-packages.md>), [package-compromise](<https://devfeed.tech/tags/package-compromise.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [shai-hulud](<https://devfeed.tech/tags/shai-hulud.md>), [slsa](<https://devfeed.tech/tags/slsa.md>)

### AI overview

Chainguard announces Chainguard Libraries for JavaScript, a source of trusted language-dependency builds intended to protect developers and organizations from compromised packages, malicious updates, and registry-based attacks. The libraries are built from source on hardened SLSA L2 infrastructure, include provenance, and are designed to fit existing developer workflows.

### Source excerpt

Chainguard Libraries for JavaScript is designed to protect developers and organizations from compromised packages, malicious updates, and registry-based attacks.

## Malware-Resistant Python without the Guesswork

DevFeed: [Malware-Resistant Python without the Guesswork](<https://devfeed.tech/articles/malware-resistant-python-without-the-guesswork-13146.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/malware-resistant-python-without-the-guesswork>)

Published: 2025-08-01T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard libraries for python](<https://devfeed.tech/topics/chainguard-libraries-for-python.md>), [chainguard libraries](<https://devfeed.tech/topics/chainguard-libraries.md>), [Security](<https://devfeed.tech/topics/security.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Malware](<https://devfeed.tech/topics/malware.md>)

Tags: [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [chainguard-libraries-for-python](<https://devfeed.tech/tags/chainguard-libraries-for-python.md>), [malicious-packages](<https://devfeed.tech/tags/malicious-packages.md>), [malware](<https://devfeed.tech/tags/malware.md>), [num2words](<https://devfeed.tech/tags/num2words.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [pypi](<https://devfeed.tech/tags/pypi.md>), [python](<https://devfeed.tech/tags/python.md>), [reproducibility](<https://devfeed.tech/tags/reproducibility.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [secure-packages](<https://devfeed.tech/tags/secure-packages.md>), [security](<https://devfeed.tech/tags/security.md>), [signing](<https://devfeed.tech/tags/signing.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>)

### AI overview

The article presents Chainguard Libraries for Python as a way to reduce malware and software supply chain risks in Python package consumption. It describes rebuilding packages from upstream source in an isolated, reproducible SLSA Level 2 environment, and publishing signed SBOMs and provenance information.

### Source excerpt

The recent compromise of the num2words package never made it into Chainguard Libraries for Python. Get the breakdown from the team on our packages you can trust.

## This Shit is Hard: SLSA L3 and Beyond

DevFeed: [This Shit is Hard: SLSA L3 and Beyond](<https://devfeed.tech/articles/this-shit-is-hard-slsa-l3-and-beyond-13288.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/this-shit-is-hard-slsa-l3-and-beyond>)

Published: 2025-07-31T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [containers](<https://devfeed.tech/tags/containers.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [security](<https://devfeed.tech/tags/security.md>), [security-engineering](<https://devfeed.tech/tags/security-engineering.md>), [signing](<https://devfeed.tech/tags/signing.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>)

### AI overview

Chainguard explains how it uses SLSA to strengthen software supply chain security, support customer compliance, and build trust in hardened container images. The article focuses on SLSA Build Level 3, especially isolated build execution and tamper-resistant provenance attestations with signing secrets separated from build and test processes.

### Source excerpt

Chainguard goes through all the necessary steps to make things SLSA 3 compliant. Get the details on how we do it.

## Google introduces OSS Rebuild for reproducible open-source package artifacts

DevFeed: [Google introduces OSS Rebuild for reproducible open-source package artifacts](<https://devfeed.tech/articles/introducing-oss-rebuild-open-source-rebuilt-to-last-19798.md>)

Original publisher: [Read original article](<http://security.googleblog.com/2025/07/introducing-oss-rebuild-open-source.html>)

Author: Kimberly Samra (noreply@blogger.com)

Published: 2025-07-21T21:34:00Z

Content type: release

Language: en

Sources: [Google Online Security](<https://devfeed.tech/sources/google-online-security.md>)

Topics: [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [supply chain attacks](<https://devfeed.tech/topics/supply-chain-attacks.md>), [npm](<https://devfeed.tech/topics/npm.md>), [PyPI](<https://devfeed.tech/topics/pypi.md>), [Rust](<https://devfeed.tech/topics/rust.md>)

Tags: [announce](<https://devfeed.tech/tags/announce.md>), [none](<https://devfeed.tech/tags/none.md>), [npm](<https://devfeed.tech/tags/npm.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [pypi](<https://devfeed.tech/tags/pypi.md>), [rust](<https://devfeed.tech/tags/rust.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [supply-chain-attacks](<https://devfeed.tech/tags/supply-chain-attacks.md>)

### AI overview

Google announced OSS Rebuild, a project that reproduces upstream package artifacts to provide build definitions, SLSA provenance, and verification tools for PyPI, npm, and Crates.io packages.

### Source excerpt

Posted by Matthew Suozzo, Google Open Source Security Team (GOSST) Today we're excited to announce OSS Rebuild, a new project to strengthen trust in open source package ecosystems by reproducing upstream artifacts. As supply chain attacks continue to target widely-used dependencies, OSS Rebuild gives security teams powerful data to avoid compromise without burden on upstream maintainers. The project comprises: Automation to derive declarative build definitions for existing PyPI (Python), npm (JS/TS), and Crates.io (Rust) packages. SLSA Provenance for thousands of packages across our supported ecosystems, meeting SLSA Build Level 3 requirements with no publisher intervention. Build observability and verification tools that security teams can integrate into their existing vulnerability management workflows. Infrastructure definitions to allow organizations to easily run their own instances of OSS Rebuild to rebuild, generate, sign, and distribute provenance. Challenges Open source software has become the foundation of our digital world. From critical infrastructure to everyday applications, OSS components now account for 77% of modern applications. With an estimated value exceeding $12 trillion, open source software has never been more integral to the global economy. Yet this very ubiquity makes open source an attractive target: Recent high-profile supply chain attacks have demonstrated sophisticated methods for compromising widely-used packages. Each incident erodes trust in open ecosystems, creating hesitation among both contributors and consumers. The security community has responded with initiatives like OpenSSF Scorecard, pypi's Trusted Publishers, and npm's native SLSA support. However, there is no panacea: Each effort targets a certain aspect of the problem, often making tradeoffs like shifting work onto publishers and maintainers. Our Aim Our aim with OSS Rebuild is to empower the security community to deeply understand and control their supply chains by makin

## Custom Assembly and Private APK Repositories are Now Generally Available

DevFeed: [Custom Assembly and Private APK Repositories are Now Generally Available](<https://devfeed.tech/articles/custom-assembly-and-private-apk-repositories-are-now-generally-available-13014.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/custom-assembly-and-private-apk-repositories-now-generally-available>)

Published: 2025-07-15T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [APK](<https://devfeed.tech/topics/apk.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [announce](<https://devfeed.tech/tags/announce.md>), [apk-repositories](<https://devfeed.tech/tags/apk-repositories.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [custom-assembly](<https://devfeed.tech/tags/custom-assembly.md>), [cve-remediation](<https://devfeed.tech/tags/cve-remediation.md>), [new-features](<https://devfeed.tech/tags/new-features.md>), [secure-image](<https://devfeed.tech/tags/secure-image.md>), [slsa](<https://devfeed.tech/tags/slsa.md>)

### AI overview

Chainguard announces the general availability of Custom Assembly and Private APK Repositories for Chainguard Containers. The features let customers customize container images, access Chainguard packages through customer-specific endpoints, and use Chainguard Factory for automated builds and ongoing maintenance.

### Source excerpt

Custom Assembly and Private APK Repositories, two new features for Chainguard Containers, are now generally available.

## No CVEs, No Surprises: Chainguard and the UK Software Security Code of Practice

DevFeed: [No CVEs, No Surprises: Chainguard and the UK Software Security Code of Practice](<https://devfeed.tech/articles/no-cves-no-surprises-chainguard-and-the-uk-software-security-code-of-practice-13187.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/no-cves-no-surprises-chainguard-and-the-uk-software-security-code-of-practice>)

Published: 2025-06-09T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [sdlc](<https://devfeed.tech/topics/sdlc.md>), [Development](<https://devfeed.tech/topics/development.md>), [Cloud Native Ecosystem](<https://devfeed.tech/topics/cloud-native-ecosystem.md>), [Resilience](<https://devfeed.tech/topics/resilience.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>), [Deployment](<https://devfeed.tech/topics/deployment.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [cyber-resilience-act](<https://devfeed.tech/tags/cyber-resilience-act.md>), [emea](<https://devfeed.tech/tags/emea.md>), [resilience](<https://devfeed.tech/tags/resilience.md>), [security](<https://devfeed.tech/tags/security.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [software-development](<https://devfeed.tech/tags/software-development.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [sscop](<https://devfeed.tech/tags/sscop.md>), [ssdf](<https://devfeed.tech/tags/ssdf.md>), [testing](<https://devfeed.tech/tags/testing.md>), [uk](<https://devfeed.tech/tags/uk.md>), [united-kingdom](<https://devfeed.tech/tags/united-kingdom.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

The article explains the United Kingdom's Software Security Code of Practice and maps its 14 principles across secure development, build integrity, deployment, and customer communication. It presents Chainguard Containers, provenance attestations, and signed SBOMs as ways Chainguard supports secure-by-default software and compliance efforts.

### Source excerpt

Chainguard Containers support compliance with the United Kingdom's Software Security Code of Practice. Check out what the framework entails and how we help.

## Chainguard's Catalog of 1,300+ Container Images: Secure Foundation for Every Engineering Team

DevFeed: [Chainguard's Catalog of 1,300+ Container Images: Secure Foundation for Every Engineering Team](<https://devfeed.tech/articles/chainguard-s-catalog-of-1-300-container-images-secure-foundation-for-every-engineering-team-12986.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguards-catalog-of-1-300-container-images-secure-foundation-for-every-engineering-team>)

Published: 2025-05-12T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [chainguard os](<https://devfeed.tech/topics/chainguard-os.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-catalog](<https://devfeed.tech/tags/chainguard-catalog.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-factory](<https://devfeed.tech/tags/chainguard-factory.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [chainguard-os](<https://devfeed.tech/tags/chainguard-os.md>), [container](<https://devfeed.tech/tags/container.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve-remediation](<https://devfeed.tech/tags/cve-remediation.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [safe-source-for-open-source](<https://devfeed.tech/tags/safe-source-for-open-source.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [slsa](<https://devfeed.tech/tags/slsa.md>)

### AI overview

Chainguard describes its catalog of more than 1,300 minimal, zero-CVE container images, built from source on Chainguard OS and maintained through the Chainguard Factory. The article highlights daily rebuilds, automated dependency and CVE handling, and default SBOMs, SLSA provenance, and Sigstore signatures.

### Source excerpt

Chainguard Containers is a catalog of over 1,300 container images powered by Chainguard OS and the Chainguard Factory. Discover the safe source for open source.

## Evaluating Container Security with Container Hardening Priorities: Some CHPs for Your SLSA

DevFeed: [Evaluating Container Security with Container Hardening Priorities: Some CHPs for Your SLSA](<https://devfeed.tech/articles/evaluating-container-security-with-container-hardening-priorities-some-chps-for-your-slsa-13031.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/evaluating-container-security-with-container-hardening-priorities-some-chps-for-your-slsa>)

Published: 2025-04-03T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [container-security](<https://devfeed.tech/topics/container-security.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [best-practices](<https://devfeed.tech/tags/best-practices.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [chps](<https://devfeed.tech/tags/chps.md>), [configuration](<https://devfeed.tech/tags/configuration.md>), [container-hardening-priorities](<https://devfeed.tech/tags/container-hardening-priorities.md>), [container-image](<https://devfeed.tech/tags/container-image.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [hardening](<https://devfeed.tech/tags/hardening.md>), [minimalism](<https://devfeed.tech/tags/minimalism.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [security](<https://devfeed.tech/tags/security.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [standard](<https://devfeed.tech/tags/standard.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Chainguard introduces Container Hardening Priorities (CHPs), a framework for assessing container image security. CHPs complements SLSA and focuses initially on build-time characteristics including minimalism, provenance, configuration and metadata, and vulnerabilities.

### Source excerpt

Chainguard has announced Container Hardening Priorities (CHPs), a new framework to assess the security of container images. Learn how it works.

## Announcing Chainguard Libraries: Guarded Java Language Dependencies Built from Source

DevFeed: [Announcing Chainguard Libraries: Guarded Java Language Dependencies Built from Source](<https://devfeed.tech/articles/announcing-chainguard-libraries-guarded-java-language-dependencies-built-from-source-12881.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/announcing-chainguard-libraries-guarded-java-language-dependencies-built-from-source>)

Published: 2025-03-25T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard libraries](<https://devfeed.tech/topics/chainguard-libraries.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Java](<https://devfeed.tech/topics/java.md>)

Tags: [built-from-source](<https://devfeed.tech/tags/built-from-source.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [java](<https://devfeed.tech/tags/java.md>), [packages](<https://devfeed.tech/tags/packages.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [supply-chain-attacks](<https://devfeed.tech/tags/supply-chain-attacks.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>)

### AI overview

Chainguard announces the beta release of Chainguard Libraries, a catalog of guarded Java dependencies built from source in SLSA-certified infrastructure. The service aims to give enterprises a standardized, safer way to consume language libraries while preserving existing developer workflows.

### Source excerpt

Chainguard Libraries is a catalog of guarded Java dependencies built securely from source in Chainguard's SLSA-certified infrastructure.

## Announcing Chainguard Custom Assembly: Image Customization Without Complexity

DevFeed: [Announcing Chainguard Custom Assembly: Image Customization Without Complexity](<https://devfeed.tech/articles/announcing-chainguard-custom-assembly-image-customization-without-complexity-12877.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/announcing-chainguard-custom-assembly-image-customization-without-complexity>)

Published: 2025-02-20T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Security](<https://devfeed.tech/topics/security.md>), [Development](<https://devfeed.tech/topics/development.md>)

Tags: [bash](<https://devfeed.tech/tags/bash.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-custom-assembly](<https://devfeed.tech/tags/chainguard-custom-assembly.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [complexity](<https://devfeed.tech/tags/complexity.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [curl](<https://devfeed.tech/tags/curl.md>), [custom-assembly](<https://devfeed.tech/tags/custom-assembly.md>), [customization](<https://devfeed.tech/tags/customization.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-remediation](<https://devfeed.tech/tags/cve-remediation.md>), [development](<https://devfeed.tech/tags/development.md>), [docker](<https://devfeed.tech/tags/docker.md>), [image](<https://devfeed.tech/tags/image.md>), [integrity](<https://devfeed.tech/tags/integrity.md>), [maintenance](<https://devfeed.tech/tags/maintenance.md>), [no-vulnerabilities](<https://devfeed.tech/tags/no-vulnerabilities.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [security](<https://devfeed.tech/tags/security.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

Chainguard announces the beta release of Custom Assembly, a product for tailoring Chainguard Images with required packages while preserving hardened builds, security practices, and CVE remediation coverage. The article explains that the product addresses complex, maintenance-heavy customization workflows involving manual image changes, Docker builds, and proprietary pipelines.

### Source excerpt

Custom Assembly is Chainguard's new image customization product that enables companies to consume zero-CVE open source software tailored to unique requirements.

## Chainguard Images Are Now Available for Government of Canada Organizations

DevFeed: [Chainguard Images Are Now Available for Government of Canada Organizations](<https://devfeed.tech/articles/chainguard-images-are-now-available-for-government-of-canada-organizations-12956.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-images-now-available-for-government-of-canada-organizations>)

Published: 2025-01-27T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>)

Tags: [canada](<https://devfeed.tech/tags/canada.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [government](<https://devfeed.tech/tags/government.md>), [government-of-canada](<https://devfeed.tech/tags/government-of-canada.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [software-licensing-supply-arrangement](<https://devfeed.tech/tags/software-licensing-supply-arrangement.md>)

### AI overview

Chainguard Images are now available for purchase by Government of Canada organizations through a Software Licensing Supply Arrangement with Carahsoft. The article explains how the arrangement supports procurement of Chainguard's zero-CVE Guarded Container Images and relates their security benefits to the Government of Canada's cybersecurity strategy.

### Source excerpt

Chainguard Images are now available for purchase by Government of Canada organizations thanks to our Software Licensing Supply Arrangement with Carahsoft.

## Check out Chainguard at KubeCon NA in Salt Lake City on November 12-15!

DevFeed: [Check out Chainguard at KubeCon NA in Salt Lake City on November 12-15!](<https://devfeed.tech/articles/check-out-chainguard-at-kubecon-na-in-salt-lake-city-on-november-12-15-13006.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/check-out-chainguard-at-kubecon-na-in-salt-lake-city-on-november-12-15>)

Published: 2024-10-16T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>), [distroless](<https://devfeed.tech/topics/distroless.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Security](<https://devfeed.tech/topics/security.md>), [devrel](<https://devfeed.tech/topics/devrel.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cloud-native-rejekts](<https://devfeed.tech/tags/cloud-native-rejekts.md>), [conference](<https://devfeed.tech/tags/conference.md>), [container](<https://devfeed.tech/tags/container.md>), [debug](<https://devfeed.tech/tags/debug.md>), [developers](<https://devfeed.tech/tags/developers.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [distroless](<https://devfeed.tech/tags/distroless.md>), [event](<https://devfeed.tech/tags/event.md>), [kubecon](<https://devfeed.tech/tags/kubecon.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [multi-arch](<https://devfeed.tech/tags/multi-arch.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [security](<https://devfeed.tech/tags/security.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [sigstorecon](<https://devfeed.tech/tags/sigstorecon.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>)

### AI overview

Chainguard announces its participation in KubeCon North America 2024 in Salt Lake City, including product demonstrations of Chainguard Images and appearances at Cloud-Native Rejekts and SigstoreCon.

### Source excerpt

Chainguard is going to be at KubeCon North America 2024 in Salt Lake City. See where we'll be and how you can meet us to learn more about Chainguard Images.

## Introducing Chainguard's Trust Center

DevFeed: [Introducing Chainguard's Trust Center](<https://devfeed.tech/articles/introducing-chainguard-s-trust-center-13114.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/introducing-chainguards-trust-center>)

Published: 2024-05-14T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Security](<https://devfeed.tech/topics/security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [soc 2](<https://devfeed.tech/topics/soc-2.md>)

Tags: [audit](<https://devfeed.tech/tags/audit.md>), [certifications](<https://devfeed.tech/tags/certifications.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [iso-27001](<https://devfeed.tech/tags/iso-27001.md>), [nist](<https://devfeed.tech/tags/nist.md>), [security](<https://devfeed.tech/tags/security.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [soc](<https://devfeed.tech/tags/soc.md>), [soc2](<https://devfeed.tech/tags/soc2.md>), [software-security-audit](<https://devfeed.tech/tags/software-security-audit.md>), [software-security-best-practices](<https://devfeed.tech/tags/software-security-best-practices.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [trust-center](<https://devfeed.tech/tags/trust-center.md>)

### AI overview

Chainguard introduces its Trust Center, a platform that centralizes security, compliance, and privacy information for users and customers. The center provides access to independent penetration-testing assessments, a SOC 2 Type 2 audit report, hardening guidance, privacy information, data-subprocessor details, and information security policies.

### Source excerpt

Learn how Chainguard prioritizes security with our new Trust Center. Find info on our policies, certifications, and how we protect your software supply chain.

## Strengthening your software supply chain security

DevFeed: [Strengthening your software supply chain security](<https://devfeed.tech/articles/strengthening-your-software-supply-chain-security-13242.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/strengthening-your-software-supply-chain-security>)

Published: 2024-01-08T00:00:00Z

Content type: tutorial

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Software](<https://devfeed.tech/topics/software.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>), [snyk](<https://devfeed.tech/topics/snyk.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cve](<https://devfeed.tech/tags/cve.md>), [dependency](<https://devfeed.tech/tags/dependency.md>), [grype](<https://devfeed.tech/tags/grype.md>), [image](<https://devfeed.tech/tags/image.md>), [reproducible-builds](<https://devfeed.tech/tags/reproducible-builds.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [security](<https://devfeed.tech/tags/security.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [software](<https://devfeed.tech/tags/software.md>), [solarwinds](<https://devfeed.tech/tags/solarwinds.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

This article explains software supply chain risks from open-source and third-party components, using the SolarWinds attack as an example. It recommends verifying artifacts, signing container images, minimizing dependencies, updating software, scanning for vulnerabilities, using smaller base images, adopting reproducible builds, and increasing SLSA maturity.

### Source excerpt

Secure your codebase with advanced supply chain security tactics: artifact authentication, minimal images and more from Chainguard.

## Elastic partners with Chainguard on Software Supply Chain security and SLSA assessment

DevFeed: [Elastic partners with Chainguard on Software Supply Chain security and SLSA assessment](<https://devfeed.tech/articles/elastic-partners-with-chainguard-on-software-supply-chain-security-and-slsa-assessment-13026.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/elastic-partners-with-chainguard-on-software-supply-chain-security-and-slsa-assessment>)

Published: 2023-07-26T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Security](<https://devfeed.tech/topics/security.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [security](<https://devfeed.tech/tags/security.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [slsa-assessement](<https://devfeed.tech/tags/slsa-assessement.md>), [slsa-levels](<https://devfeed.tech/tags/slsa-levels.md>), [software-artifact-signing](<https://devfeed.tech/tags/software-artifact-signing.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [trust](<https://devfeed.tech/tags/trust.md>)

### AI overview

Elastic partnered with Chainguard to assess its software supply chain using the SLSA framework. The article describes supply-chain risks across source, build, dependencies, and packages, and highlights software artifact signing with Sigstore as a security measure.

### Source excerpt

Elastic and Chainguard unite for enhanced software supply chain security and SLSA assessment.

## Strengthening CI/CD Environments: Insights from NSA and DHS CISA guidance

DevFeed: [Strengthening CI/CD Environments: Insights from NSA and DHS CISA guidance](<https://devfeed.tech/articles/strengthening-ci-cd-environments-insights-from-nsa-and-dhs-cisa-guidance-13241.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/strengthening-ci-cd-environments-insights-from-nsa-and-dhs-cisa-guidance>)

Published: 2023-06-30T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [CI/CD](<https://devfeed.tech/topics/cicd.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [DevSecOps](<https://devfeed.tech/topics/devsecops.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [cisa](<https://devfeed.tech/topics/cisa.md>)

Tags: [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [cicd](<https://devfeed.tech/tags/cicd.md>), [cisa](<https://devfeed.tech/tags/cisa.md>), [continuous-verification](<https://devfeed.tech/tags/continuous-verification.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [secure-software-development-frameworks](<https://devfeed.tech/tags/secure-software-development-frameworks.md>), [security](<https://devfeed.tech/tags/security.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [ssdf](<https://devfeed.tech/tags/ssdf.md>)

### AI overview

This commentary explains NSA and DHS CISA guidance for securing CI/CD environments. It highlights risks to downstream environments and software consumers, including compromised developer credentials and application libraries, and recommends established software supply chain security frameworks such as SLSA and CNCF best practices.

### Source excerpt

Fortify your CI/CD environments with insights from NSA and DHS CISA guidance, presented by Chainguard.

## An enhanced Chainguard Academy learning experience

DevFeed: [An enhanced Chainguard Academy learning experience](<https://devfeed.tech/articles/an-enhanced-chainguard-academy-learning-experience-12869.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/an-enhanced-chainguard-academy-learning-experience>)

Published: 2023-06-22T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Learning](<https://devfeed.tech/topics/learning.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Documentation](<https://devfeed.tech/topics/documentation.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-academy](<https://devfeed.tech/tags/chainguard-academy.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [security](<https://devfeed.tech/tags/security.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [slsa-levels](<https://devfeed.tech/tags/slsa-levels.md>), [software-education](<https://devfeed.tech/tags/software-education.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [ssdf](<https://devfeed.tech/tags/ssdf.md>)

### AI overview

Chainguard announces an enhanced Chainguard Academy with a redesigned user experience, improved navigation, topic pages, and expanded educational resources covering software security, software supply chain security, SLSA, SSDF, SBOMs, apko, and Wolfi. The article also highlights ongoing product documentation updates for Chainguard Images and Chainguard Enforce.

### Source excerpt

Catch the latest updates from Chainguard Academy, including a new design and software security resources for SLSA, SSDF and more.

## OSS security: Chainguard May 2023 update

DevFeed: [OSS security: Chainguard May 2023 update](<https://devfeed.tech/articles/oss-security-chainguard-may-2023-update-13198.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/oss-security-chainguard-may-2023-update>)

Published: 2023-05-22T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [openssf](<https://devfeed.tech/tags/openssf.md>), [oss](<https://devfeed.tech/tags/oss.md>), [security](<https://devfeed.tech/tags/security.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Chainguard's May 2023 update recaps open-source software security community activity, including talks and events, work on the Kubernetes 1.27 release, and the announcement of SLSA 1.0.

### Source excerpt

Read the latest announcements in open source software security this spring including SLSA 1.0, Sigstore + npm, OpenVEX had its kickoff meeting, and more!

## Chainguard and CNCF conduct SLSA assessments for Argo and Prometheus projects

DevFeed: [Chainguard and CNCF conduct SLSA assessments for Argo and Prometheus projects](<https://devfeed.tech/articles/chainguard-and-cncf-conduct-slsa-assessments-for-argo-and-prometheus-projects-12923.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-and-cncf-conduct-slsa-assessments-for-argo-and-prometheus-projects>)

Published: 2023-04-19T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Prometheus](<https://devfeed.tech/topics/prometheus.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Security](<https://devfeed.tech/topics/security.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>)

Tags: [argo](<https://devfeed.tech/tags/argo.md>), [argo-cd](<https://devfeed.tech/tags/argo-cd.md>), [audits](<https://devfeed.tech/tags/audits.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [cncf](<https://devfeed.tech/tags/cncf.md>), [github](<https://devfeed.tech/tags/github.md>), [maintainers](<https://devfeed.tech/tags/maintainers.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [prometheus](<https://devfeed.tech/tags/prometheus.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [security](<https://devfeed.tech/tags/security.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [slsa-levels](<https://devfeed.tech/tags/slsa-levels.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [supply-chain-integrity](<https://devfeed.tech/tags/supply-chain-integrity.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>)

### AI overview

Chainguard and CNCF assessed the software supply chain security of the Argo CD and Prometheus projects using the SLSA framework. Argo CD achieved SLSA Level 3 for source, build, and provenance, while Prometheus achieved Level 3 for source and build; the assessment recommended adding provenance generation to Prometheus build infrastructure.

### Source excerpt

Chainguard and the CNCF partnered to conduct security assessments of Argo and Prometheus to ensure open source software projects apply security best practices.

[Next page](<https://devfeed.tech/tags/slsa.md?cursor=WyIyMDIzLTA0LTE5VDAwOjAwOjAwKzAwOjAwIiwgImZjOTU0Nzc3LTk4NTUtNDY5ZS1iZTc2LTBmNjM4NmI5OWMwYyJd>)