# software security audit

Published articles for software security audit.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Introducing Chainguard's Trust Center

DevFeed: [Introducing Chainguard's Trust Center](<https://devfeed.tech/articles/introducing-chainguard-s-trust-center-13114.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/introducing-chainguards-trust-center>)

Published: 2024-05-14T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Security](<https://devfeed.tech/topics/security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [soc 2](<https://devfeed.tech/topics/soc-2.md>)

Tags: [audit](<https://devfeed.tech/tags/audit.md>), [certifications](<https://devfeed.tech/tags/certifications.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [iso-27001](<https://devfeed.tech/tags/iso-27001.md>), [nist](<https://devfeed.tech/tags/nist.md>), [security](<https://devfeed.tech/tags/security.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [soc](<https://devfeed.tech/tags/soc.md>), [soc2](<https://devfeed.tech/tags/soc2.md>), [software-security-audit](<https://devfeed.tech/tags/software-security-audit.md>), [software-security-best-practices](<https://devfeed.tech/tags/software-security-best-practices.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [trust-center](<https://devfeed.tech/tags/trust-center.md>)

### AI overview

Chainguard introduces its Trust Center, a platform that centralizes security, compliance, and privacy information for users and customers. The center provides access to independent penetration-testing assessments, a SOC 2 Type 2 audit report, hardening guidance, privacy information, data-subprocessor details, and information security policies.

### Source excerpt

Learn how Chainguard prioritizes security with our new Trust Center. Find info on our policies, certifications, and how we protect your software supply chain.

## Chainguard's Trail of Bits security assessment

DevFeed: [Chainguard's Trail of Bits security assessment](<https://devfeed.tech/articles/chainguard-s-trail-of-bits-security-assessment-12997.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguards-trail-of-bits-security-assessment>)

Published: 2024-05-14T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [Code review](<https://devfeed.tech/topics/code-review.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [code-review](<https://devfeed.tech/tags/code-review.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [github-credentials](<https://devfeed.tech/tags/github-credentials.md>), [github-pat](<https://devfeed.tech/tags/github-pat.md>), [least-privilege](<https://devfeed.tech/tags/least-privilege.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [octo-sts](<https://devfeed.tech/tags/octo-sts.md>), [security](<https://devfeed.tech/tags/security.md>), [software-security-audit](<https://devfeed.tech/tags/software-security-audit.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>)

### AI overview

Chainguard describes an independent Trail of Bits security assessment of its production environment and supply-chain defenses. The assessment found no critical issues, but identified command injection in a GitHub Action and insufficient redaction of sensitive CloudEvents; Chainguard reports that both issues were fixed. The article also outlines security improvements involving GitHub credentials, GitHub Actions monitoring, FIDO security keys, anomaly monitoring, and production-network alerts.

### Source excerpt

Trust but verify: Read about Chainguard's independent security assessment by Trail of Bits and our dedication to transparency in security practices.

## What every CISO should know about the new SSDF security self-attestation form

DevFeed: [What every CISO should know about the new SSDF security self-attestation form](<https://devfeed.tech/articles/what-every-ciso-should-know-about-the-new-ssdf-security-self-attestation-form-13316.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/what-every-ciso-should-know-about-the-new-ssdf-security-self-attestation-form>)

Published: 2023-08-08T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [cisa](<https://devfeed.tech/topics/cisa.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [cisa](<https://devfeed.tech/tags/cisa.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [regulatory](<https://devfeed.tech/tags/regulatory.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [secure-software-development-frameworks](<https://devfeed.tech/tags/secure-software-development-frameworks.md>), [self-attestation](<https://devfeed.tech/tags/self-attestation.md>), [software-security-audit](<https://devfeed.tech/tags/software-security-audit.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [ssdf](<https://devfeed.tech/tags/ssdf.md>), [standards](<https://devfeed.tech/tags/standards.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

This joint blog post explains a proposed Secure Software Self-Attestation Form published by CISA and its implications for CISOs. It describes how organizations selling software for government use may need to attest to their best efforts to follow NIST's Secure Software Development Framework, while highlighting related software supply chain security practices and regulatory developments.

### Source excerpt

Explore the pivotal SSDF Security Self-Attestation Form, a key resource for CISOs to navigate and enhance security compliance.

## The principle of minimalism

DevFeed: [The principle of minimalism](<https://devfeed.tech/articles/the-principle-of-minimalism-13267.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/the-principle-of-minimalism>)

Published: 2023-06-22T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Access Control](<https://devfeed.tech/topics/access-control.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Docker](<https://devfeed.tech/topics/docker.md>), [systems](<https://devfeed.tech/topics/systems.md>)

Tags: [access-control](<https://devfeed.tech/tags/access-control.md>), [docker](<https://devfeed.tech/tags/docker.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [iam](<https://devfeed.tech/tags/iam.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [kubernetes-security](<https://devfeed.tech/tags/kubernetes-security.md>), [least-privilege](<https://devfeed.tech/tags/least-privilege.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [security](<https://devfeed.tech/tags/security.md>), [software-security-audit](<https://devfeed.tech/tags/software-security-audit.md>), [software-security-practices](<https://devfeed.tech/tags/software-security-practices.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [zero-trust-networking](<https://devfeed.tech/tags/zero-trust-networking.md>), [zero-trust-security](<https://devfeed.tech/tags/zero-trust-security.md>)

### AI overview

This engineering commentary argues that systems should use secure-by-default minimalism: defaults should expose only what users actually need, while deviations should be intentional and audited. It uses Docker and Kubernetes examples, including root containers, mutable deployment references, and secret handling, and introduces access-control applications such as non-root execution and minimal seccomp profiles.

### Source excerpt

Learn about the principle of minimalism in engineering, where your default should be the lowest-common denominator of what you actually need.