# software security practices

Published articles for software security practices.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Chainguard's image tagging philosophy: enabling high velocity updates (pt. 1 of 3)

DevFeed: [Chainguard's image tagging philosophy: enabling high velocity updates (pt. 1 of 3)](<https://devfeed.tech/articles/chainguard-s-image-tagging-philosophy-enabling-high-velocity-updates-pt-1-of-3-12988.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguards-image-tagging-philosophy-enabling-high-velocity-updates-pt-1-of-3>)

Published: 2023-11-13T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [releases](<https://devfeed.tech/topics/releases.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-image](<https://devfeed.tech/tags/container-image.md>), [cve](<https://devfeed.tech/tags/cve.md>), [distro](<https://devfeed.tech/tags/distro.md>), [dockerfiles](<https://devfeed.tech/tags/dockerfiles.md>), [github](<https://devfeed.tech/tags/github.md>), [image-tagging](<https://devfeed.tech/tags/image-tagging.md>), [series](<https://devfeed.tech/tags/series.md>), [software-security-practices](<https://devfeed.tech/tags/software-security-practices.md>), [velocity](<https://devfeed.tech/tags/velocity.md>)

### AI overview

Part 1 explains Chainguard's image-tagging philosophy for delivering fast updates while keeping image identities clear and usable. It describes epoch-based package revisions, vulnerability fixes, and how updates to packages within multi-package images can be delivered without changing the upstream version.

### Source excerpt

Explore Part 1 of Chainguard's image tagging philosophy series, focusing on enabling high-velocity updates.

## The principle of minimalism

DevFeed: [The principle of minimalism](<https://devfeed.tech/articles/the-principle-of-minimalism-13267.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/the-principle-of-minimalism>)

Published: 2023-06-22T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Access Control](<https://devfeed.tech/topics/access-control.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Docker](<https://devfeed.tech/topics/docker.md>), [systems](<https://devfeed.tech/topics/systems.md>)

Tags: [access-control](<https://devfeed.tech/tags/access-control.md>), [docker](<https://devfeed.tech/tags/docker.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [iam](<https://devfeed.tech/tags/iam.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [kubernetes-security](<https://devfeed.tech/tags/kubernetes-security.md>), [least-privilege](<https://devfeed.tech/tags/least-privilege.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [security](<https://devfeed.tech/tags/security.md>), [software-security-audit](<https://devfeed.tech/tags/software-security-audit.md>), [software-security-practices](<https://devfeed.tech/tags/software-security-practices.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [zero-trust-networking](<https://devfeed.tech/tags/zero-trust-networking.md>), [zero-trust-security](<https://devfeed.tech/tags/zero-trust-security.md>)

### AI overview

This engineering commentary argues that systems should use secure-by-default minimalism: defaults should expose only what users actually need, while deviations should be intentional and audited. It uses Docker and Kubernetes examples, including root containers, mutable deployment references, and secret handling, and introduces access-control applications such as non-root execution and minimal seccomp profiles.

### Source excerpt

Learn about the principle of minimalism in engineering, where your default should be the lowest-common denominator of what you actually need.

## ICYMI: What's new in Chainguard Academy

DevFeed: [ICYMI: What's new in Chainguard Academy](<https://devfeed.tech/articles/icymi-what-s-new-in-chainguard-academy-13099.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/icymi-whats-new-in-chainguard-academy>)

Published: 2023-04-03T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [openvex](<https://devfeed.tech/topics/openvex.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-academy](<https://devfeed.tech/tags/chainguard-academy.md>), [chainguard-enforce](<https://devfeed.tech/tags/chainguard-enforce.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [openvex](<https://devfeed.tech/tags/openvex.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [sigstore-policy-controller](<https://devfeed.tech/tags/sigstore-policy-controller.md>), [software-education](<https://devfeed.tech/tags/software-education.md>), [software-security-practices](<https://devfeed.tech/tags/software-security-practices.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Chainguard Academy has expanded to more than 300 tutorials, documentation pages, and reference materials covering open source projects and Chainguard products. The article highlights resources for Chainguard Images and Wolfi Images, OpenVEX, SBOMs, and Sigstore policy-controller.

### Source excerpt

See what's new in Chainguard Academy to help you level up your software supply chain and open source security knowledge.

## New SLSA++ Survey reveals real-world developer approaches to software supply chain security

DevFeed: [New SLSA++ Survey reveals real-world developer approaches to software supply chain security](<https://devfeed.tech/articles/new-slsa-survey-reveals-real-world-developer-approaches-to-software-supply-chain-security-13183.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/new-slsa-survey-reveals-real-world-developer-approaches-to-software-supply-chain-security>)

Published: 2023-03-15T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [openssf](<https://devfeed.tech/topics/openssf.md>)

Tags: [best-practices](<https://devfeed.tech/tags/best-practices.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [digital-signatures](<https://devfeed.tech/tags/digital-signatures.md>), [integrity](<https://devfeed.tech/tags/integrity.md>), [maintainers](<https://devfeed.tech/tags/maintainers.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [openssf](<https://devfeed.tech/tags/openssf.md>), [report](<https://devfeed.tech/tags/report.md>), [rust](<https://devfeed.tech/tags/rust.md>), [secure-software-development-frameworks](<https://devfeed.tech/tags/secure-software-development-frameworks.md>), [security](<https://devfeed.tech/tags/security.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [software-development](<https://devfeed.tech/tags/software-development.md>), [software-security-practices](<https://devfeed.tech/tags/software-security-practices.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [supply-chain-integrity](<https://devfeed.tech/tags/supply-chain-integrity.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [survey](<https://devfeed.tech/tags/survey.md>)

### AI overview

A joint survey by Chainguard, the Eclipse Foundation, the Rust Foundation, and OpenSSF examined how developers, open source maintainers, and security practitioners adopt software supply chain security practices. Among nearly 170 respondents, centralized build services showed relatively strong adoption, while consistently signing built artifacts was less common, with 25% reporting that their team always did so. Respondents generally considered the surveyed practices helpful.

### Source excerpt

Findings on software supply chain security practice adoption from our joint survey with OpenSSF, Rust, and Eclipse with questions derived from SLSA requirements.