# software signatures

Published articles for software signatures.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Celebrating innovation in open source software and container image security with Chainguard Images

DevFeed: [Celebrating innovation in open source software and container image security with Chainguard Images](<https://devfeed.tech/articles/celebrating-innovation-in-open-source-software-and-container-image-security-with-chainguard-images-12920.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/celebrating-innovation-in-open-source-software-and-container-image-security-with-chainguard-images>)

Published: 2023-11-01T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-image-security](<https://devfeed.tech/tags/container-image-security.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [fips](<https://devfeed.tech/tags/fips.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [software-signatures](<https://devfeed.tech/tags/software-signatures.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

Chainguard describes the growth of Chainguard Images as a secure container image offering for open source software development and software supply chain security. The article highlights more than one million image builds, over 90 million pulls, a large inventory of tools and applications, reduced CVEs, passwordless token-based authentication, SBOMs, and Sigstore-verified software signatures.

### Source excerpt

Explore the fusion of open source innovation and container security with Chainguard Images.

## Chainguard raises $61 million series B round as enterprises move to fortify open source software

DevFeed: [Chainguard raises $61 million series B round as enterprises move to fortify open source software](<https://devfeed.tech/articles/chainguard-raises-61-million-series-b-round-as-enterprises-move-to-fortify-open-source-software-12978.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-raises-61-million-series-b-round-as-enterprises-move-to-fortify-open-source-software>)

Published: 2023-11-01T00:00:00Z

Content type: news

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [funding](<https://devfeed.tech/tags/funding.md>), [fundraising](<https://devfeed.tech/tags/fundraising.md>), [safe-source-for-open-source](<https://devfeed.tech/tags/safe-source-for-open-source.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [secure-container-images](<https://devfeed.tech/tags/secure-container-images.md>), [series-b](<https://devfeed.tech/tags/series-b.md>), [software-signatures](<https://devfeed.tech/tags/software-signatures.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [spark-capital](<https://devfeed.tech/tags/spark-capital.md>)

### AI overview

Chainguard announced a $61 million Series B funding round led by Spark Capital, bringing total fundraising to $116 million. The company says its Chainguard Images solution is expanding among Fortune 500 companies and technology providers, with secure container images, vulnerability-status tracking, SBOMs, and software signatures.

### Source excerpt

Series B funding elevates Chainguard's capabilities in pioneering next-gen software security technologies.

## Securing the ML supply chain with new Chainguard AI Images

DevFeed: [Securing the ML supply chain with new Chainguard AI Images](<https://devfeed.tech/articles/securing-the-ml-supply-chain-with-new-chainguard-ai-images-13225.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/securing-the-ml-supply-chain-with-new-chainguard-ai-images>)

Published: 2023-08-24T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Machine learning](<https://devfeed.tech/topics/machine-learning.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-ai](<https://devfeed.tech/tags/chainguard-ai.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [conda-image](<https://devfeed.tech/tags/conda-image.md>), [cve-remediation](<https://devfeed.tech/tags/cve-remediation.md>), [kubeflow-image](<https://devfeed.tech/tags/kubeflow-image.md>), [ml-security](<https://devfeed.tech/tags/ml-security.md>), [ml-supply-chain](<https://devfeed.tech/tags/ml-supply-chain.md>), [open-ai-image](<https://devfeed.tech/tags/open-ai-image.md>), [openai-image](<https://devfeed.tech/tags/openai-image.md>), [python-image](<https://devfeed.tech/tags/python-image.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [secure-images](<https://devfeed.tech/tags/secure-images.md>), [security](<https://devfeed.tech/tags/security.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [software-signatures](<https://devfeed.tech/tags/software-signatures.md>)

### AI overview

Chainguard announces a Chainguard Images AI bundle for securing the ML supply chain across the AI workload lifecycle. The collection includes development, workflow management, deployment, and vector database images, with software signatures, SBOMs, and CVE remediation.

### Source excerpt

Chainguard AI Images: Your pathway to a secure ML supply chain with hardened, efficient AI/ML lifecycle solutions.

## Five Challenges of Verifying Container Signatures at Deployment Time in Kubernetes

DevFeed: [Five Challenges of Verifying Container Signatures at Deployment Time in Kubernetes](<https://devfeed.tech/articles/so-you-want-to-check-image-signatures-in-kubernetes-13235.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/so-you-want-to-check-image-signatures-in-kubernetes>)

Published: 2023-07-06T00:00:00Z

Content type: tutorial

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Security](<https://devfeed.tech/topics/security.md>), [Deployment](<https://devfeed.tech/topics/deployment.md>)

Tags: [admission-controller](<https://devfeed.tech/tags/admission-controller.md>), [container](<https://devfeed.tech/tags/container.md>), [container-image](<https://devfeed.tech/tags/container-image.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [policy-controller](<https://devfeed.tech/tags/policy-controller.md>), [security](<https://devfeed.tech/tags/security.md>), [security-policy-platform](<https://devfeed.tech/tags/security-policy-platform.md>), [signing](<https://devfeed.tech/tags/signing.md>), [signing-containers](<https://devfeed.tech/tags/signing-containers.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [sigstore-policy-controller](<https://devfeed.tech/tags/sigstore-policy-controller.md>), [software-signatures](<https://devfeed.tech/tags/software-signatures.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [webhooks](<https://devfeed.tech/tags/webhooks.md>)

### AI overview

This article explains five challenges involved in verifying container signatures during Kubernetes deployment. It focuses on admission webhooks, locating containers across resource types, handling ephemeral containers and custom resource definitions, and maintaining logic as Kubernetes APIs change.

### Source excerpt

Learn about five challenges you might encounter when trying to verify container signatures at deployment time in Kubernetes.

## Not all that's signed is secure: Verify the right way with TUF and Sigstore

DevFeed: [Not all that's signed is secure: Verify the right way with TUF and Sigstore](<https://devfeed.tech/articles/not-all-that-s-signed-is-secure-verify-the-right-way-with-tuf-and-sigstore-13189.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/not-all-thats-signed-is-secure-verify-the-right-way-with-tuf-and-sigstore>)

Published: 2023-02-08T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [sigstore](<https://devfeed.tech/topics/sigstore.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard enforce](<https://devfeed.tech/topics/chainguard-enforce.md>)

Tags: [chainguard-enforce](<https://devfeed.tech/tags/chainguard-enforce.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [policy](<https://devfeed.tech/tags/policy.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [signing](<https://devfeed.tech/tags/signing.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [software-signatures](<https://devfeed.tech/tags/software-signatures.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [supply-chain-attacks](<https://devfeed.tech/tags/supply-chain-attacks.md>), [verification](<https://devfeed.tech/tags/verification.md>)

### AI overview

The article summarizes a talk on using Sigstore and The Update Framework (TUF) to create verification policies for securing software supply chains. It explains that signing alone does not provide sufficient protection, because verifying the wrong way can leave systems vulnerable to supply chain attacks. It presents TUF as a way to build flexible verification policies and describes how Sigstore supports easier signing with rigorous verification.

### Source excerpt

CloudNativeSecurityCon: Marina Moore & Zack Newman on using Sigstore & The Update Framework TUF to create verification policies to secure software supply chains