# software supply chain security research

Published articles for software supply chain security research.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Can debloated containers pass the zero CVE test?

DevFeed: [Can debloated containers pass the zero CVE test?](<https://devfeed.tech/articles/can-debloated-containers-pass-the-zero-cve-test-12915.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/can-debloated-containers-pass-the-zero-cve-test>)

Published: 2023-11-20T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Containers](<https://devfeed.tech/topics/containers.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [grype](<https://devfeed.tech/topics/grype.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>)

Tags: [container-images](<https://devfeed.tech/tags/container-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cves](<https://devfeed.tech/tags/cves.md>), [grype](<https://devfeed.tech/tags/grype.md>), [hardened-images](<https://devfeed.tech/tags/hardened-images.md>), [hardening](<https://devfeed.tech/tags/hardening.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain-security-research](<https://devfeed.tech/tags/software-supply-chain-security-research.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

The article analyzes 28 debloated container images and finds that they reduce CVEs by an average of 64% compared with baseline images, but still contain an average of 33 CVEs. It also reports an average of five high or critical vulnerabilities, concluding that debloated containers do not pass the zero-CVE test. The comparison uses Grype and includes Chainguard Images versions.

### Source excerpt

Exploring the efficiency of debloated containers in the Zero CVE test: Chaingaurd's analysis of security and efficiency.

## New report shows disconnect between developers and security teams on software supply chain security priorities and responsibilities

DevFeed: [New report shows disconnect between developers and security teams on software supply chain security priorities and responsibilities](<https://devfeed.tech/articles/new-report-shows-disconnect-between-developers-and-security-teams-on-software-supply-chain-security-priorities-and-responsibilities-13182.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/new-report-shows-disconnect-between-developers-and-security-teams-on-software-supply-chain-security-priorities-and-responsibilities>)

Published: 2023-11-08T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Security](<https://devfeed.tech/topics/security.md>), [developer velocity](<https://devfeed.tech/topics/developer-velocity.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [ciso](<https://devfeed.tech/tags/ciso.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [developer-velocity](<https://devfeed.tech/tags/developer-velocity.md>), [developers](<https://devfeed.tech/tags/developers.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [report](<https://devfeed.tech/tags/report.md>), [security](<https://devfeed.tech/tags/security.md>), [software-developer](<https://devfeed.tech/tags/software-developer.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [software-supply-chain-security-research](<https://devfeed.tech/tags/software-supply-chain-security-research.md>), [survey](<https://devfeed.tech/tags/survey.md>)

### AI overview

Chainguard and The Harris Poll released a 2023 survey of CISOs and developers about software supply chain security. The report found that both groups consider it important but differ in their views of security awareness, responsibilities, tooling, and associated risks.

### Source excerpt

Chainguard's new report reveals a crucial gap between developers and security teams on software supply chain priorities.

## Good MLOps is good ML supply chain security

DevFeed: [Good MLOps is good ML supply chain security](<https://devfeed.tech/articles/good-mlops-is-good-ml-supply-chain-security-13070.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/good-mlops-is-good-ml-supply-chain-security>)

Published: 2023-07-25T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [MLOps](<https://devfeed.tech/topics/mlops.md>), [Security](<https://devfeed.tech/topics/security.md>), [AI, ML & Data Engineering](<https://devfeed.tech/topics/ai-ml-data-engineering.md>), [Software Engineering](<https://devfeed.tech/topics/software-engineering.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>)

Tags: [data](<https://devfeed.tech/tags/data.md>), [ml-ops](<https://devfeed.tech/tags/ml-ops.md>), [ml-security](<https://devfeed.tech/tags/ml-security.md>), [ml-supply-chain](<https://devfeed.tech/tags/ml-supply-chain.md>), [mlops](<https://devfeed.tech/tags/mlops.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [software-supply-chain-security-research](<https://devfeed.tech/tags/software-supply-chain-security-research.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [tensorflow](<https://devfeed.tech/tags/tensorflow.md>)

### AI overview

The article explains how MLOps and ML supply chain security share a common infrastructure philosophy. It identifies training data, data delivery, software dependencies, model code, training environments, build steps, and production deployment as parts of the machine learning supply chain whose security and correctness must be addressed together.

### Source excerpt

Uncover the symbiosis of good MLOps and ML supply chain security with Chainguard's expert insights.

## Introducing "Speranza": Enhancing software signing with privacy and usability

DevFeed: [Introducing "Speranza": Enhancing software signing with privacy and usability](<https://devfeed.tech/articles/introducing-speranza-enhancing-software-signing-with-privacy-and-usability-13121.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/introducing-speranza-enhancing-software-signing-with-privacy-and-usability>)

Published: 2023-05-30T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>), [OpenID connect (OIDC)](<https://devfeed.tech/topics/oidc.md>), [npm](<https://devfeed.tech/topics/npm.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-labs](<https://devfeed.tech/tags/chainguard-labs.md>), [cryptography](<https://devfeed.tech/tags/cryptography.md>), [digital-signatures](<https://devfeed.tech/tags/digital-signatures.md>), [oidc](<https://devfeed.tech/tags/oidc.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [pii](<https://devfeed.tech/tags/pii.md>), [privacy](<https://devfeed.tech/tags/privacy.md>), [security](<https://devfeed.tech/tags/security.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [software-artifact-signing](<https://devfeed.tech/tags/software-artifact-signing.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [software-supply-chain-security-research](<https://devfeed.tech/tags/software-supply-chain-security-research.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>)

### AI overview

Chainguard Labs introduces Speranza, a research project for usable, privacy-friendly software signing. The article explains how it aims to improve software supply chain security while addressing the usability problems of long-lived cryptographic keys and the privacy risks of exposing maintainers' identities or metadata. It also discusses potential applications in open source package repositories and enterprise deployments of Sigstore.

### Source excerpt

Chainguard Labs announces, "Speranza: Usable, privacy-friendly software signing," to help balance usability and privacy for software signing techniques.