# ssdf

Published articles for ssdf.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## No CVEs, No Surprises: Chainguard and the UK Software Security Code of Practice

DevFeed: [No CVEs, No Surprises: Chainguard and the UK Software Security Code of Practice](<https://devfeed.tech/articles/no-cves-no-surprises-chainguard-and-the-uk-software-security-code-of-practice-13187.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/no-cves-no-surprises-chainguard-and-the-uk-software-security-code-of-practice>)

Published: 2025-06-09T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [sdlc](<https://devfeed.tech/topics/sdlc.md>), [Development](<https://devfeed.tech/topics/development.md>), [Cloud Native Ecosystem](<https://devfeed.tech/topics/cloud-native-ecosystem.md>), [Resilience](<https://devfeed.tech/topics/resilience.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>), [Deployment](<https://devfeed.tech/topics/deployment.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [cyber-resilience-act](<https://devfeed.tech/tags/cyber-resilience-act.md>), [emea](<https://devfeed.tech/tags/emea.md>), [resilience](<https://devfeed.tech/tags/resilience.md>), [security](<https://devfeed.tech/tags/security.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [software-development](<https://devfeed.tech/tags/software-development.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [sscop](<https://devfeed.tech/tags/sscop.md>), [ssdf](<https://devfeed.tech/tags/ssdf.md>), [testing](<https://devfeed.tech/tags/testing.md>), [uk](<https://devfeed.tech/tags/uk.md>), [united-kingdom](<https://devfeed.tech/tags/united-kingdom.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

The article explains the United Kingdom's Software Security Code of Practice and maps its 14 principles across secure development, build integrity, deployment, and customer communication. It presents Chainguard Containers, provenance attestations, and signed SBOMs as ways Chainguard supports secure-by-default software and compliance efforts.

### Source excerpt

Chainguard Containers support compliance with the United Kingdom's Software Security Code of Practice. Check out what the framework entails and how we help.

## What every CISO should know about the new SSDF security self-attestation form

DevFeed: [What every CISO should know about the new SSDF security self-attestation form](<https://devfeed.tech/articles/what-every-ciso-should-know-about-the-new-ssdf-security-self-attestation-form-13316.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/what-every-ciso-should-know-about-the-new-ssdf-security-self-attestation-form>)

Published: 2023-08-08T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [cisa](<https://devfeed.tech/topics/cisa.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [cisa](<https://devfeed.tech/tags/cisa.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [regulatory](<https://devfeed.tech/tags/regulatory.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [secure-software-development-frameworks](<https://devfeed.tech/tags/secure-software-development-frameworks.md>), [self-attestation](<https://devfeed.tech/tags/self-attestation.md>), [software-security-audit](<https://devfeed.tech/tags/software-security-audit.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [ssdf](<https://devfeed.tech/tags/ssdf.md>), [standards](<https://devfeed.tech/tags/standards.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

This joint blog post explains a proposed Secure Software Self-Attestation Form published by CISA and its implications for CISOs. It describes how organizations selling software for government use may need to attest to their best efforts to follow NIST's Secure Software Development Framework, while highlighting related software supply chain security practices and regulatory developments.

### Source excerpt

Explore the pivotal SSDF Security Self-Attestation Form, a key resource for CISOs to navigate and enhance security compliance.

## Strengthening CI/CD Environments: Insights from NSA and DHS CISA guidance

DevFeed: [Strengthening CI/CD Environments: Insights from NSA and DHS CISA guidance](<https://devfeed.tech/articles/strengthening-ci-cd-environments-insights-from-nsa-and-dhs-cisa-guidance-13241.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/strengthening-ci-cd-environments-insights-from-nsa-and-dhs-cisa-guidance>)

Published: 2023-06-30T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [CI/CD](<https://devfeed.tech/topics/cicd.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [DevSecOps](<https://devfeed.tech/topics/devsecops.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [cisa](<https://devfeed.tech/topics/cisa.md>)

Tags: [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [cicd](<https://devfeed.tech/tags/cicd.md>), [cisa](<https://devfeed.tech/tags/cisa.md>), [continuous-verification](<https://devfeed.tech/tags/continuous-verification.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [secure-software-development-frameworks](<https://devfeed.tech/tags/secure-software-development-frameworks.md>), [security](<https://devfeed.tech/tags/security.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [ssdf](<https://devfeed.tech/tags/ssdf.md>)

### AI overview

This commentary explains NSA and DHS CISA guidance for securing CI/CD environments. It highlights risks to downstream environments and software consumers, including compromised developer credentials and application libraries, and recommends established software supply chain security frameworks such as SLSA and CNCF best practices.

### Source excerpt

Fortify your CI/CD environments with insights from NSA and DHS CISA guidance, presented by Chainguard.

## An enhanced Chainguard Academy learning experience

DevFeed: [An enhanced Chainguard Academy learning experience](<https://devfeed.tech/articles/an-enhanced-chainguard-academy-learning-experience-12869.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/an-enhanced-chainguard-academy-learning-experience>)

Published: 2023-06-22T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Learning](<https://devfeed.tech/topics/learning.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Documentation](<https://devfeed.tech/topics/documentation.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-academy](<https://devfeed.tech/tags/chainguard-academy.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [security](<https://devfeed.tech/tags/security.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [slsa-levels](<https://devfeed.tech/tags/slsa-levels.md>), [software-education](<https://devfeed.tech/tags/software-education.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [ssdf](<https://devfeed.tech/tags/ssdf.md>)

### AI overview

Chainguard announces an enhanced Chainguard Academy with a redesigned user experience, improved navigation, topic pages, and expanded educational resources covering software security, software supply chain security, SLSA, SSDF, SBOMs, apko, and Wolfi. The article also highlights ongoing product documentation updates for Chainguard Images and Chainguard Enforce.

### Source excerpt

Catch the latest updates from Chainguard Academy, including a new design and software security resources for SLSA, SSDF and more.

## Government perspectives on software self-attestation requirements

DevFeed: [Government perspectives on software self-attestation requirements](<https://devfeed.tech/articles/government-perspectives-on-software-self-attestation-requirements-13071.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/government-perspectives-on-software-self-attestation-requirements>)

Published: 2023-06-15T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [cisa](<https://devfeed.tech/topics/cisa.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [cisa](<https://devfeed.tech/tags/cisa.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [nist](<https://devfeed.tech/tags/nist.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [regulatory](<https://devfeed.tech/tags/regulatory.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [security](<https://devfeed.tech/tags/security.md>), [self-attestation](<https://devfeed.tech/tags/self-attestation.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [ssdf](<https://devfeed.tech/tags/ssdf.md>)

### AI overview

Chainguard CEO Dan Lorenc and CISA Fellow Chris Hughes discuss CISA's draft software self-attestation form, its relationship to federal software supply chain security requirements, and the regulatory context surrounding secure software development.

### Source excerpt

Chainguard CEO Dan Lorenc and Chris Hughes, CISO & Cofounder of Aquia and CISA Fellow discuss the upcoming software self-attestation form.

## The importance of toolchain security in NIST's SSDF

DevFeed: [The importance of toolchain security in NIST's SSDF](<https://devfeed.tech/articles/the-importance-of-toolchain-security-in-nist-s-ssdf-13258.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/the-importance-of-toolchain-security-in-nists-ssdf>)

Published: 2023-06-12T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [toolchain](<https://devfeed.tech/topics/toolchain.md>), [Security](<https://devfeed.tech/topics/security.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [Software Engineering](<https://devfeed.tech/topics/software-engineering.md>)

Tags: [cloud-security](<https://devfeed.tech/tags/cloud-security.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [nist](<https://devfeed.tech/tags/nist.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [security](<https://devfeed.tech/tags/security.md>), [self-attestation](<https://devfeed.tech/tags/self-attestation.md>), [ssdf](<https://devfeed.tech/tags/ssdf.md>), [supply-chain-attacks](<https://devfeed.tech/tags/supply-chain-attacks.md>), [toolchain](<https://devfeed.tech/tags/toolchain.md>)

### AI overview

This article argues that build systems and programming-language toolchains should be secured and inventoried like production systems. It discusses third-party code execution during installation and highlights Go toolchain vulnerabilities that enabled remote code execution during builds.

### Source excerpt

The new Secure Software Development Framework (SSDF) from NIST places toolchain inventory management and security front and center.

## Celebrating 5 years of NTIA's SBOM work

DevFeed: [Celebrating 5 years of NTIA's SBOM work](<https://devfeed.tech/articles/celebrating-5-years-of-ntia-s-sbom-work-12919.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/celebrating-5-years-of-ntias-sbom-work>)

Published: 2023-06-07T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security](<https://devfeed.tech/topics/security.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [cisa](<https://devfeed.tech/topics/cisa.md>), [distroless](<https://devfeed.tech/topics/distroless.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [cisa](<https://devfeed.tech/tags/cisa.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [distroless](<https://devfeed.tech/tags/distroless.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [openvex](<https://devfeed.tech/tags/openvex.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [software-dark-matter](<https://devfeed.tech/tags/software-dark-matter.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [sofware-supply-chain](<https://devfeed.tech/tags/sofware-supply-chain.md>), [ssdf](<https://devfeed.tech/tags/ssdf.md>), [vex](<https://devfeed.tech/tags/vex.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>)

### AI overview

The article commemorates five years of the NTIA's Software Bill of Materials work and reviews the development of SBOMs as a foundation of software supply chain security. It describes the NTIA's initiative, its multi-stakeholder guidelines, and CISA's continuing role in advancing software transparency.

### Source excerpt

Celebrate 5 transformative years of SBOM work with Chainguard, reflecting on the journey of software bill of materials.

## How to explain the CISA software attestation requirements to your board

DevFeed: [How to explain the CISA software attestation requirements to your board](<https://devfeed.tech/articles/how-to-explain-the-cisa-software-attestation-requirements-to-your-board-13094.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/how-to-explain-the-cisa-software-attestation-requirements-to-your-board>)

Published: 2023-05-05T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [cisa](<https://devfeed.tech/topics/cisa.md>), [cybersecurity and infrastructure security agency](<https://devfeed.tech/topics/cybersecurity-and-infrastructure-security-agency.md>), [software bill of materials](<https://devfeed.tech/topics/software-bill-of-materials.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [attestation](<https://devfeed.tech/tags/attestation.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [cisa](<https://devfeed.tech/tags/cisa.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [government](<https://devfeed.tech/tags/government.md>), [national-cybersecurity-strategy](<https://devfeed.tech/tags/national-cybersecurity-strategy.md>), [nist](<https://devfeed.tech/tags/nist.md>), [policy](<https://devfeed.tech/tags/policy.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [secure-container-image](<https://devfeed.tech/tags/secure-container-image.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [self-attestation](<https://devfeed.tech/tags/self-attestation.md>), [signing-artifacts](<https://devfeed.tech/tags/signing-artifacts.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [software-artifact-signing](<https://devfeed.tech/tags/software-artifact-signing.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [ssdf](<https://devfeed.tech/tags/ssdf.md>)

### AI overview

This article explains how software companies can brief their boards on CISA software attestation requirements and the broader federal software supply chain security policy landscape. It discusses Executive Order 14028, SBOMs, secure software development, CISA's Secure Software Development Attestation Form, and the requirements in OMB Memorandum M-22-18, including alignment with NIST guidance.

### Source excerpt

CISA's draft self-attestation form clarifies the minimum requirements that software developers must meet to comply with OMB Memorandum M-22-18.

## The National CyberSecurity Strategy: Liability is Coming

DevFeed: [The National CyberSecurity Strategy: Liability is Coming](<https://devfeed.tech/articles/the-national-cybersecurity-strategy-liability-is-coming-37007.md>)

Original publisher: [Read original article](<https://shostack.org/blog/the-national-cybersecurity-strategy/>)

Author: Adam

Published: 2023-03-21T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>)

Tags: [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [nist](<https://devfeed.tech/tags/nist.md>), [security](<https://devfeed.tech/tags/security.md>), [ssdf](<https://devfeed.tech/tags/ssdf.md>), [standard](<https://devfeed.tech/tags/standard.md>), [strategy](<https://devfeed.tech/tags/strategy.md>), [us](<https://devfeed.tech/tags/us.md>)

### AI overview

This commentary discusses the new US National Cybersecurity Strategy, focusing on its proposed shift of software and service liability toward manufacturers and providers. It outlines three elements: limiting contractual disclaimers, establishing a standard of care, and creating a safe harbor for companies that take reasonable, measurable security measures. The author expects debate over how eligibility for the safe harbor will be defined.

### Source excerpt

The National CyberSecurity Strategy: Liability is Coming After months of signals, the new US National CyberSecurity Strategy is out, and I can stop beating around the bush and be explicit: Liability is coming. There's lots more in the Strategy. Bruce Schneier has a good roundup of first responses. I didn't to try to provide a hot take on it, because I think others did a fine job.

## The Appsec Landscape in 2023

DevFeed: [The Appsec Landscape in 2023](<https://devfeed.tech/articles/the-appsec-landscape-in-2023-36998.md>)

Original publisher: [Read original article](<https://shostack.org/blog/the-appsec-landscape-in-2023/>)

Author: Adam

Published: 2023-01-05T00:00:00Z

Content type: article

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Requirements](<https://devfeed.tech/topics/requirements.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>)

Tags: [appsec](<https://devfeed.tech/tags/appsec.md>), [changes](<https://devfeed.tech/tags/changes.md>), [circleci](<https://devfeed.tech/tags/circleci.md>), [driving](<https://devfeed.tech/tags/driving.md>), [external](<https://devfeed.tech/tags/external.md>), [government](<https://devfeed.tech/tags/government.md>), [legacy](<https://devfeed.tech/tags/legacy.md>), [requirements](<https://devfeed.tech/tags/requirements.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [ssdf](<https://devfeed.tech/tags/ssdf.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>)

### AI overview

This article examines how economic conditions, new regulations, and engineering considerations may shape application security decisions in 2023. It emphasizes threat modeling, secure software development requirements, legacy code, and software supply-chain concerns.

### Source excerpt

External changes will be driving appsec in 2023. It's time to frame the decisions in front of you.

## NIST Opens Comments on Draft Secure Software Development Framework

DevFeed: [NIST Opens Comments on Draft Secure Software Development Framework](<https://devfeed.tech/articles/nist-on-sdls-36903.md>)

Original publisher: [Read original article](<https://shostack.org/blog/nist-on-sdls/>)

Author: Adam

Published: 2019-07-11T00:00:00Z

Content type: article

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Software Engineering](<https://devfeed.tech/topics/software-engineering.md>)

Tags: [adopting](<https://devfeed.tech/tags/adopting.md>), [framework](<https://devfeed.tech/tags/framework.md>), [nist](<https://devfeed.tech/tags/nist.md>), [open](<https://devfeed.tech/tags/open.md>), [risk](<https://devfeed.tech/tags/risk.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [ssdf](<https://devfeed.tech/tags/ssdf.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

NIST has released a draft Secure Software Development Framework (SSDF) for public comment, with comments accepted through August 5.

### Source excerpt

Mitigating the Risk of Software Vulnerabilities by Adopting a Secure Software Development Framework (SSDF) from NIST is open for comment.