# supply chain integrity

Published articles for supply chain integrity.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Chainguard's Vision for a Safer Software Supply Chain

DevFeed: [Chainguard's Vision for a Safer Software Supply Chain](<https://devfeed.tech/articles/chainguard-s-vision-for-a-safer-software-supply-chain-12998.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguards-vision-for-a-safer-software-supply-chain>)

Published: 2025-01-30T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Security](<https://devfeed.tech/topics/security.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve](<https://devfeed.tech/tags/cve.md>), [integrity](<https://devfeed.tech/tags/integrity.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [security](<https://devfeed.tech/tags/security.md>), [signing](<https://devfeed.tech/tags/signing.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [software-development](<https://devfeed.tech/tags/software-development.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [supply-chain-attacks](<https://devfeed.tech/tags/supply-chain-attacks.md>), [supply-chain-integrity](<https://devfeed.tech/tags/supply-chain-integrity.md>)

### AI overview

Chainguard presents its vision for secure software development, arguing that security and innovation should advance together. The article advocates signed binaries, verified dependencies, source-built container images, cryptographic build evidence, and broader adoption of supply-chain integrity standards such as Sigstore.

### Source excerpt

Chainguard is building the future of secure software development, where security and innovation move in lockstep and every line of code makes software safer.

## Mitigating software supply chain risks through faster vulnerability response and verified software images

DevFeed: [Mitigating software supply chain risks through faster vulnerability response and verified software images](<https://devfeed.tech/articles/if-xz-s-backdoors-are-inevitable-how-do-we-stay-secure-the-answer-is-move-faster-13100.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/if-xzs-backdoors-are-inevitable-how-do-we-stay-secure-the-answer-is-move-faster>)

Published: 2024-04-16T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [supply chain attacks](<https://devfeed.tech/topics/supply-chain-attacks.md>)

Tags: [auditability](<https://devfeed.tech/tags/auditability.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [cve-2024-3094](<https://devfeed.tech/tags/cve-2024-3094.md>), [golang](<https://devfeed.tech/tags/golang.md>), [liblzma](<https://devfeed.tech/tags/liblzma.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [supply-chain-attacks](<https://devfeed.tech/tags/supply-chain-attacks.md>), [supply-chain-integrity](<https://devfeed.tech/tags/supply-chain-integrity.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [xz](<https://devfeed.tech/tags/xz.md>), [xz-backdoor](<https://devfeed.tech/tags/xz-backdoor.md>), [zero-trust](<https://devfeed.tech/tags/zero-trust.md>)

### AI overview

The article discusses the xz vulnerability, the risk of future software supply chain attacks, and the importance of rapid patch propagation and software inventory auditability. It presents Chainguard Images as a continuously verified and auditable approach to mitigating these risks.

### Source excerpt

Software backdoors are a threat. Learn how to mitigate supply chain security risks by responding faster to vulnerabilities like the xz flaw.

## Chainguard and CNCF conduct SLSA assessments for Argo and Prometheus projects

DevFeed: [Chainguard and CNCF conduct SLSA assessments for Argo and Prometheus projects](<https://devfeed.tech/articles/chainguard-and-cncf-conduct-slsa-assessments-for-argo-and-prometheus-projects-12923.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-and-cncf-conduct-slsa-assessments-for-argo-and-prometheus-projects>)

Published: 2023-04-19T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Prometheus](<https://devfeed.tech/topics/prometheus.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Security](<https://devfeed.tech/topics/security.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>)

Tags: [argo](<https://devfeed.tech/tags/argo.md>), [argo-cd](<https://devfeed.tech/tags/argo-cd.md>), [audits](<https://devfeed.tech/tags/audits.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [cncf](<https://devfeed.tech/tags/cncf.md>), [github](<https://devfeed.tech/tags/github.md>), [maintainers](<https://devfeed.tech/tags/maintainers.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [prometheus](<https://devfeed.tech/tags/prometheus.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [security](<https://devfeed.tech/tags/security.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [slsa-levels](<https://devfeed.tech/tags/slsa-levels.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [supply-chain-integrity](<https://devfeed.tech/tags/supply-chain-integrity.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>)

### AI overview

Chainguard and CNCF assessed the software supply chain security of the Argo CD and Prometheus projects using the SLSA framework. Argo CD achieved SLSA Level 3 for source, build, and provenance, while Prometheus achieved Level 3 for source and build; the assessment recommended adding provenance generation to Prometheus build infrastructure.

### Source excerpt

Chainguard and the CNCF partnered to conduct security assessments of Argo and Prometheus to ensure open source software projects apply security best practices.

## New SLSA++ Survey reveals real-world developer approaches to software supply chain security

DevFeed: [New SLSA++ Survey reveals real-world developer approaches to software supply chain security](<https://devfeed.tech/articles/new-slsa-survey-reveals-real-world-developer-approaches-to-software-supply-chain-security-13183.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/new-slsa-survey-reveals-real-world-developer-approaches-to-software-supply-chain-security>)

Published: 2023-03-15T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [openssf](<https://devfeed.tech/topics/openssf.md>)

Tags: [best-practices](<https://devfeed.tech/tags/best-practices.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [digital-signatures](<https://devfeed.tech/tags/digital-signatures.md>), [integrity](<https://devfeed.tech/tags/integrity.md>), [maintainers](<https://devfeed.tech/tags/maintainers.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [openssf](<https://devfeed.tech/tags/openssf.md>), [report](<https://devfeed.tech/tags/report.md>), [rust](<https://devfeed.tech/tags/rust.md>), [secure-software-development-frameworks](<https://devfeed.tech/tags/secure-software-development-frameworks.md>), [security](<https://devfeed.tech/tags/security.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [software-development](<https://devfeed.tech/tags/software-development.md>), [software-security-practices](<https://devfeed.tech/tags/software-security-practices.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [supply-chain-integrity](<https://devfeed.tech/tags/supply-chain-integrity.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [survey](<https://devfeed.tech/tags/survey.md>)

### AI overview

A joint survey by Chainguard, the Eclipse Foundation, the Rust Foundation, and OpenSSF examined how developers, open source maintainers, and security practitioners adopt software supply chain security practices. Among nearly 170 respondents, centralized build services showed relatively strong adoption, while consistently signing built artifacts was less common, with 25% reporting that their team always did so. Respondents generally considered the surveyed practices helpful.

### Source excerpt

Findings on software supply chain security practice adoption from our joint survey with OpenSSF, Rust, and Eclipse with questions derived from SLSA requirements.

## Supply chain integrity with GoReleaser using Go mod proxy

DevFeed: [Supply chain integrity with GoReleaser using Go mod proxy](<https://devfeed.tech/articles/supply-chain-integrity-with-goreleaser-using-go-mod-proxy-37854.md>)

Original publisher: [Read original article](<https://carlosbecker.com/posts/supply-chain-goreleaser-go-mod-proxy/>)

Author: Carlos Alexandro Becker

Published: 2021-08-23T00:00:00Z

Content type: tutorial

Language: en

Sources: [Carlos Becker](<https://devfeed.tech/sources/carlos-becker.md>)

Topics: [integrity](<https://devfeed.tech/topics/integrity.md>), [Go Language](<https://devfeed.tech/topics/go-language.md>), [proxy](<https://devfeed.tech/topics/proxy.md>), [builds](<https://devfeed.tech/topics/builds.md>), [hash](<https://devfeed.tech/topics/hash.md>), [opensource](<https://devfeed.tech/topics/opensource.md>)

Tags: [builds](<https://devfeed.tech/tags/builds.md>), [go](<https://devfeed.tech/tags/go.md>), [hash](<https://devfeed.tech/tags/hash.md>), [making](<https://devfeed.tech/tags/making.md>), [opensource](<https://devfeed.tech/tags/opensource.md>), [proxy](<https://devfeed.tech/tags/proxy.md>), [supply-chain-integrity](<https://devfeed.tech/tags/supply-chain-integrity.md>)

### AI overview

This tutorial explains how to verify Go binaries built with GoReleaser by using the Go module proxy and comparing module hashes. It also discusses signing, reproducible builds, and limitations involving dependencies and non-open-source GoReleaser Pro.

### Source excerpt

Since the infamous SolarWinds attack, supply chain integrity is something a lot of people are discussing and working on.