# chainguard

Chainguard is an organization that builds secure, hardened open-source software artifacts and maintains tools for secure software delivery.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Announcing the Sovereign Artifacts beta

DevFeed: [Announcing the Sovereign Artifacts beta](<https://devfeed.tech/articles/announcing-the-sovereign-artifacts-beta-26773.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/announcing-the-sovereign-artifacts-beta>)

Published: 2026-09-15T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Software](<https://devfeed.tech/topics/software.md>), [cyber resilience act](<https://devfeed.tech/topics/cyber-resilience-act.md>), [Resilience](<https://devfeed.tech/topics/resilience.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [container](<https://devfeed.tech/tags/container.md>), [cyber-resilience-act](<https://devfeed.tech/tags/cyber-resilience-act.md>), [eu](<https://devfeed.tech/tags/eu.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [network](<https://devfeed.tech/tags/network.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [performance](<https://devfeed.tech/tags/performance.md>), [resilience](<https://devfeed.tech/tags/resilience.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>)

### AI overview

Chainguard has launched Sovereign Artifacts in beta, providing EU-local storage and delivery for secure container and library artifact bytes. Phase 1 stores artifacts in the EU, while authentication and build pipelines remain hosted in the United States. The service is intended to support sovereignty and data-residency requirements and reduce artifact pull times for European customers.

### Source excerpt

Chainguard launches Sovereign Artifacts in beta, giving global organizations an EU-local option for secure container and library artifacts.

## Chainguard and Athena prepare to disclose vulnerabilities found by frontier AI models

DevFeed: [Chainguard and Athena prepare to disclose vulnerabilities found by frontier AI models](<https://devfeed.tech/articles/the-flood-is-coming-and-the-pipes-were-already-full-26774.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/the-flood-is-coming-and-the-pipes-were-already-full>)

Published: 2026-09-15T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [anthropic](<https://devfeed.tech/topics/anthropic.md>), [Software](<https://devfeed.tech/topics/software.md>), [Code](<https://devfeed.tech/topics/code.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [anthropic](<https://devfeed.tech/tags/anthropic.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [project-glasswing](<https://devfeed.tech/tags/project-glasswing.md>), [software](<https://devfeed.tech/tags/software.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This opinion post reports on Chainguard's Athena initiative and its plans to begin disclosing 50 model-generated vulnerability findings. It discusses Anthropic's Project Glasswing, vulnerability discovery, responsible disclosure, patch pipelines, and infrastructure the company plans to open source.

### Source excerpt

Frontier AI is finding zero-days faster than the industry can fix them. See how Chainguard and Athena are preparing for what comes next.

## Chainguard's Factory-Scale Automation for Toolchain Upgrades and Testing

DevFeed: [Chainguard's Factory-Scale Automation for Toolchain Upgrades and Testing](<https://devfeed.tech/articles/this-shit-is-hard-factory-scale-toolchain-management-13278.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/this-shit-is-hard-factory-scale-toolchain-management>)

Published: 2026-09-09T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [toolchain](<https://devfeed.tech/topics/toolchain.md>), [Automation](<https://devfeed.tech/topics/automation.md>), [Testing](<https://devfeed.tech/topics/testing.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Go Language](<https://devfeed.tech/topics/go-language.md>)

Tags: [automation](<https://devfeed.tech/tags/automation.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [go](<https://devfeed.tech/tags/go.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [security](<https://devfeed.tech/tags/security.md>), [testing](<https://devfeed.tech/tags/testing.md>), [toolchain](<https://devfeed.tech/tags/toolchain.md>), [upgrades](<https://devfeed.tech/tags/upgrades.md>)

### AI overview

Chainguard describes how its Factory uses automation to manage toolchain version selection, upgrades, builds, and testing across open source packages. The approach uses version streams and rebuilds packages with newer toolchain versions when builds and tests succeed, helping deliver updates quickly while maintaining reliability and security.

### Source excerpt

See how Chainguard automates toolchain upgrades and testing to keep thousands of open source packages current, secure, and reliable at scale.

## What it took to reach 1 billion build manifests

DevFeed: [What it took to reach 1 billion build manifests](<https://devfeed.tech/articles/what-it-took-to-reach-1-billion-build-manifests-13318.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/what-it-took-to-reach-1-billion-build-manifests>)

Published: 2026-09-03T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [chainguard os](<https://devfeed.tech/topics/chainguard-os.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [NumPy](<https://devfeed.tech/topics/numpy.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-factory](<https://devfeed.tech/tags/chainguard-factory.md>), [chainguard-os](<https://devfeed.tech/tags/chainguard-os.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [go](<https://devfeed.tech/tags/go.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>)

### AI overview

Chainguard describes how it doubled container build output from 500 million to more than 1 billion manifests in six months. The article explains how Chainguard Factory and Chainguard OS support continuous rebuilds, while using source builds, SLSA Level 3 provenance, Sigstore signatures, and full SBOMs.

### Source excerpt

Chainguard doubled its container build output in six months. Learn how Factory 2.0 uses AI and reconciliation to rebuild secure software at scale.

## Proven, not promised: Chainguard Containers achieves SLSA Build Level 3

DevFeed: [Proven, not promised: Chainguard Containers achieves SLSA Build Level 3](<https://devfeed.tech/articles/proven-not-promised-chainguard-containers-achieves-slsa-build-level-3-13206.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/proven-not-promised-chainguard-containers-achieves-slsa-build-level-3>)

Published: 2026-08-17T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [software bill of materials](<https://devfeed.tech/topics/software-bill-of-materials.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [security](<https://devfeed.tech/tags/security.md>), [signing](<https://devfeed.tech/tags/signing.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>)

### AI overview

Chainguard says Coalfire independently assessed the Chainguard Containers build and release system as meeting SLSA Build Level 3 requirements. The article describes hardened, isolated builds, separately managed signing, provenance generation, and signed SBOMs for releases.

### Source excerpt

Coalfire independently assessed Chainguard Containers at SLSA Build Level 3, validating hardened builds, provenance, and supply chain integrity.

## Patching Vulnerabilities Without an Upstream Fix

DevFeed: [Patching Vulnerabilities Without an Upstream Fix](<https://devfeed.tech/articles/this-shit-is-hard-patching-a-vulnerability-that-has-no-fix-13287.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/this-shit-is-hard-patching-a-vulnerability-that-has-no-fix>)

Published: 2026-08-17T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [ai security](<https://devfeed.tech/topics/ai-security.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Automation](<https://devfeed.tech/topics/automation.md>), [Frontier AI](<https://devfeed.tech/topics/frontier-ai.md>)

Tags: [ai-security](<https://devfeed.tech/tags/ai-security.md>), [automation](<https://devfeed.tech/tags/automation.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [cves](<https://devfeed.tech/tags/cves.md>), [sandbox](<https://devfeed.tech/tags/sandbox.md>), [software](<https://devfeed.tech/tags/software.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

Chainguard describes how its Athena vulnerability clearinghouse addresses exploitable vulnerabilities when no upstream fix exists. The article explains that generating an AI-written patch is straightforward, while proving the patch is correct and safe requires extensive engineering and validation inside a microVM sandbox.

### Source excerpt

Generating an AI security patch is easy. Trusting it is hard. Learn how Chainguard proves zero-day fixes are safe before they ship.

## The keyv and cacheable npm Supply Chain Attack: Inside the Mini Shai-Hulud Campaign

DevFeed: [The keyv and cacheable npm Supply Chain Attack: Inside the Mini Shai-Hulud Campaign](<https://devfeed.tech/articles/the-keyv-and-cacheable-npm-supply-chain-attack-inside-the-mini-shai-hulud-campaign-13261.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/the-keyv-and-cacheable-npm-supply-chain-attack-inside-the-mini-shai-hulud-campaign>)

Published: 2026-08-04T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [npm](<https://devfeed.tech/topics/npm.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [C2](<https://devfeed.tech/topics/c2.md>), [Ethereum](<https://devfeed.tech/topics/ethereum.md>)

Tags: [aws](<https://devfeed.tech/tags/aws.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [ethereum](<https://devfeed.tech/tags/ethereum.md>), [github](<https://devfeed.tech/tags/github.md>), [malware](<https://devfeed.tech/tags/malware.md>), [mini-shai-hulud](<https://devfeed.tech/tags/mini-shai-hulud.md>), [npm](<https://devfeed.tech/tags/npm.md>), [payload](<https://devfeed.tech/tags/payload.md>), [shai-hulud](<https://devfeed.tech/tags/shai-hulud.md>), [smart-contract](<https://devfeed.tech/tags/smart-contract.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>)

### AI overview

The article examines a 2026 npm supply-chain attack in which a compromised maintainer account was used to publish malicious versions of keyv and cacheable-related packages. It reports credential theft, worm-like propagation to hundreds of downstream packages, and command-and-control infrastructure discovered through an Ethereum smart contract. It also explains that Chainguard customers were protected by malware scanning and package cooldowns.

### Source excerpt

The latest npm supply chain attack hit keyv and cacheable. See how Chainguard's malware scanning and cooldowns kept customers protected.

## How Chainguard Uses Hardware-Virtualized Sandboxes to Isolate AI Agents and Untrusted Code

DevFeed: [How Chainguard Uses Hardware-Virtualized Sandboxes to Isolate AI Agents and Untrusted Code](<https://devfeed.tech/articles/this-shit-is-hard-how-chainguard-is-sandboxing-athena-13283.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/this-shit-is-hard-how-chainguard-is-sandboxing-athena>)

Published: 2026-07-29T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Security](<https://devfeed.tech/topics/security.md>), [Code](<https://devfeed.tech/topics/code.md>), [qemu](<https://devfeed.tech/topics/qemu.md>), [Containers](<https://devfeed.tech/topics/containers.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [code](<https://devfeed.tech/tags/code.md>), [hardware](<https://devfeed.tech/tags/hardware.md>), [kvm](<https://devfeed.tech/tags/kvm.md>), [sandboxes](<https://devfeed.tech/tags/sandboxes.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

Chainguard describes applying its build-isolation approach to sandboxing AI agents and other untrusted code. The approach uses fresh hardware-virtualized QEMU/KVM environments with their own kernels to limit blast radius and prevent persistence or access to sensitive signing materials.

### Source excerpt

AI agents need sandboxes. Learn how Chainguard uses microVMs to safely run untrusted code, contain exploits, and protect sensitive workloads.

## Responding to the Five Eyes guidance on AI and cyber risk

DevFeed: [Responding to the Five Eyes guidance on AI and cyber risk](<https://devfeed.tech/articles/responding-to-the-five-eyes-guidance-on-ai-and-cyber-risk-13212.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/responding-to-the-five-eyes-guidance-on-ai-and-cyber-risk>)

Published: 2026-07-15T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Frontier AI](<https://devfeed.tech/topics/frontier-ai.md>), [Resilience](<https://devfeed.tech/topics/resilience.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [five-eyes-security](<https://devfeed.tech/tags/five-eyes-security.md>), [government-of-canada](<https://devfeed.tech/tags/government-of-canada.md>), [identity-and-access-management](<https://devfeed.tech/tags/identity-and-access-management.md>), [mythos](<https://devfeed.tech/tags/mythos.md>), [resilience](<https://devfeed.tech/tags/resilience.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

The article interprets joint Five Eyes guidance warning that frontier AI may increase the speed, scale, and sophistication of cyberattacks. It argues that organizations should strengthen software supply chain security, accelerate vulnerability remediation, reduce unnecessary dependencies, address legacy systems, improve identity and access management, and build cyber resilience into business and development practices.

### Source excerpt

The Five Eyes AI guidance urges organizations to strengthen software supply chain security. Learn how Chainguard helps teams stay ahead.

## Chainguard Repository adds new policies, Chainguard Libraries for JavaScript is GA

DevFeed: [Chainguard Repository adds new policies, Chainguard Libraries for JavaScript is GA](<https://devfeed.tech/articles/chainguard-repository-adds-new-policies-chainguard-libraries-for-javascript-is-ga-12979.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-repository-adds-new-policies-chainguard-libraries-for-javascript-is-ga>)

Published: 2026-06-25T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard repository](<https://devfeed.tech/topics/chainguard-repository.md>), [chainguard libraries for javascript](<https://devfeed.tech/topics/chainguard-libraries-for-javascript.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [chainguard-libraries-for-java](<https://devfeed.tech/tags/chainguard-libraries-for-java.md>), [chainguard-libraries-for-javascript](<https://devfeed.tech/tags/chainguard-libraries-for-javascript.md>), [chainguard-libraries-for-python](<https://devfeed.tech/tags/chainguard-libraries-for-python.md>), [chainguard-repo](<https://devfeed.tech/tags/chainguard-repo.md>), [chainguard-repository](<https://devfeed.tech/tags/chainguard-repository.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [libraries](<https://devfeed.tech/tags/libraries.md>), [malware](<https://devfeed.tech/tags/malware.md>), [malware-scanner](<https://devfeed.tech/tags/malware-scanner.md>), [policy](<https://devfeed.tech/tags/policy.md>), [visibility](<https://devfeed.tech/tags/visibility.md>)

### AI overview

Chainguard announces new malware and greyware scanning for additional artifact types, expanded policy controls, and new visibility features in Chainguard Repository. The article also announces general availability of Chainguard Libraries for JavaScript.

### Source excerpt

Chainguard Repository adds malware and greyware scanning, expanded policy controls, and visibility to secure AI-driven software supply chains.

## Fewer CVEs, more accurate findings: Wiz now scans Chainguard Libraries for Python and Java

DevFeed: [Fewer CVEs, more accurate findings: Wiz now scans Chainguard Libraries for Python and Java](<https://devfeed.tech/articles/fewer-cves-more-accurate-findings-wiz-now-scans-chainguard-libraries-for-python-and-java-13335.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/wiz-now-scans-chainguard-libraries-for-python-and-java>)

Published: 2026-06-25T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard libraries](<https://devfeed.tech/topics/chainguard-libraries.md>), [chainguard libraries for python](<https://devfeed.tech/topics/chainguard-libraries-for-python.md>), [Java](<https://devfeed.tech/topics/java.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [chainguard-libraries-for-java](<https://devfeed.tech/tags/chainguard-libraries-for-java.md>), [chainguard-libraries-for-python](<https://devfeed.tech/tags/chainguard-libraries-for-python.md>), [cves](<https://devfeed.tech/tags/cves.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [java](<https://devfeed.tech/tags/java.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [python](<https://devfeed.tech/tags/python.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [wiz](<https://devfeed.tech/tags/wiz.md>), [wiz-chainguard-libraries](<https://devfeed.tech/tags/wiz-chainguard-libraries.md>), [wiz-chainguard-scanner](<https://devfeed.tech/tags/wiz-chainguard-scanner.md>)

### AI overview

Wiz now scans Chainguard Libraries for Python and Java. The partnership combines source-built dependencies and backported fixes with Wiz's risk context and visibility, helping organizations assess vulnerabilities, prioritize remediation, and verify artifact provenance.

### Source excerpt

Wiz now scans Chainguard Libraries for Python and Java, combining trusted, source-built dependencies with risk-based visibility and remediation.

## Everything we announced during AI Readiness Innovation Week

DevFeed: [Everything we announced during AI Readiness Innovation Week](<https://devfeed.tech/articles/everything-we-announced-during-ai-readiness-innovation-week-13033.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/everything-we-announced-during-ai-readiness-innovation-week>)

Published: 2026-06-25T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [ai-coding](<https://devfeed.tech/topics/ai-coding.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [chainguard libraries](<https://devfeed.tech/topics/chainguard-libraries.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [Frontier AI](<https://devfeed.tech/topics/frontier-ai.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-readiness](<https://devfeed.tech/tags/ai-readiness.md>), [athena](<https://devfeed.tech/tags/athena.md>), [aws-kiro](<https://devfeed.tech/tags/aws-kiro.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cursor](<https://devfeed.tech/tags/cursor.md>), [frontier-ai-models](<https://devfeed.tech/tags/frontier-ai-models.md>), [gartner-magic-quadrant](<https://devfeed.tech/tags/gartner-magic-quadrant.md>), [github](<https://devfeed.tech/tags/github.md>), [innovation](<https://devfeed.tech/tags/innovation.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [speed](<https://devfeed.tech/tags/speed.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Chainguard summarizes announcements from AI Readiness Innovation Week, covering supply-chain security advances for containers, libraries, CI/CD pipelines, AI agent skills, IDE integrations, partnerships, and an industry coalition. The article highlights Athena, a coalition designed to coordinate defense against vulnerabilities discovered by frontier AI models.

### Source excerpt

Read about everything Chainguard announced during AI Readiness Innovation Week, including new features for Chainguard Libraries and Chainguard Containers.

## How Chainguard uses AI agents to enforce engineering standards across a monorepo

DevFeed: [How Chainguard uses AI agents to enforce engineering standards across a monorepo](<https://devfeed.tech/articles/this-shit-is-hard-how-ai-keeps-our-code-on-standard-13282.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/this-shit-is-hard-how-ai-keeps-our-code-on-standard>)

Published: 2026-06-24T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Bot](<https://devfeed.tech/topics/bot.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Pull Request](<https://devfeed.tech/topics/pull-request.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>)

Tags: [agentic](<https://devfeed.tech/tags/agentic.md>), [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-agent-skills](<https://devfeed.tech/tags/chainguard-agent-skills.md>), [chainguard-agents](<https://devfeed.tech/tags/chainguard-agents.md>), [chainguard-ai](<https://devfeed.tech/tags/chainguard-ai.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-engineering](<https://devfeed.tech/tags/chainguard-engineering.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [ci](<https://devfeed.tech/tags/ci.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [github](<https://devfeed.tech/tags/github.md>), [policy](<https://devfeed.tech/tags/policy.md>), [pull-request](<https://devfeed.tech/tags/pull-request.md>), [workflow](<https://devfeed.tech/tags/workflow.md>)

### AI overview

Chainguard describes a system of specialized AI agents built on DriftlessAF that continuously checks code against machine-readable engineering standards, fixes drift, and supports CI repair. Over eight weeks, it opened more than 4,700 standards-fix pull requests; 75% judged low-risk were auto-merged when AI judgment agreed with deterministic checks.

### Source excerpt

Chainguard uses AI-powered agents to continuously enforce engineering standards, remediate drift, and keep codebases aligned at scale.

## Securing the AI coding ecosystem: Chainguard and the AI tools developers use

DevFeed: [Securing the AI coding ecosystem: Chainguard and the AI tools developers use](<https://devfeed.tech/articles/securing-the-ai-coding-ecosystem-chainguard-and-the-ai-tools-developers-use-13222.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/securing-the-ai-coding-ecosystem-chainguard-and-the-ai-tools-developers-use>)

Published: 2026-06-24T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Kiro](<https://devfeed.tech/topics/kiro.md>), [AI Development](<https://devfeed.tech/topics/ai-development.md>), [cursor](<https://devfeed.tech/topics/cursor.md>), [Security](<https://devfeed.tech/topics/security.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [ai-coding](<https://devfeed.tech/tags/ai-coding.md>), [aws-kiro](<https://devfeed.tech/tags/aws-kiro.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-ai-tools](<https://devfeed.tech/tags/chainguard-ai-tools.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cursor](<https://devfeed.tech/tags/cursor.md>), [developers](<https://devfeed.tech/tags/developers.md>), [kiro](<https://devfeed.tech/tags/kiro.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>)

### AI overview

Chainguard argues that AI coding tools such as Kiro and Cursor need trusted sources for dependencies and container images. The article describes Chainguard Containers, Libraries, and a Kiro plugin intended to move projects from public registries to hardened supply-chain components.

### Source excerpt

Chainguard brings secure-by-default containers and libraries to AI coding tools like Kiro and Cursor, making trusted open source the default.

## Chainguard plug-in now available on Cursor Marketplace

DevFeed: [Chainguard plug-in now available on Cursor Marketplace](<https://devfeed.tech/articles/chainguard-plug-in-now-available-on-cursor-marketplace-12976.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-plug-in-now-available-on-cursor-marketplace>)

Published: 2026-06-24T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [cursor](<https://devfeed.tech/topics/cursor.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [AI-assisted coding](<https://devfeed.tech/topics/ai-assisted-coding.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [ai-coding-agents](<https://devfeed.tech/tags/ai-coding-agents.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-cursor](<https://devfeed.tech/tags/chainguard-cursor.md>), [chainguard-cursor-marketplace](<https://devfeed.tech/tags/chainguard-cursor-marketplace.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cursor](<https://devfeed.tech/tags/cursor.md>), [cursor-chainguard-containers](<https://devfeed.tech/tags/cursor-chainguard-containers.md>), [cursor-chainguard-libraries](<https://devfeed.tech/tags/cursor-chainguard-libraries.md>), [libraries](<https://devfeed.tech/tags/libraries.md>), [mcp](<https://devfeed.tech/tags/mcp.md>), [plugin](<https://devfeed.tech/tags/plugin.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

Chainguard has launched a plugin on the Cursor Marketplace that connects Cursor to Chainguard Containers, Chainguard Libraries, and the Chainguard Repository. The plugin is intended to make secure-by-default artifacts available in AI coding workflows and help agents remediate known vulnerabilities.

### Source excerpt

Connect Cursor to Chainguard in minutes and make secure, malware-resistant containers and libraries the default for AI-generated code.

## Chainguard is named a Leader in the 2026 Gartner® Magic Quadrant™ for Software Supply Chain Security

DevFeed: [Chainguard is named a Leader in the 2026 Gartner® Magic Quadrant™ for Software Supply Chain Security](<https://devfeed.tech/articles/chainguard-is-named-a-leader-in-the-2026-gartner-magic-quadranttm-for-software-supply-chain-security-12961.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-is-named-a-leader-in-the-2026-gartner-magic-quadrant-for-software-supply-chain-security>)

Published: 2026-06-18T00:00:00Z

Content type: news

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-gartner](<https://devfeed.tech/tags/chainguard-gartner.md>), [chainguard-gartner-magic-quadrant](<https://devfeed.tech/tags/chainguard-gartner-magic-quadrant.md>), [cyber-resilience-act](<https://devfeed.tech/tags/cyber-resilience-act.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [gartner](<https://devfeed.tech/tags/gartner.md>), [gartner-mq-software-supply-chain](<https://devfeed.tech/tags/gartner-mq-software-supply-chain.md>), [nis2](<https://devfeed.tech/tags/nis2.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [security](<https://devfeed.tech/tags/security.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [software-supply-chain-security-gartner](<https://devfeed.tech/tags/software-supply-chain-security-gartner.md>)

### AI overview

Chainguard announces that it has been recognized as a Leader in the 2026 Gartner Magic Quadrant for Software Supply Chain Security. The article highlights Chainguard's secure-by-default approach, hardened open source artifacts, cryptographic signatures, signed SBOMs, and SLSA-aligned provenance, along with support for regulatory requirements.

### Source excerpt

Chainguard named a Leader in the 2026 Gartner® Magic Quadrant™ for Software Supply Chain Security, recognized for vision and secure-by-default innovation.

## Introducing the Chainguard cinc-auditor image: STIG scanning for Chainguard Containers, ready to run

DevFeed: [Introducing the Chainguard cinc-auditor image: STIG scanning for Chainguard Containers, ready to run](<https://devfeed.tech/articles/introducing-the-chainguard-cinc-auditor-image-stig-scanning-for-chainguard-containers-ready-to-run-13123.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/introducing-the-chainguard-cinc-auditor-image-stig-scanning-for-chainguard-containers-ready-to-run>)

Published: 2026-06-18T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [anchore](<https://devfeed.tech/topics/anchore.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [anchore](<https://devfeed.tech/tags/anchore.md>), [anchore-enterprise](<https://devfeed.tech/tags/anchore-enterprise.md>), [apache](<https://devfeed.tech/tags/apache.md>), [built-from-source](<https://devfeed.tech/tags/built-from-source.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [cinc-auditor](<https://devfeed.tech/tags/cinc-auditor.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [pipeline](<https://devfeed.tech/tags/pipeline.md>), [scanner](<https://devfeed.tech/tags/scanner.md>), [stig](<https://devfeed.tech/tags/stig.md>), [stigs](<https://devfeed.tech/tags/stigs.md>)

### AI overview

Chainguard introduces a ready-to-run cinc-auditor container image for STIG scanning of Chainguard Containers. The image includes a maintained GPOS SRG InSpec profile, removes separate profile and dependency setup, and supports production compliance pipelines, including FedRAMP workflows.

### Source excerpt

Chainguard launches a ready-to-run STIG scanner with a built-in GPOS SRG InSpec profile, simplifying compliance scans for containers and FedRAMP workflows.

## Chainguard Agent Skills is now open to everyone, with a private registry to manage your internal skills

DevFeed: [Chainguard Agent Skills is now open to everyone, with a private registry to manage your internal skills](<https://devfeed.tech/articles/chainguard-agent-skills-is-now-open-to-everyone-with-a-private-registry-to-manage-your-internal-skills-12922.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-agent-skills-is-now-open-to-everyone-with-a-private-registry-to-manage-your-internal-skills>)

Published: 2026-06-17T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Agent Skills](<https://devfeed.tech/topics/agent-skills.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Security](<https://devfeed.tech/topics/security.md>), [audit trail](<https://devfeed.tech/topics/audit-trail.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [agent-skills](<https://devfeed.tech/tags/agent-skills.md>), [ai-agent-skills](<https://devfeed.tech/tags/ai-agent-skills.md>), [audit-trail](<https://devfeed.tech/tags/audit-trail.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-agent-skills](<https://devfeed.tech/tags/chainguard-agent-skills.md>), [chainguard-ai-agents](<https://devfeed.tech/tags/chainguard-ai-agents.md>), [chainguard-skills](<https://devfeed.tech/tags/chainguard-skills.md>), [cursor](<https://devfeed.tech/tags/cursor.md>), [hardening](<https://devfeed.tech/tags/hardening.md>), [private-registry](<https://devfeed.tech/tags/private-registry.md>), [registry](<https://devfeed.tech/tags/registry.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

Chainguard Agent Skills is now available to all users with more than 1,000 hardened community skills, a private registry for internal skills, and a closed beta for hardening first-party skills. The service is intended to help organizations securely standardize, distribute, and manage AI agent skills.

### Source excerpt

Chainguard Agent Skills now offers 1,000+ hardened community skills, private registries, and beta hardening for first-party AI agent skills.

## The expanding threat landscape: Chainguard now scans source code for traditional malware and "greyware"

DevFeed: [The expanding threat landscape: Chainguard now scans source code for traditional malware and "greyware"](<https://devfeed.tech/articles/the-expanding-threat-landscape-chainguard-now-scans-source-code-for-traditional-malware-and-greyware-13252.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/the-expanding-threat-landscape-chainguard-now-scans-source-code-for-traditional-malware-and-greyware>)

Published: 2026-06-09T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Code](<https://devfeed.tech/topics/code.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [npm](<https://devfeed.tech/topics/npm.md>), [npm packages](<https://devfeed.tech/topics/npm-packages.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [ecosystems](<https://devfeed.tech/tags/ecosystems.md>), [greyware](<https://devfeed.tech/tags/greyware.md>), [greyware-scanner](<https://devfeed.tech/tags/greyware-scanner.md>), [hardening](<https://devfeed.tech/tags/hardening.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [malware](<https://devfeed.tech/tags/malware.md>), [malware-prevention](<https://devfeed.tech/tags/malware-prevention.md>), [malware-scanner](<https://devfeed.tech/tags/malware-scanner.md>), [npm](<https://devfeed.tech/tags/npm.md>), [npm-packages](<https://devfeed.tech/tags/npm-packages.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [packages](<https://devfeed.tech/tags/packages.md>), [scanner](<https://devfeed.tech/tags/scanner.md>), [security](<https://devfeed.tech/tags/security.md>), [source](<https://devfeed.tech/tags/source.md>), [supply-chain-attacks](<https://devfeed.tech/tags/supply-chain-attacks.md>)

### AI overview

Chainguard has introduced a source code scanner that detects traditional malware and "greyware," harmful packages that may perform actions such as credential theft, command interception, API key harvesting, or persistent remote access. The scanner currently protects npm packages, scans more than 100,000 packages daily, and has blocked more than 52,000 packages identified as malware or greyware.

### Source excerpt

Chainguard's new scanner blocks malware and 'greyware' before it reaches developers, protecting 100,000+ packages daily across open source ecosystems.

## Chainguard and Upwind: Secure what you build. Verify what you run.

DevFeed: [Chainguard and Upwind: Secure what you build. Verify what you run.](<https://devfeed.tech/articles/chainguard-and-upwind-secure-what-you-build-verify-what-you-run-12926.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-and-upwind-secure-what-you-build-verify-what-you-run>)

Published: 2026-05-26T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard libraries](<https://devfeed.tech/topics/chainguard-libraries.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [malicious packages](<https://devfeed.tech/topics/malicious-packages.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [chainguard-libraries-for-python](<https://devfeed.tech/tags/chainguard-libraries-for-python.md>), [chainguard-scanners](<https://devfeed.tech/tags/chainguard-scanners.md>), [chainguard-upwind](<https://devfeed.tech/tags/chainguard-upwind.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [malicious-packages](<https://devfeed.tech/tags/malicious-packages.md>), [malware-scanners](<https://devfeed.tech/tags/malware-scanners.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain-attacks](<https://devfeed.tech/tags/supply-chain-attacks.md>), [upwind](<https://devfeed.tech/tags/upwind.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Chainguard announces that Upwind now scans Chainguard Libraries for Python. The article describes combining trusted software artifacts with runtime visibility to reduce noise and supply chain risk.

### Source excerpt

Chainguard and Upwind combine trusted, source-built artifacts with runtime verification to cut noise, reduce risk, and secure AI-era software.

## Canada's CPCSC and Bill C-8 are coming. Here's what you need to do.

DevFeed: [Canada's CPCSC and Bill C-8 are coming. Here's what you need to do.](<https://devfeed.tech/articles/canada-s-cpcsc-and-bill-c-8-are-coming-here-s-what-you-need-to-do-12917.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/canadas-cpcsc-and-bill-c-8-are-coming-heres-what-you-need-to-do>)

Published: 2026-05-14T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Critical Infrastructure](<https://devfeed.tech/topics/critical-infrastructure.md>), [Security](<https://devfeed.tech/topics/security.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Cloud Native Ecosystem](<https://devfeed.tech/topics/cloud-native-ecosystem.md>)

Tags: [bill-c-8](<https://devfeed.tech/tags/bill-c-8.md>), [canada-cmmc](<https://devfeed.tech/tags/canada-cmmc.md>), [canadian-program-for-cyber-security-certification](<https://devfeed.tech/tags/canadian-program-for-cyber-security-certification.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [cmmc](<https://devfeed.tech/tags/cmmc.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cpcsc](<https://devfeed.tech/tags/cpcsc.md>), [critical-infrastructure](<https://devfeed.tech/tags/critical-infrastructure.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [federal-compliance](<https://devfeed.tech/tags/federal-compliance.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [nist](<https://devfeed.tech/tags/nist.md>), [zero-cve-containers](<https://devfeed.tech/tags/zero-cve-containers.md>)

### AI overview

This article explains Canada's Canadian Program for Cyber Security Certification (CPCSC) and Bill C-8, focusing on the implications for defence suppliers and organizations in critical infrastructure. It describes the CPCSC as a mandatory cybersecurity certification regime, compares its technical basis with CMMC and NIST Special Publications 800-171 and 800-172, and outlines why organizations should prepare for Level 1 requirements. The article also describes how Chainguard can help Canadian defence suppliers meet those requirements with secure, zero-CVE containers.

### Source excerpt

CPCSC compliance is coming fast. Learn how Chainguard helps Canadian defence suppliers meet Level 1 requirements with secure, zero-CVE containers.

## Chainguard brings first-party RHEL 9 and RHEL 10 RPM support to Chainguard OS, joins FINOS

DevFeed: [Chainguard brings first-party RHEL 9 and RHEL 10 RPM support to Chainguard OS, joins FINOS](<https://devfeed.tech/articles/chainguard-brings-first-party-rhel-9-and-rhel-10-rpm-support-to-chainguard-os-joins-finos-12933.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-brings-first-party-rhel-9-and-rhel-10-rpm-support-to-chainguard-os-joins-finos>)

Published: 2026-05-11T00:00:00Z

Content type: news

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard os](<https://devfeed.tech/topics/chainguard-os.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [Security](<https://devfeed.tech/topics/security.md>), [Critical Infrastructure](<https://devfeed.tech/topics/critical-infrastructure.md>), [Package Management](<https://devfeed.tech/topics/package-management.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Cloud Native Ecosystem](<https://devfeed.tech/topics/cloud-native-ecosystem.md>), [Resilience](<https://devfeed.tech/topics/resilience.md>), [APK](<https://devfeed.tech/topics/apk.md>), [Linux](<https://devfeed.tech/topics/linux.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-finserv](<https://devfeed.tech/tags/chainguard-finserv.md>), [chainguard-os](<https://devfeed.tech/tags/chainguard-os.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cloud-native](<https://devfeed.tech/tags/cloud-native.md>), [compatibility](<https://devfeed.tech/tags/compatibility.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container](<https://devfeed.tech/tags/container.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [critical-infrastructure](<https://devfeed.tech/tags/critical-infrastructure.md>), [cve](<https://devfeed.tech/tags/cve.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [hardening](<https://devfeed.tech/tags/hardening.md>), [images](<https://devfeed.tech/tags/images.md>), [linux](<https://devfeed.tech/tags/linux.md>), [make](<https://devfeed.tech/tags/make.md>), [mythos](<https://devfeed.tech/tags/mythos.md>), [open](<https://devfeed.tech/tags/open.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [project-glasswing](<https://devfeed.tech/tags/project-glasswing.md>), [rhel](<https://devfeed.tech/tags/rhel.md>), [rhel-10](<https://devfeed.tech/tags/rhel-10.md>), [rhel-9](<https://devfeed.tech/tags/rhel-9.md>)

### AI overview

Chainguard announces first-party RHEL 9 and RHEL 10 RPM compatibility for packages in Chainguard Containers built on Chainguard OS. The company also announces that it is joining FINOS to support open source collaboration in financial infrastructure.

### Source excerpt

Chainguard adds first-party RHEL 9/10 RPM compatibility and joins FINOS, helping financial institutions modernize securely for the AI-driven threat era.

## How does Chainguard prevent malware in Chainguard Libraries?

DevFeed: [How does Chainguard prevent malware in Chainguard Libraries?](<https://devfeed.tech/articles/how-does-chainguard-prevent-malware-in-chainguard-libraries-13088.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/how-does-chainguard-prevent-malware-in-chainguard-libraries>)

Published: 2026-05-01T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard libraries](<https://devfeed.tech/topics/chainguard-libraries.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [malware](<https://devfeed.tech/tags/malware.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>)

### AI overview

Chainguard explains how Chainguard Libraries protects customers from malware in open source dependencies by building packages from source in a controlled environment. The article describes binary artifacts without corresponding source code as a common supply-chain attack vector and highlights Chainguard's AI-powered Factory for reproducing packages at scale.

### Source excerpt

With Chainguard Libraries, customers rely on a single controlled, auditable system.

## Chainguard EKS add-ons are now available in the AWS Marketplace

DevFeed: [Chainguard EKS add-ons are now available in the AWS Marketplace](<https://devfeed.tech/articles/chainguard-eks-add-ons-are-now-available-in-the-aws-marketplace-12942.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-eks-add-ons-are-now-available-in-the-aws-marketplace>)

Published: 2026-04-30T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Amazon EKS](<https://devfeed.tech/topics/amazon-eks.md>), [aws-marketplace](<https://devfeed.tech/topics/aws-marketplace.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Security](<https://devfeed.tech/topics/security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Image](<https://devfeed.tech/topics/image.md>), [Containers](<https://devfeed.tech/topics/containers.md>)

Tags: [aws-eks-add-ons](<https://devfeed.tech/tags/aws-eks-add-ons.md>), [aws-marketplace](<https://devfeed.tech/tags/aws-marketplace.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-aws](<https://devfeed.tech/tags/chainguard-aws.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-eks-add-ons](<https://devfeed.tech/tags/chainguard-eks-add-ons.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [eks-add-ons](<https://devfeed.tech/tags/eks-add-ons.md>), [fips](<https://devfeed.tech/tags/fips.md>), [fips-140-3](<https://devfeed.tech/tags/fips-140-3.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>)

### AI overview

Chainguard announces that its EKS add-ons are available in AWS Marketplace. The five add-ons provide networking, DNS, storage, and traffic-management components, with zero-known-CVE images and FIPS 140-3 validation for organizations that need greater control over security and compliance.

### Source excerpt

Chainguard delivers zero-CVE, FIPS 140-3 EKS add-ons on AWS Marketplace, simplifying secure Kubernetes for regulated environments with full control.

[Next page](<https://devfeed.tech/topics/chainguard.md?cursor=WyIyMDI2LTA0LTMwVDAwOjAwOjAwKzAwOjAwIiwgIjUyN2M3Y2MzLTNlNzctNDEyOS1hMDU5LTdiMjQxMjY4YjQzYyJd>)