# sigstore

Sigstore is an open-source project providing tools and services for signing and verifying software artifacts to improve software supply-chain security.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## What it took to reach 1 billion build manifests

DevFeed: [What it took to reach 1 billion build manifests](<https://devfeed.tech/articles/what-it-took-to-reach-1-billion-build-manifests-13318.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/what-it-took-to-reach-1-billion-build-manifests>)

Published: 2026-09-03T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [chainguard os](<https://devfeed.tech/topics/chainguard-os.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [NumPy](<https://devfeed.tech/topics/numpy.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-factory](<https://devfeed.tech/tags/chainguard-factory.md>), [chainguard-os](<https://devfeed.tech/tags/chainguard-os.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [go](<https://devfeed.tech/tags/go.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>)

### AI overview

Chainguard describes how it doubled container build output from 500 million to more than 1 billion manifests in six months. The article explains how Chainguard Factory and Chainguard OS support continuous rebuilds, while using source builds, SLSA Level 3 provenance, Sigstore signatures, and full SBOMs.

### Source excerpt

Chainguard doubled its container build output in six months. Learn how Factory 2.0 uses AI and reconciliation to rebuild secure software at scale.

## SOC 2 Controls for Non-Human Identities: CC6, CC7, and CC8

DevFeed: [SOC 2 Controls for Non-Human Identities: CC6, CC7, and CC8](<https://devfeed.tech/articles/soc-2-controls-for-non-human-identities-cc6-cc7-and-cc8-29856.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/soc2-non-human-identities/>)

Author: info@goteleport.com (Kayne McGladrey)

Published: 2026-06-09T00:00:00Z

Content type: tutorial

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [soc 2](<https://devfeed.tech/topics/soc-2.md>), [audit](<https://devfeed.tech/topics/audit.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>)

Tags: [audit](<https://devfeed.tech/tags/audit.md>), [authorization](<https://devfeed.tech/tags/authorization.md>), [certificates](<https://devfeed.tech/tags/certificates.md>), [credentials](<https://devfeed.tech/tags/credentials.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>)

### AI overview

This article explains how Teleport maps workload attestation, short-lived certificates, access rules, and audit logs for non-human identities to SOC 2 controls CC6, CC7, and CC8. It describes evidence auditors can use, including access rules, denied credential issuance logs, and Sigstore policy configurations where enabled.

### Source excerpt

Discover how to meet SOC 2 CC6, CC7, and CC8 controls for non-human identities.

## Securely Signing WebAssembly Components with Cosign (OIDC)

DevFeed: [Securely Signing WebAssembly Components with Cosign (OIDC)](<https://devfeed.tech/articles/securely-signing-webassembly-components-with-cosign-oidc-15432.md>)

Original publisher: [Read original article](<https://wasmcloud.com/blog/2025-09-02-securely-signing-wasm-components-with-cosign-oidc/>)

Author: Liam Randall

Published: 2025-09-02T00:00:00Z

Content type: tutorial

Language: en

Sources: [wasmCloud Blog](<https://devfeed.tech/sources/wasmcloud-blog.md>)

Topics: [WebAssembly](<https://devfeed.tech/topics/web-assembly.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>), [GitHub Container Registry](<https://devfeed.tech/topics/github-container-registry.md>), [OpenID connect (OIDC)](<https://devfeed.tech/topics/oidc.md>), [Rust](<https://devfeed.tech/topics/rust.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [cli](<https://devfeed.tech/tags/cli.md>), [cosign](<https://devfeed.tech/tags/cosign.md>), [github-container-registry](<https://devfeed.tech/tags/github-container-registry.md>), [integrity](<https://devfeed.tech/tags/integrity.md>), [oci-registry](<https://devfeed.tech/tags/oci-registry.md>), [oidc](<https://devfeed.tech/tags/oidc.md>), [registry](<https://devfeed.tech/tags/registry.md>), [security](<https://devfeed.tech/tags/security.md>), [signing](<https://devfeed.tech/tags/signing.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [verify](<https://devfeed.tech/tags/verify.md>), [wasi](<https://devfeed.tech/tags/wasi.md>), [wasm-components](<https://devfeed.tech/tags/wasm-components.md>), [wasmcloud](<https://devfeed.tech/tags/wasmcloud.md>), [webassembly](<https://devfeed.tech/tags/webassembly.md>), [webassembly-wasmcloud-security-cosign-oidc-signing-oci-registry-supply-chain-security-wasi-wasm-comp](<https://devfeed.tech/tags/webassembly-wasmcloud-security-cosign-oidc-signing-oci-registry-supply-chain-security-wasi-wasm-comp.md>)

### AI overview

A tutorial showing how to build a Rust-based WebAssembly component, sign it with Sigstore Cosign using OIDC identity, push it to GitHub Container Registry, and verify it before execution.

### Source excerpt

Build, sign, and verify WebAssembly component artifacts using Sigstore's cosign with OIDC identity--secure, registry-native signatures for wasmCloud.

## No CVEs, No Surprises: Chainguard and the UK Software Security Code of Practice

DevFeed: [No CVEs, No Surprises: Chainguard and the UK Software Security Code of Practice](<https://devfeed.tech/articles/no-cves-no-surprises-chainguard-and-the-uk-software-security-code-of-practice-13187.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/no-cves-no-surprises-chainguard-and-the-uk-software-security-code-of-practice>)

Published: 2025-06-09T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [sdlc](<https://devfeed.tech/topics/sdlc.md>), [Development](<https://devfeed.tech/topics/development.md>), [Cloud Native Ecosystem](<https://devfeed.tech/topics/cloud-native-ecosystem.md>), [Resilience](<https://devfeed.tech/topics/resilience.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>), [Deployment](<https://devfeed.tech/topics/deployment.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [cyber-resilience-act](<https://devfeed.tech/tags/cyber-resilience-act.md>), [emea](<https://devfeed.tech/tags/emea.md>), [resilience](<https://devfeed.tech/tags/resilience.md>), [security](<https://devfeed.tech/tags/security.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [software-development](<https://devfeed.tech/tags/software-development.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [sscop](<https://devfeed.tech/tags/sscop.md>), [ssdf](<https://devfeed.tech/tags/ssdf.md>), [testing](<https://devfeed.tech/tags/testing.md>), [uk](<https://devfeed.tech/tags/uk.md>), [united-kingdom](<https://devfeed.tech/tags/united-kingdom.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

The article explains the United Kingdom's Software Security Code of Practice and maps its 14 principles across secure development, build integrity, deployment, and customer communication. It presents Chainguard Containers, provenance attestations, and signed SBOMs as ways Chainguard supports secure-by-default software and compliance efforts.

### Source excerpt

Chainguard Containers support compliance with the United Kingdom's Software Security Code of Practice. Check out what the framework entails and how we help.

## Workload Identity Meets Supply Chain Security: Teleport's Sigstore Integration

DevFeed: [Workload Identity Meets Supply Chain Security: Teleport's Sigstore Integration](<https://devfeed.tech/articles/workload-identity-meets-supply-chain-security-teleport-s-sigstore-integration-29974.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/workload-identity-meets-supply-chain-security/>)

Author: daniel.upton@goteleport.com (Dan Upton)

Published: 2025-06-05T00:00:00Z

Content type: tutorial

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [sigstore](<https://devfeed.tech/topics/sigstore.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [OpenID connect (OIDC)](<https://devfeed.tech/topics/oidc.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>)

Tags: [attestation](<https://devfeed.tech/tags/attestation.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [oidc](<https://devfeed.tech/tags/oidc.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [security](<https://devfeed.tech/tags/security.md>), [signing](<https://devfeed.tech/tags/signing.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>)

### AI overview

This article explains how Teleport integrates with Sigstore to strengthen software supply chain security for workload identity. It describes signing software artifacts and attestations, and explains Sigstore's keyless approach using single-use certificates tied to OIDC identities.

### Source excerpt

Learn how to use Teleport's integration with Sigstore to build supply chain security into your workload identity.

## Chainguard's Catalog of 1,300+ Container Images: Secure Foundation for Every Engineering Team

DevFeed: [Chainguard's Catalog of 1,300+ Container Images: Secure Foundation for Every Engineering Team](<https://devfeed.tech/articles/chainguard-s-catalog-of-1-300-container-images-secure-foundation-for-every-engineering-team-12986.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguards-catalog-of-1-300-container-images-secure-foundation-for-every-engineering-team>)

Published: 2025-05-12T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [chainguard os](<https://devfeed.tech/topics/chainguard-os.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-catalog](<https://devfeed.tech/tags/chainguard-catalog.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-factory](<https://devfeed.tech/tags/chainguard-factory.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [chainguard-os](<https://devfeed.tech/tags/chainguard-os.md>), [container](<https://devfeed.tech/tags/container.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve-remediation](<https://devfeed.tech/tags/cve-remediation.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [safe-source-for-open-source](<https://devfeed.tech/tags/safe-source-for-open-source.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [slsa](<https://devfeed.tech/tags/slsa.md>)

### AI overview

Chainguard describes its catalog of more than 1,300 minimal, zero-CVE container images, built from source on Chainguard OS and maintained through the Chainguard Factory. The article highlights daily rebuilds, automated dependency and CVE handling, and default SBOMs, SLSA provenance, and Sigstore signatures.

### Source excerpt

Chainguard Containers is a catalog of over 1,300 container images powered by Chainguard OS and the Chainguard Factory. Discover the safe source for open source.

## Chainguard's Vision for a Safer Software Supply Chain

DevFeed: [Chainguard's Vision for a Safer Software Supply Chain](<https://devfeed.tech/articles/chainguard-s-vision-for-a-safer-software-supply-chain-12998.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguards-vision-for-a-safer-software-supply-chain>)

Published: 2025-01-30T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Security](<https://devfeed.tech/topics/security.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve](<https://devfeed.tech/tags/cve.md>), [integrity](<https://devfeed.tech/tags/integrity.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [security](<https://devfeed.tech/tags/security.md>), [signing](<https://devfeed.tech/tags/signing.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [software-development](<https://devfeed.tech/tags/software-development.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [supply-chain-attacks](<https://devfeed.tech/tags/supply-chain-attacks.md>), [supply-chain-integrity](<https://devfeed.tech/tags/supply-chain-integrity.md>)

### AI overview

Chainguard presents its vision for secure software development, arguing that security and innovation should advance together. The article advocates signed binaries, verified dependencies, source-built container images, cryptographic build evidence, and broader adoption of supply-chain integrity standards such as Sigstore.

### Source excerpt

Chainguard is building the future of secure software development, where security and innovation move in lockstep and every line of code makes software safer.

## Check out Chainguard at KubeCon NA in Salt Lake City on November 12-15!

DevFeed: [Check out Chainguard at KubeCon NA in Salt Lake City on November 12-15!](<https://devfeed.tech/articles/check-out-chainguard-at-kubecon-na-in-salt-lake-city-on-november-12-15-13006.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/check-out-chainguard-at-kubecon-na-in-salt-lake-city-on-november-12-15>)

Published: 2024-10-16T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>), [distroless](<https://devfeed.tech/topics/distroless.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Security](<https://devfeed.tech/topics/security.md>), [devrel](<https://devfeed.tech/topics/devrel.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cloud-native-rejekts](<https://devfeed.tech/tags/cloud-native-rejekts.md>), [conference](<https://devfeed.tech/tags/conference.md>), [container](<https://devfeed.tech/tags/container.md>), [debug](<https://devfeed.tech/tags/debug.md>), [developers](<https://devfeed.tech/tags/developers.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [distroless](<https://devfeed.tech/tags/distroless.md>), [event](<https://devfeed.tech/tags/event.md>), [kubecon](<https://devfeed.tech/tags/kubecon.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [multi-arch](<https://devfeed.tech/tags/multi-arch.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [security](<https://devfeed.tech/tags/security.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [sigstorecon](<https://devfeed.tech/tags/sigstorecon.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>)

### AI overview

Chainguard announces its participation in KubeCon North America 2024 in Salt Lake City, including product demonstrations of Chainguard Images and appearances at Cloud-Native Rejekts and SigstoreCon.

### Source excerpt

Chainguard is going to be at KubeCon North America 2024 in Salt Lake City. See where we'll be and how you can meet us to learn more about Chainguard Images.

## Chainguard announces new Sigstore Images to bring critical software supply chain tooling to enterprises

DevFeed: [Chainguard announces new Sigstore Images to bring critical software supply chain tooling to enterprises](<https://devfeed.tech/articles/chainguard-announces-new-sigstore-images-to-bring-critical-software-supply-chain-tooling-to-enterprises-12927.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-announces-new-sigstore-images-to-bring-critical-software-supply-chain-tooling-to-enterprises>)

Published: 2023-11-14T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [cve](<https://devfeed.tech/tags/cve.md>), [helm-charts](<https://devfeed.tech/tags/helm-charts.md>), [image](<https://devfeed.tech/tags/image.md>), [on-prem](<https://devfeed.tech/tags/on-prem.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

Chainguard launched a Sigstore bundle of 17 images for organizations that need to run a private, on-premises Sigstore stack. The bundle is compatible with official Helm charts and includes components such as Fulcio, Rekor, Trillian, CT Log, Redis, Cosign, and a Timestamp Authority.

### Source excerpt

Revolutionize your enterprise's software supply chain with Chainguard's new Sigstore images.

## Securing the ML supply chain with new Chainguard AI Images

DevFeed: [Securing the ML supply chain with new Chainguard AI Images](<https://devfeed.tech/articles/securing-the-ml-supply-chain-with-new-chainguard-ai-images-13225.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/securing-the-ml-supply-chain-with-new-chainguard-ai-images>)

Published: 2023-08-24T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Machine learning](<https://devfeed.tech/topics/machine-learning.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-ai](<https://devfeed.tech/tags/chainguard-ai.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [conda-image](<https://devfeed.tech/tags/conda-image.md>), [cve-remediation](<https://devfeed.tech/tags/cve-remediation.md>), [kubeflow-image](<https://devfeed.tech/tags/kubeflow-image.md>), [ml-security](<https://devfeed.tech/tags/ml-security.md>), [ml-supply-chain](<https://devfeed.tech/tags/ml-supply-chain.md>), [open-ai-image](<https://devfeed.tech/tags/open-ai-image.md>), [openai-image](<https://devfeed.tech/tags/openai-image.md>), [python-image](<https://devfeed.tech/tags/python-image.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [secure-images](<https://devfeed.tech/tags/secure-images.md>), [security](<https://devfeed.tech/tags/security.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [software-signatures](<https://devfeed.tech/tags/software-signatures.md>)

### AI overview

Chainguard announces a Chainguard Images AI bundle for securing the ML supply chain across the AI workload lifecycle. The collection includes development, workflow management, deployment, and vector database images, with software signatures, SBOMs, and CVE remediation.

### Source excerpt

Chainguard AI Images: Your pathway to a secure ML supply chain with hardened, efficient AI/ML lifecycle solutions.

## Elastic partners with Chainguard on Software Supply Chain security and SLSA assessment

DevFeed: [Elastic partners with Chainguard on Software Supply Chain security and SLSA assessment](<https://devfeed.tech/articles/elastic-partners-with-chainguard-on-software-supply-chain-security-and-slsa-assessment-13026.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/elastic-partners-with-chainguard-on-software-supply-chain-security-and-slsa-assessment>)

Published: 2023-07-26T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Security](<https://devfeed.tech/topics/security.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [security](<https://devfeed.tech/tags/security.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [slsa-assessement](<https://devfeed.tech/tags/slsa-assessement.md>), [slsa-levels](<https://devfeed.tech/tags/slsa-levels.md>), [software-artifact-signing](<https://devfeed.tech/tags/software-artifact-signing.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [trust](<https://devfeed.tech/tags/trust.md>)

### AI overview

Elastic partnered with Chainguard to assess its software supply chain using the SLSA framework. The article describes supply-chain risks across source, build, dependencies, and packages, and highlights software artifact signing with Sigstore as a security measure.

### Source excerpt

Elastic and Chainguard unite for enhanced software supply chain security and SLSA assessment.

## Introducing "Speranza": Enhancing software signing with privacy and usability

DevFeed: [Introducing "Speranza": Enhancing software signing with privacy and usability](<https://devfeed.tech/articles/introducing-speranza-enhancing-software-signing-with-privacy-and-usability-13121.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/introducing-speranza-enhancing-software-signing-with-privacy-and-usability>)

Published: 2023-05-30T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>), [OpenID connect (OIDC)](<https://devfeed.tech/topics/oidc.md>), [npm](<https://devfeed.tech/topics/npm.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-labs](<https://devfeed.tech/tags/chainguard-labs.md>), [cryptography](<https://devfeed.tech/tags/cryptography.md>), [digital-signatures](<https://devfeed.tech/tags/digital-signatures.md>), [oidc](<https://devfeed.tech/tags/oidc.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [pii](<https://devfeed.tech/tags/pii.md>), [privacy](<https://devfeed.tech/tags/privacy.md>), [security](<https://devfeed.tech/tags/security.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [software-artifact-signing](<https://devfeed.tech/tags/software-artifact-signing.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [software-supply-chain-security-research](<https://devfeed.tech/tags/software-supply-chain-security-research.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>)

### AI overview

Chainguard Labs introduces Speranza, a research project for usable, privacy-friendly software signing. The article explains how it aims to improve software supply chain security while addressing the usability problems of long-lived cryptographic keys and the privacy risks of exposing maintainers' identities or metadata. It also discusses potential applications in open source package repositories and enterprise deployments of Sigstore.

### Source excerpt

Chainguard Labs announces, "Speranza: Usable, privacy-friendly software signing," to help balance usability and privacy for software signing techniques.

## Open source software takes center stage at RSA

DevFeed: [Open source software takes center stage at RSA](<https://devfeed.tech/articles/open-source-software-takes-center-stage-at-rsa-13196.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/open-source-software-takes-center-stage-at-rsa>)

Published: 2023-04-24T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [npm](<https://devfeed.tech/topics/npm.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>), [Python](<https://devfeed.tech/topics/python.md>), [OpenID connect (OIDC)](<https://devfeed.tech/topics/oidc.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>)

Tags: [npm](<https://devfeed.tech/tags/npm.md>), [oidc](<https://devfeed.tech/tags/oidc.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [open-source-software-security](<https://devfeed.tech/tags/open-source-software-security.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [python](<https://devfeed.tech/tags/python.md>), [security](<https://devfeed.tech/tags/security.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>)

### AI overview

The article examines why open-source software security became a major topic at the 2023 RSA Conference. It discusses software supply-chain risks, including the Log4j exploit, and highlights package provenance in npm, Sigstore-based signing and verification, and trusted publishers using OpenID Connect in PyPI.

### Source excerpt

Open source software security takes center stage in the 2023 RSA Trends Report. Learn why it's a top concern.

## npm + Sigstore: Making Javascript secure by default

DevFeed: [npm + Sigstore: Making Javascript secure by default](<https://devfeed.tech/articles/npm-sigstore-making-javascript-secure-by-default-13190.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/npm-sigstore-making-javascript-secure-by-default>)

Published: 2023-04-19T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [npm](<https://devfeed.tech/topics/npm.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [Security](<https://devfeed.tech/topics/security.md>), [Package manager](<https://devfeed.tech/topics/package-manager.md>)

Tags: [javascript](<https://devfeed.tech/tags/javascript.md>), [npm](<https://devfeed.tech/tags/npm.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [rekor](<https://devfeed.tech/tags/rekor.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [signing](<https://devfeed.tech/tags/signing.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [verification](<https://devfeed.tech/tags/verification.md>)

### AI overview

npm announced a public beta for end-to-end signing of npm packages with Sigstore. The integration lets developers verify package build provenance and records signed attestations in the Rekor transparency log.

### Source excerpt

npm launches Sigstore beta for end-to-end package signing, improving developer trust and security.

## Chainguard open sources new policy catalog for Sigstore policy-controller

DevFeed: [Chainguard open sources new policy catalog for Sigstore policy-controller](<https://devfeed.tech/articles/chainguard-open-sources-new-policy-catalog-for-sigstore-policy-controller-12974.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-open-sources-new-policy-catalog-for-sigstore-policy-controller>)

Published: 2023-04-18T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [sigstore policy controller](<https://devfeed.tech/topics/sigstore-policy-controller.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [rego](<https://devfeed.tech/topics/rego.md>), [YAML](<https://devfeed.tech/topics/yaml.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [kubernetes-security](<https://devfeed.tech/tags/kubernetes-security.md>), [rego](<https://devfeed.tech/tags/rego.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [security](<https://devfeed.tech/tags/security.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [sigstore-policy-controller](<https://devfeed.tech/tags/sigstore-policy-controller.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [trust](<https://devfeed.tech/tags/trust.md>), [verification](<https://devfeed.tech/tags/verification.md>), [yaml](<https://devfeed.tech/tags/yaml.md>)

### AI overview

Chainguard open sources a policy catalog for Sigstore policy-controller. The catalog provides policies that organizations and open source projects can adopt incrementally to improve software supply-chain security, with community contributions supported.

### Source excerpt

To help unlock benefits of the Sigstore policy-controller, Chainguard open sources a policy catalog that can be adopted to improve your supply chain security.

## Join Chainguard at KubeCon EU in Amsterdam April 19-21!

DevFeed: [Join Chainguard at KubeCon EU in Amsterdam April 19-21!](<https://devfeed.tech/articles/join-chainguard-at-kubecon-eu-in-amsterdam-april-19-21-13131.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/join-chainguard-at-kubecon-eu-in-amsterdam-april-19-21>)

Published: 2023-04-13T00:00:00Z

Content type: news

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [chainguard enforce](<https://devfeed.tech/topics/chainguard-enforce.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>), [SPIRE](<https://devfeed.tech/topics/spire.md>), [eBPF](<https://devfeed.tech/topics/ebpf.md>), [observability](<https://devfeed.tech/topics/observability.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-enforce](<https://devfeed.tech/tags/chainguard-enforce.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [cloud-native](<https://devfeed.tech/tags/cloud-native.md>), [cncf](<https://devfeed.tech/tags/cncf.md>), [cves](<https://devfeed.tech/tags/cves.md>), [ebpf](<https://devfeed.tech/tags/ebpf.md>), [kubecon](<https://devfeed.tech/tags/kubecon.md>), [kubecon-eu](<https://devfeed.tech/tags/kubecon-eu.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [linux-foundation](<https://devfeed.tech/tags/linux-foundation.md>), [observability](<https://devfeed.tech/tags/observability.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [security](<https://devfeed.tech/tags/security.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [spire](<https://devfeed.tech/tags/spire.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>)

### AI overview

Chainguard announces its participation in KubeCon EU 2023 in Amsterdam, including booth demonstrations of the Chainguard platform and Chainguard Images. The article highlights comparisons of minimal container image size and CVE counts, Chainguard Enforce visibility into deployed software and dependencies, and conference sessions on CI/CD security on Kubernetes, SLSA, Tekton, Sigstore, SPIRE, and Falco.

### Source excerpt

Join Chainguard at KubeCon EU in Amsterdam, April 19-21, for groundbreaking insights into cloud-native technologies.

## It all started with a commit: Celebrating 6 years of Distroless

DevFeed: [It all started with a commit: Celebrating 6 years of Distroless](<https://devfeed.tech/articles/it-all-started-with-a-commit-celebrating-6-years-of-distroless-13129.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/it-all-started-with-a-commit-celebrating-6-years-of-distroless>)

Published: 2023-04-12T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [distroless](<https://devfeed.tech/topics/distroless.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [bazel](<https://devfeed.tech/topics/bazel.md>), [Debian](<https://devfeed.tech/topics/debian.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [Go](<https://devfeed.tech/topics/go.md>)

Tags: [bazel](<https://devfeed.tech/tags/bazel.md>), [c-plus-plus](<https://devfeed.tech/tags/c-plus-plus.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [debian](<https://devfeed.tech/tags/debian.md>), [digital-signatures](<https://devfeed.tech/tags/digital-signatures.md>), [distroless](<https://devfeed.tech/tags/distroless.md>), [distroless-containers](<https://devfeed.tech/tags/distroless-containers.md>), [go](<https://devfeed.tech/tags/go.md>), [java](<https://devfeed.tech/tags/java.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [python](<https://devfeed.tech/tags/python.md>), [release-engineering](<https://devfeed.tech/tags/release-engineering.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [verify](<https://devfeed.tech/tags/verify.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

The article commemorates six years of Distroless, describing its goal of creating more secure and efficient container images by removing non-essential components. It covers the Bazel-based build tooling, language runtimes, Kubernetes adoption, vulnerability-management benefits, and later integration with Sigstore for container signing and authenticity verification. It also introduces the subsequent development of Chainguard Images.

### Source excerpt

The goal of Distroless is to provide a more secure and efficient way to package and run software in containers by using only essential components.

## ICYMI: What's new in Chainguard Academy

DevFeed: [ICYMI: What's new in Chainguard Academy](<https://devfeed.tech/articles/icymi-what-s-new-in-chainguard-academy-13099.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/icymi-whats-new-in-chainguard-academy>)

Published: 2023-04-03T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [openvex](<https://devfeed.tech/topics/openvex.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-academy](<https://devfeed.tech/tags/chainguard-academy.md>), [chainguard-enforce](<https://devfeed.tech/tags/chainguard-enforce.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [openvex](<https://devfeed.tech/tags/openvex.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [sigstore-policy-controller](<https://devfeed.tech/tags/sigstore-policy-controller.md>), [software-education](<https://devfeed.tech/tags/software-education.md>), [software-security-practices](<https://devfeed.tech/tags/software-security-practices.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Chainguard Academy has expanded to more than 300 tutorials, documentation pages, and reference materials covering open source projects and Chainguard products. The article highlights resources for Chainguard Images and Wolfi Images, OpenVEX, SBOMs, and Sigstore policy-controller.

### Source excerpt

See what's new in Chainguard Academy to help you level up your software supply chain and open source security knowledge.

## New Chainguard Academy tutorial: Cosign the manual way

DevFeed: [New Chainguard Academy tutorial: Cosign the manual way](<https://devfeed.tech/articles/new-chainguard-academy-tutorial-cosign-the-manual-way-13173.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/new-chainguard-academy-tutorial-cosign-the-manual-way>)

Published: 2023-03-30T00:00:00Z

Content type: tutorial

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Tutorial](<https://devfeed.tech/topics/tutorial.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>), [Security](<https://devfeed.tech/topics/security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>), [Software](<https://devfeed.tech/topics/software.md>)

Tags: [algorithm](<https://devfeed.tech/tags/algorithm.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-academy](<https://devfeed.tech/tags/chainguard-academy.md>), [cli](<https://devfeed.tech/tags/cli.md>), [cosign](<https://devfeed.tech/tags/cosign.md>), [rekor](<https://devfeed.tech/tags/rekor.md>), [rsa](<https://devfeed.tech/tags/rsa.md>), [security](<https://devfeed.tech/tags/security.md>), [sha-256](<https://devfeed.tech/tags/sha-256.md>), [signing](<https://devfeed.tech/tags/signing.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [software-artifact-signing](<https://devfeed.tech/tags/software-artifact-signing.md>), [transparency-log](<https://devfeed.tech/tags/transparency-log.md>), [trust](<https://devfeed.tech/tags/trust.md>), [tutorial](<https://devfeed.tech/tags/tutorial.md>), [verify](<https://devfeed.tech/tags/verify.md>)

### AI overview

This article introduces a Chainguard Academy tutorial that explains Cosign's blob-signing capabilities. It covers generating an RSA key pair, signing data with SHA-256, uploading signatures to the Rekor transparency log, and verifying the signature.

### Source excerpt

New Chainguard Academy tutorial unpacks Cosign the manual way and explores Cosign's blob signing capabilities.

## SBOMs in a multi-architecture world

DevFeed: [SBOMs in a multi-architecture world](<https://devfeed.tech/articles/sboms-in-a-multi-architecture-world-13215.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/sboms-in-a-multi-architecture-world>)

Published: 2023-02-22T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [container images](<https://devfeed.tech/topics/container-images.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>)

Tags: [architecture](<https://devfeed.tech/tags/architecture.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-enforce](<https://devfeed.tech/tags/chainguard-enforce.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>)

### AI overview

This article explains how Chainguard handles SBOMs for multi-architecture container images. Each architecture-specific image carries its own standalone SBOM, while the image index avoids duplicating variant information and instead references the constituent metadata.

### Source excerpt

As the world becomes more architecturally diverse, we at Chainguard want to make sure our users are armed with the tools they need to remain secure.

## Chainguard named an IDC Innovator for open source software supply chain security

DevFeed: [Chainguard named an IDC Innovator for open source software supply chain security](<https://devfeed.tech/articles/chainguard-named-an-idc-innovator-for-open-source-software-supply-chain-security-12970.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-named-an-idc-innovator-for-open-source-software-supply-chain-security>)

Published: 2023-02-15T00:00:00Z

Content type: news

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [idc](<https://devfeed.tech/topics/idc.md>), [chainguard enforce](<https://devfeed.tech/topics/chainguard-enforce.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [DevSecOps](<https://devfeed.tech/topics/devsecops.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>), [DevOps](<https://devfeed.tech/topics/devops.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-enforce](<https://devfeed.tech/tags/chainguard-enforce.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [idc-innovators](<https://devfeed.tech/tags/idc-innovators.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>)

### AI overview

Chainguard was named an IDC Innovator in a 2023 report on open source software supply chain security. The article describes Chainguard's developer platform, including Chainguard Images and Chainguard Enforce, and its use of SLSA and Sigstore to integrate security checkpoints throughout the software development lifecycle.

### Source excerpt

The IDC Innovators report profiles Chainguard as one of three companies offering enhanced capabilities for open source software supply chain management.

## Not all that's signed is secure: Verify the right way with TUF and Sigstore

DevFeed: [Not all that's signed is secure: Verify the right way with TUF and Sigstore](<https://devfeed.tech/articles/not-all-that-s-signed-is-secure-verify-the-right-way-with-tuf-and-sigstore-13189.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/not-all-thats-signed-is-secure-verify-the-right-way-with-tuf-and-sigstore>)

Published: 2023-02-08T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [sigstore](<https://devfeed.tech/topics/sigstore.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard enforce](<https://devfeed.tech/topics/chainguard-enforce.md>)

Tags: [chainguard-enforce](<https://devfeed.tech/tags/chainguard-enforce.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [policy](<https://devfeed.tech/tags/policy.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [signing](<https://devfeed.tech/tags/signing.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [software-signatures](<https://devfeed.tech/tags/software-signatures.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [supply-chain-attacks](<https://devfeed.tech/tags/supply-chain-attacks.md>), [verification](<https://devfeed.tech/tags/verification.md>)

### AI overview

The article summarizes a talk on using Sigstore and The Update Framework (TUF) to create verification policies for securing software supply chains. It explains that signing alone does not provide sufficient protection, because verifying the wrong way can leave systems vulnerable to supply chain attacks. It presents TUF as a way to build flexible verification policies and describes how Sigstore supports easier signing with rigorous verification.

### Source excerpt

CloudNativeSecurityCon: Marina Moore & Zack Newman on using Sigstore & The Update Framework TUF to create verification policies to secure software supply chains

## Chainguard Image now available for Kubectl

DevFeed: [Chainguard Image now available for Kubectl](<https://devfeed.tech/articles/chainguard-image-now-available-for-kubectl-12947.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-image-now-available-for-kubectl>)

Published: 2023-02-07T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Security](<https://devfeed.tech/topics/security.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>), [vulnerability scanning](<https://devfeed.tech/topics/vulnerability-scanning.md>), [Cloud Native Ecosystem](<https://devfeed.tech/topics/cloud-native-ecosystem.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [ci](<https://devfeed.tech/topics/ci.md>), [GitOps](<https://devfeed.tech/topics/gitops.md>)

Tags: [base-images](<https://devfeed.tech/tags/base-images.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [ci](<https://devfeed.tech/tags/ci.md>), [containers](<https://devfeed.tech/tags/containers.md>), [gitops](<https://devfeed.tech/tags/gitops.md>), [kubectl](<https://devfeed.tech/tags/kubectl.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [security](<https://devfeed.tech/tags/security.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>)

### AI overview

Chainguard announces a kubectl image in the Chainguard Images catalog. The image supports multiple architectures, including arm64, is 75% smaller than a commonly used alternative, includes SBOMs, and is signed with Sigstore. Chainguard reports zero known CVEs at publication time.

### Source excerpt

Kubectl added to Chainguard Images catalog. Chainguard kubectl build is 75% smaller than the usual image used & is the only supported image with arm64 support.

## GoReleaser v1 -- one year later

DevFeed: [GoReleaser v1 -- one year later](<https://devfeed.tech/articles/goreleaser-v1-one-year-later-37765.md>)

Original publisher: [Read original article](<https://carlosbecker.com/posts/goreleaser-v1-1year/>)

Author: Carlos Alexandro Becker

Published: 2022-11-14T00:00:00Z

Content type: article

Language: en

Sources: [Carlos Becker](<https://devfeed.tech/sources/carlos-becker.md>)

Topics: [releases](<https://devfeed.tech/topics/releases.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [Maintainers](<https://devfeed.tech/topics/maintainers.md>), [Security](<https://devfeed.tech/topics/security.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>), [anchore](<https://devfeed.tech/topics/anchore.md>), [openssf](<https://devfeed.tech/topics/openssf.md>)

Tags: [anchore](<https://devfeed.tech/tags/anchore.md>), [github](<https://devfeed.tech/tags/github.md>), [maintainers](<https://devfeed.tech/tags/maintainers.md>), [openssf](<https://devfeed.tech/tags/openssf.md>), [release](<https://devfeed.tech/tags/release.md>), [releases](<https://devfeed.tech/tags/releases.md>), [security](<https://devfeed.tech/tags/security.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>)

### AI overview

A retrospective on GoReleaser's first year after version 1.0.0, covering its development activity, release cadence, community growth, new features, bug fixes, integrations, and progress on security and supply-chain practices.

### Source excerpt

We launched GoReleaser v1 exactly 1 year ago today!