# software bill of materials

A formal record of the components and supply-chain relationships used to build software.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Proven, not promised: Chainguard Containers achieves SLSA Build Level 3

DevFeed: [Proven, not promised: Chainguard Containers achieves SLSA Build Level 3](<https://devfeed.tech/articles/proven-not-promised-chainguard-containers-achieves-slsa-build-level-3-13206.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/proven-not-promised-chainguard-containers-achieves-slsa-build-level-3>)

Published: 2026-08-17T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [software bill of materials](<https://devfeed.tech/topics/software-bill-of-materials.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [security](<https://devfeed.tech/tags/security.md>), [signing](<https://devfeed.tech/tags/signing.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>)

### AI overview

Chainguard says Coalfire independently assessed the Chainguard Containers build and release system as meeting SLSA Build Level 3 requirements. The article describes hardened, isolated builds, separately managed signing, provenance generation, and signed SBOMs for releases.

### Source excerpt

Coalfire independently assessed Chainguard Containers at SLSA Build Level 3, validating hardened builds, provenance, and supply chain integrity.

## Staying Ahead with ESP32 Security Updates

DevFeed: [Staying Ahead with ESP32 Security Updates](<https://devfeed.tech/articles/staying-ahead-with-esp32-security-updates-13755.md>)

Original publisher: [Read original article](<https://developer.espressif.com/blog/2026/03/esp32-security-updates/>)

Author: John Lee

Published: 2026-03-05T00:00:00Z

Content type: article

Language: en

Sources: [Blog on Developer Portal](<https://devfeed.tech/sources/blog-on-developer-portal.md>)

Topics: [ESP32](<https://devfeed.tech/topics/esp32.md>), [Security](<https://devfeed.tech/topics/security.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [cyber resilience act](<https://devfeed.tech/topics/cyber-resilience-act.md>), [dashboards](<https://devfeed.tech/topics/dashboards.md>), [ESP-IDF](<https://devfeed.tech/topics/esp-idf.md>), [Espressif](<https://devfeed.tech/topics/espressif.md>), [software bill of materials](<https://devfeed.tech/topics/software-bill-of-materials.md>)

Tags: [blog](<https://devfeed.tech/tags/blog.md>), [cyber-resilience-act](<https://devfeed.tech/tags/cyber-resilience-act.md>), [dashboards](<https://devfeed.tech/tags/dashboards.md>), [esp-idf](<https://devfeed.tech/tags/esp-idf.md>), [esp32](<https://devfeed.tech/tags/esp32.md>), [espressif](<https://devfeed.tech/tags/espressif.md>), [iot](<https://devfeed.tech/tags/iot.md>), [lts](<https://devfeed.tech/tags/lts.md>), [ota](<https://devfeed.tech/tags/ota.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

This article explains how the ESP32 ecosystem supports long-term firmware security and compliance under regulations such as the EU Cyber Resilience Act. It covers vulnerability management, secure OTA updates, Long-Term Support branches, the ESP-IDF Security Dashboard, and SBOMs for tracking affected components and patched versions.

### Source excerpt

This article explains how manufacturers can use the ESP32 ecosystem to build and maintain secure firmware over time, especially in light of new regulations like the EU Cyber Resilience Act. It highlights tools such as vulnerability dashboards, Long-Term Support branches, and secure OTA updates to ensure ongoing compliance and device security.

## Meeting the Zero-CVE Mandate: How Chainguard Helps Businesses Ship Secure Software That Customers Trust

DevFeed: [Meeting the Zero-CVE Mandate: How Chainguard Helps Businesses Ship Secure Software That Customers Trust](<https://devfeed.tech/articles/meeting-the-zero-cve-mandate-how-chainguard-helps-businesses-ship-secure-software-that-customers-trust-13155.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/meeting-the-zero-cve-mandate-how-chainguard-helps-businesses-ship-secure-software-that-customers-trust>)

Published: 2025-10-06T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [software bill of materials](<https://devfeed.tech/topics/software-bill-of-materials.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-custom-assembly](<https://devfeed.tech/tags/chainguard-custom-assembly.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cves](<https://devfeed.tech/tags/cves.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

The article explains how Chainguard helps businesses meet stricter software security requirements for self-hosted, cloud, packaged-agent, and embedded software. It focuses on zero known CVEs at delivery, verifiable SBOMs, provenance attestations, compatibility with security tooling, and the challenges of open source dependencies and container images.

### Source excerpt

Chainguard's zero-CVE containers come with broad compatibility, custom assembly, verifiable provenance and SBOMs, and more to help you ship secure software.

## Why Golden Images still matter and how to secure them with Chainguard

DevFeed: [Why Golden Images still matter and how to secure them with Chainguard](<https://devfeed.tech/articles/why-golden-images-still-matter-and-how-to-secure-them-with-chainguard-13330.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/why-golden-images-still-matter-and-how-to-secure-them-with-chainguard>)

Published: 2025-05-22T00:00:00Z

Content type: tutorial

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [DevOps](<https://devfeed.tech/topics/devops.md>), [software bill of materials](<https://devfeed.tech/topics/software-bill-of-materials.md>), [Software](<https://devfeed.tech/topics/software.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [aws](<https://devfeed.tech/tags/aws.md>), [azure](<https://devfeed.tech/tags/azure.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [container-image](<https://devfeed.tech/tags/container-image.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [devops](<https://devfeed.tech/tags/devops.md>), [golden-image](<https://devfeed.tech/tags/golden-image.md>), [golden-images](<https://devfeed.tech/tags/golden-images.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [security](<https://devfeed.tech/tags/security.md>), [zero-cves](<https://devfeed.tech/tags/zero-cves.md>)

### AI overview

This article explains why well-managed golden image programs remain important for modern software delivery. It describes how continuously rebuilt, patched, signed, scanned, and versioned images--with SBOMs, attestations, provenance, and policy compliance--can improve security and streamline development workflows, while presenting Chainguard as an alternative to homegrown programs.

### Source excerpt

Golden container image programs can be a great way to increase efficiency and security for your engineering team. Learn how to do it right with Chainguard.

## Software Bill of Materials (SBOM) for your Spin Apps

DevFeed: [Software Bill of Materials (SBOM) for your Spin Apps](<https://devfeed.tech/articles/software-bill-of-materials-sbom-for-your-spin-apps-15336.md>)

Original publisher: [Read original article](<https://www.fermyon.com/blog/sbom-for-your-spin-apps>)

Author: Thorsten Hans

Published: 2025-01-16T12:00:00Z

Content type: tutorial

Language: en

Sources: [Fermyon - Experience the next wave of cloud computing.](<https://devfeed.tech/sources/fermyon-experience-the-next-wave-of-cloud-computing.md>)

Topics: [software bill of materials](<https://devfeed.tech/topics/software-bill-of-materials.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [trivy](<https://devfeed.tech/topics/trivy.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Requirements](<https://devfeed.tech/topics/requirements.md>), [Software](<https://devfeed.tech/topics/software.md>)

Tags: [open-source](<https://devfeed.tech/tags/open-source.md>), [regulatory](<https://devfeed.tech/tags/regulatory.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [trivy](<https://devfeed.tech/tags/trivy.md>)

### AI overview

A tutorial on creating Software Bills of Materials for Spin apps, addressing regulatory requirements and software supply chain security with open-source tools such as Trivy.

### Source excerpt

Learn how to create SBOMs for Spin apps, meet regulatory requirements, and secure your software supply chain with open-source tools like Trivy

## New Chainguard Academy Course: Linky's Guide to Chainguard Images

DevFeed: [New Chainguard Academy Course: Linky's Guide to Chainguard Images](<https://devfeed.tech/articles/new-chainguard-academy-course-linky-s-guide-to-chainguard-images-13170.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/new-chainguard-academy-course-linkys-guide-to-chainguard-images>)

Published: 2024-10-23T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Security](<https://devfeed.tech/topics/security.md>), [software bill of materials](<https://devfeed.tech/topics/software-bill-of-materials.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-academy](<https://devfeed.tech/tags/chainguard-academy.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [command-line](<https://devfeed.tech/tags/command-line.md>), [container](<https://devfeed.tech/tags/container.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cosign](<https://devfeed.tech/tags/cosign.md>), [course](<https://devfeed.tech/tags/course.md>), [customer-course](<https://devfeed.tech/tags/customer-course.md>), [education](<https://devfeed.tech/tags/education.md>), [federal-information-processing-standards](<https://devfeed.tech/tags/federal-information-processing-standards.md>), [fips](<https://devfeed.tech/tags/fips.md>), [getting-started](<https://devfeed.tech/tags/getting-started.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>)

### AI overview

Chainguard announces Linky's Guide to Chainguard Images, a seven-part course covering image acquisition, management, security, authentication, scanning, updates, the user interface, versions, chainctl, FIPS images, SBOMs, and build comparison.

### Source excerpt

Linky's Guide to Chainguard Images is a set of courses for customers and prospects of Chainguard to learn more about our container images product.

## Get Smart in 5 Minutes: Vulnerability remediation unveiled

DevFeed: [Get Smart in 5 Minutes: Vulnerability remediation unveiled](<https://devfeed.tech/articles/get-smart-in-5-minutes-vulnerability-remediation-unveiled-13060.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/get-smart-in-5-minutes-vulnerability-remediation-unveiled>)

Published: 2024-08-16T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [software bill of materials](<https://devfeed.tech/topics/software-bill-of-materials.md>), [Security](<https://devfeed.tech/topics/security.md>), [Software](<https://devfeed.tech/topics/software.md>)

Tags: [developer](<https://devfeed.tech/tags/developer.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [scanners](<https://devfeed.tech/tags/scanners.md>), [security](<https://devfeed.tech/tags/security.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This introductory article explains vulnerability remediation as the process of fixing flaws identified by software scanners. It describes common obstacles, including triage, uncertainty about the affected code, and unclear ownership. It presents software bills of materials (SBOMs) as a way to identify software components, while noting that outdated or inaccurate SBOMs may miss vulnerabilities or malware. The article emphasizes that software vulnerabilities can affect everyone through data breaches, service disruptions, and physical harm.

### Source excerpt

Learn the basics of vulnerability remediation from this teaser of Chainguard's Get Smart in Five Minutes series on Youtube.

## Reproducible Builds at FOSDEM 2024

DevFeed: [Reproducible Builds at FOSDEM 2024](<https://devfeed.tech/articles/reproducible-builds-at-fosdem-2024-34158.md>)

Original publisher: [Read original article](<https://reproducible-builds.org/news/2024/02/08/reproducible-builds-at-fosdem-2024/>)

Published: 2024-02-08T00:00:00Z

Content type: news

Language: en

Sources: [reproducible-builds.org](<https://devfeed.tech/sources/reproducible-builds-org.md>)

Topics: [reproducible builds](<https://devfeed.tech/topics/reproducible-builds.md>), [FOSDEM](<https://devfeed.tech/topics/fosdem.md>), [Arch Linux](<https://devfeed.tech/topics/archlinux.md>), [Debian](<https://devfeed.tech/topics/debian.md>), [Fedora](<https://devfeed.tech/topics/fedora.md>), [coreboot](<https://devfeed.tech/topics/coreboot.md>), [software bill of materials](<https://devfeed.tech/topics/software-bill-of-materials.md>)

Tags: [coreboot](<https://devfeed.tech/tags/coreboot.md>), [debian](<https://devfeed.tech/tags/debian.md>), [fedora](<https://devfeed.tech/tags/fedora.md>), [fosdem](<https://devfeed.tech/tags/fosdem.md>), [org](<https://devfeed.tech/tags/org.md>), [reproducible-builds](<https://devfeed.tech/tags/reproducible-builds.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>)

### AI overview

The article reports on Reproducible Builds activities at FOSDEM 2024. It highlights Holger Levsen's talk covering the project's history, current state, and future goals, along with other talks on reproducibility, confidential computing, RISC-V bootstrapping, reproducible development environments, HPC experiments, configuration options, and software bills of materials.

### Source excerpt

Core Reproducible Builds developer Holger Levsen presented at the main track at FOSDEM on Saturday 3rd February this year in Brussels, Belgium. Titled Reproducible Builds: The First Ten Years... In this talk Holger 'h01ger' Levsen will give an overview about Reproducible Builds: How it started with a small BoF at DebConf13 (and before), then grew from being a Debian effort to something many projects work on together, until in 2021 it was mentioned in an Executive Order of the President of the United States. And of course, the talk will not end there, but rather outline where we are today and where we still need to be going, until Debian stable (and other distros!) will be 100% reproducible, verified by many. h01ger has been involved in reproducible builds since 2014 and so far has set up automated reproducibility testing for Debian, Fedora, Arch Linux, FreeBSD, NetBSD and coreboot. More information can be found on FOSDEM's own page for the talk, including a video recording and slides. Separate from Holger's talk, however, there were a number of other talks about reproducible builds at FOSDEM this year: Reproducible builds for confidential computing: Why remote attestation is worthless without it by Malte Poll and Paul Meyer. RISC-V Bootstrapping in Guix and Live-Bootstrap by Ekaitz. rix: an R package for reproducible dev environments with Nix by Bruno Rodrigues. Making reproducible and publishable large-scale HPC experiments by Philippe Swartvagher. Documenting and Fixing Non-Reproducible Builds due to Configuration Options by RANDRIANAINA Georges Aaron. ... and there was even an entire track on Software Bill of Materials.

## Software development security redefined: Sourcegraph's story

DevFeed: [Software development security redefined: Sourcegraph's story](<https://devfeed.tech/articles/software-development-security-redefined-sourcegraph-s-story-13236.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/software-development-security-redefined-sourcegraphs-story>)

Published: 2023-12-20T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [software bill of materials](<https://devfeed.tech/topics/software-bill-of-materials.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [customer-story](<https://devfeed.tech/tags/customer-story.md>), [cve](<https://devfeed.tech/tags/cve.md>), [open-source-software-security](<https://devfeed.tech/tags/open-source-software-security.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [sourcegraph](<https://devfeed.tech/tags/sourcegraph.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

This customer story describes how Sourcegraph used Chainguard Images, built on Wolfi OS, together with OpenVEX and SBOMs to simplify vulnerability management and strengthen software supply chain security. The article states that Sourcegraph achieved zero known vulnerabilities in a short timespan.

### Source excerpt

Sourcegraph's story: leveraging Chainguard's technology for streamlined software development and heightened security.

## Software Bill of Materials

DevFeed: [Software Bill of Materials](<https://devfeed.tech/articles/software-bill-of-materials-13961.md>)

Original publisher: [Read original article](<https://developer.espressif.com/blog/software-bill-of-materials/>)

Author: John Lee

Published: 2023-11-02T00:00:00Z

Content type: tutorial

Language: en

Sources: [Blog on Developer Portal](<https://devfeed.tech/sources/blog-on-developer-portal.md>)

Topics: [software bill of materials](<https://devfeed.tech/topics/software-bill-of-materials.md>), [ESP-IDF](<https://devfeed.tech/topics/esp-idf.md>), [Espressif](<https://devfeed.tech/topics/espressif.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [NVD](<https://devfeed.tech/topics/nvd.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [blog](<https://devfeed.tech/tags/blog.md>), [esp-idf](<https://devfeed.tech/tags/esp-idf.md>), [esp32](<https://devfeed.tech/tags/esp32.md>), [espressif](<https://devfeed.tech/tags/espressif.md>), [iot](<https://devfeed.tech/tags/iot.md>), [nvd](<https://devfeed.tech/tags/nvd.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [security](<https://devfeed.tech/tags/security.md>), [security-vulnerabilities](<https://devfeed.tech/tags/security-vulnerabilities.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [spdx](<https://devfeed.tech/tags/spdx.md>), [tools](<https://devfeed.tech/tags/tools.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This article introduces software bills of materials (SBOMs), explains their structure and formats such as SPDX and CycloneDX, and presents Espressif's ESP-IDF-SBOM tool. The tool generates SPDX SBOMs for ESP-IDF-based applications and checks them against the National Vulnerability Database for known vulnerabilities.

### Source excerpt

Overview# The "software bill of materials" (SBOM) has emerged as a key building block in software security and software supply chain risk management. An SBOM is a comprehensive list of all the software components, dependencies, and metadata associated with an application. Espressif believes that this information is a key step towards ensuring the security of the connected devices. And as such, we have now enabled easy to use tools and solutions to track and analyze this information.

## Working with government and industry to put open source security tooling into practice

DevFeed: [Working with government and industry to put open source security tooling into practice](<https://devfeed.tech/articles/working-with-government-and-industry-to-put-open-source-security-tooling-into-practice-13342.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/working-with-government-and-industry-to-put-open-source-security-tooling-into-practice>)

Published: 2023-09-12T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [software bill of materials](<https://devfeed.tech/topics/software-bill-of-materials.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Tooling](<https://devfeed.tech/topics/tooling.md>), [cisa](<https://devfeed.tech/topics/cisa.md>), [Docker Hardened Images](<https://devfeed.tech/topics/docker-hardened-images.md>)

Tags: [bombshell](<https://devfeed.tech/tags/bombshell.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [cisa](<https://devfeed.tech/tags/cisa.md>), [cyclonedx](<https://devfeed.tech/tags/cyclonedx.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [protobom](<https://devfeed.tech/tags/protobom.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [security](<https://devfeed.tech/tags/security.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [spdx](<https://devfeed.tech/tags/spdx.md>), [vex](<https://devfeed.tech/tags/vex.md>)

### AI overview

Chainguard describes two open-source SBOM tools developed with the U.S. Department of Homeland Security and other startups: protobom, which translates SBOM data between formats, and bomshell, which combines and composes SBOMs. The initiative aims to improve software supply chain security and visibility.

### Source excerpt

Pioneering SBOM tools with government and industry allies, Chainguard advances open source security measures.

## How to explain the CISA software attestation requirements to your board

DevFeed: [How to explain the CISA software attestation requirements to your board](<https://devfeed.tech/articles/how-to-explain-the-cisa-software-attestation-requirements-to-your-board-13094.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/how-to-explain-the-cisa-software-attestation-requirements-to-your-board>)

Published: 2023-05-05T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [cisa](<https://devfeed.tech/topics/cisa.md>), [cybersecurity and infrastructure security agency](<https://devfeed.tech/topics/cybersecurity-and-infrastructure-security-agency.md>), [software bill of materials](<https://devfeed.tech/topics/software-bill-of-materials.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [attestation](<https://devfeed.tech/tags/attestation.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [cisa](<https://devfeed.tech/tags/cisa.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [government](<https://devfeed.tech/tags/government.md>), [national-cybersecurity-strategy](<https://devfeed.tech/tags/national-cybersecurity-strategy.md>), [nist](<https://devfeed.tech/tags/nist.md>), [policy](<https://devfeed.tech/tags/policy.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [secure-container-image](<https://devfeed.tech/tags/secure-container-image.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [self-attestation](<https://devfeed.tech/tags/self-attestation.md>), [signing-artifacts](<https://devfeed.tech/tags/signing-artifacts.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [software-artifact-signing](<https://devfeed.tech/tags/software-artifact-signing.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [ssdf](<https://devfeed.tech/tags/ssdf.md>)

### AI overview

This article explains how software companies can brief their boards on CISA software attestation requirements and the broader federal software supply chain security policy landscape. It discusses Executive Order 14028, SBOMs, secure software development, CISA's Secure Software Development Attestation Form, and the requirements in OMB Memorandum M-22-18, including alignment with NIST guidance.

### Source excerpt

CISA's draft self-attestation form clarifies the minimum requirements that software developers must meet to comply with OMB Memorandum M-22-18.

## OSS Security: Chainguard Spring 2023 update

DevFeed: [OSS Security: Chainguard Spring 2023 update](<https://devfeed.tech/articles/oss-security-chainguard-spring-2023-update-13199.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/oss-security-chainguard-spring-2023-update>)

Published: 2023-03-22T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Security](<https://devfeed.tech/topics/security.md>), [software bill of materials](<https://devfeed.tech/topics/software-bill-of-materials.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [cloud-native](<https://devfeed.tech/tags/cloud-native.md>), [cloud-native-security-con](<https://devfeed.tech/tags/cloud-native-security-con.md>), [fosdem](<https://devfeed.tech/tags/fosdem.md>), [foss](<https://devfeed.tech/tags/foss.md>), [gitops](<https://devfeed.tech/tags/gitops.md>), [kubecon-eu](<https://devfeed.tech/tags/kubecon-eu.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [open-source-software-security](<https://devfeed.tech/tags/open-source-software-security.md>), [openssf](<https://devfeed.tech/tags/openssf.md>), [oss](<https://devfeed.tech/tags/oss.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>)

### AI overview

Chainguard's Spring 2023 update describes its involvement in open-source software security during the first part of 2023. It covers community leadership, conference talks and workshops, software freedom advocacy, and efforts to make software bills of materials useful and widely adopted for supply-chain security.

### Source excerpt

Chainguard believes open source is important and we mean it. Check out how we've been involved in OSS Security in the first part of 2023.

## Chainguard's perspective on the National Cybersecurity Strategy and secure software development

DevFeed: [Chainguard's perspective on the National Cybersecurity Strategy and secure software development](<https://devfeed.tech/articles/charting-a-secure-by-default-future-13002.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/charting-a-secure-by-default-future>)

Published: 2023-03-02T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [software-development](<https://devfeed.tech/topics/software-development.md>), [Memory Safety](<https://devfeed.tech/topics/memory-safety.md>), [software bill of materials](<https://devfeed.tech/topics/software-bill-of-materials.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-enforce](<https://devfeed.tech/tags/chainguard-enforce.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [memory-safety](<https://devfeed.tech/tags/memory-safety.md>), [national-cybersecurity-strategy](<https://devfeed.tech/tags/national-cybersecurity-strategy.md>), [nist](<https://devfeed.tech/tags/nist.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [software-bill-of-materials](<https://devfeed.tech/tags/software-bill-of-materials.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [standards](<https://devfeed.tech/tags/standards.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Chainguard discusses the National Cybersecurity Strategy's implications for software liability and secure software development, highlighting SBOM tooling, NIST frameworks, memory-safe languages, and open source software security.

### Source excerpt

Chainguard's vision for a 'Secure by Default' future: Pioneering strategies to integrate security into the tech fabric.

## Make SBOMs, not GuessBOMs: Why we need to shift left on SBOM generation

DevFeed: [Make SBOMs, not GuessBOMs: Why we need to shift left on SBOM generation](<https://devfeed.tech/articles/make-sboms-not-guessboms-why-we-need-to-shift-left-on-sbom-generation-13142.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/make-sboms-not-guessboms-why-we-need-to-shift-left-on-sbom-generation>)

Published: 2023-01-26T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [software bill of materials](<https://devfeed.tech/topics/software-bill-of-materials.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [software dark matter](<https://devfeed.tech/topics/software-dark-matter.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [Reverse Engineering](<https://devfeed.tech/topics/reverse-engineering.md>), [Containers](<https://devfeed.tech/topics/containers.md>)

Tags: [apko](<https://devfeed.tech/tags/apko.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [guessbom](<https://devfeed.tech/tags/guessbom.md>), [melange](<https://devfeed.tech/tags/melange.md>), [reverse-engineering](<https://devfeed.tech/tags/reverse-engineering.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [sca](<https://devfeed.tech/tags/sca.md>), [shift-left](<https://devfeed.tech/tags/shift-left.md>), [software-composition-analysis](<https://devfeed.tech/tags/software-composition-analysis.md>), [software-dark-matter](<https://devfeed.tech/tags/software-dark-matter.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

The article argues that SBOMs generated after a build by software composition analysis tools can be incomplete because they may miss components that bypass recorded metadata, such as files copied through Dockerfiles. It presents build-time generation as a better way to produce complete SBOMs and describes untracked files as software dark matter, which can make post-build SBOMs closer to best guesses than reliable inventories.

### Source excerpt

GuessBOMs, SBOMs generated by reverse-engineering software artifacts, have severe limitations. The optimal point for generating complete SBOMs is at build time.