Strengthening CI/CD Environments: Insights from NSA and DHS CISA guidance
Fortify your CI/CD environments with insights from NSA and DHS CISA guidance, presented by Chainguard.

3862 articles
3862 ARTICLES
Fortify your CI/CD environments with insights from NSA and DHS CISA guidance, presented by Chainguard.


In the previous post in this series, we discussed how to do some basic cleaning of AWS access keys. In this post, we’ll show how to reduce the privileges in order to mitigate their risk.

In this post, we’ll discuss CI/CD pipelines and how they can be configured to integrate security throughout the development process.

Webhooks are a callback integration technique for sending and receiving information, such as event notifications, in close to real-time. In this walkthrough, we’ll implement a GitHub webhook in Node.js that detects when users push code to a repository.

See a 57% reduction in your Pulumi image sizes with more security built in by default and a 97% reduction in CVEs with the new Chainguard Pulumi Image.

Learn security best practices to deploy generative AI models as part of your multi-tenant cloud applications and avoid putting your customers’ data at risk.

In this post, we’ll discuss npm postinstall, recent security events involving it, and how to protect the sensitive data stored shortcuts stored in your keyboard shortcuts from insecure npm package manager defaults.

We’re proud to announce the general availability of Project Collections. Project Collections aims to enable you to create collections of Projects based on the focus you and your teams need, whilst allowing you to perform actions on the Collection.

In this post, we’ll walk you through maximizing IAM security with AWS permissions boundaries and Snyk IaC.

As applications and projects scale, so will the number of secrets you need to keep safe. Learn the best practices and tools to use to secure your secrets.

Learn about the upcoming Chainguard Images catalog changes and the actions required for Public tier users.

In a recent research project, Snyk and Redhunt Labs set out to learn more about the security posture of popular GitHub repositories. Read on to learn more.
Cookies
We use analytics cookies (Google Analytics) to improve this site. Accept to allow them. Privacy Policy