Make SBOMs, not GuessBOMs: Why we need to shift left on SBOM generation
GuessBOMs, SBOMs generated by reverse-engineering software artifacts, have severe limitations. The optimal point for generating complete SBOMs is at build time.

3862 articles
3862 ARTICLES
GuessBOMs, SBOMs generated by reverse-engineering software artifacts, have severe limitations. The optimal point for generating complete SBOMs is at build time.


Thanks to our ISRG partnership, we are enabling memory-safe TLS by introducing Rustls to Wolfi, which now sets the standard for memory safety in distributions.

We’re excited to announce a new partnership to bring Snyk security insights to ServiceNow workflows. The integration between Snyk Open Source and ServiceNow Application Vulnerability Response, the first of its kind, gives application security teams visibility into vulnerabilities in open source dependencies to provide a complete view of an organization’s application security posture.

Go 1.20 now available in Wolfi and Chainguard Images. New Go 1.20 security features include experimental secure-by-default functionality for tar file handling.

Learn how to improve cluster security with user namespaces, a new feature introduced in Kubernetes v1.25.

GitHub Container Registry (GHCR) had an information leak bug, where names of private repos were exposed. Here’s the background on how it was reported and fixed.

Chainguard Images now contains Python 3.11.1, giving developers minimal, hardened base images that still contain everything needed to build and run Python apps.


Software supply chain: understand the relationship between software distributors and software consumers and what FOSS maintainers are or are not responsible for.

The Wiz and Tines partnership empowers organizations to protect their cloud infrastructure at scale with no-code automation.

Do SBOMs meet the US government’s minimum elements standards? We created a dataset to methodically examine SBOM quality and check NTIA conformance to find out.

The Vulnerability Exploitability eXchange (VEX) helps efficiently assess vulnerabilities. If used with SBOMs, VEX improves overall security of a supply chain.
Cookies
We use analytics cookies (Google Analytics) to improve this site. Accept to allow them. Privacy Policy