
Fork yeah: We’re adding ten new open source projects to EmeritOSS
We added 10 open source projects to EmeritOSS—including MinIO, Prometheus exporters, and PgCat—to provide long-term, stability-focused maintenance and security.
2432 articles

We added 10 open source projects to EmeritOSS—including MinIO, Prometheus exporters, and PgCat—to provide long-term, stability-focused maintenance and security.

New integrated authentication for Python Libraries with a keyring: use short-lived credentials for pip installs to stay secure without slowing developers down.

Chainguard CEO Dan Lorenc explains why real security comes from trusted, from-source software supply chains, not post-hoc hardening or zero-CVE promises.

The critical ServiceNow Virtual Agent vulnerability highlights a vital lesson: securing agentic AI requires a return to traditional AppSec foundations. While AI can amplify risks, the root causes often stem from classic failures in authentication and authorization.

Get ready for the EU Cyber Resilience Act. See how Chainguard helps teams meet CRA security-by-design requirements with zero-CVE container images and libraries.

The Shai-Hulud npm incident exposed the limitations of reactive security in modern software supply chains. To survive the next major attack, organizations must shift toward a multi-layered strategy of proactive prevention, real-time intelligence, and automated action.

Snyk and Augment Code have partnered to deliver real-time security scanning and autonomous remediation directly within AI-powered development workflows, allowing teams to maintain peak velocity while ensuring every line of code is secure by default and compliant with organizational policies.

Learn how Chainguard helps organizations in Australia and New Zealand apply the Essential Eight to cloud-native, containerized environments.

We updated our FIPS container images with OpenSSL 3.1.2 (CMVP #5102), clearer CMVP visibility in SBOMs, and a roadmap for upcoming FIPS 140-3 cryptography.

A refined variant of the Shai-Hulud malware, dubbed The Golden Path, has been discovered targeting the npm ecosystem during the holiday season. Security teams are encouraged to prioritize structural hardening, such as disabling lifecycle scripts, to mitigate risks during this testing phase.

Chainguard’s Vibelympics competition brought out the best and most creative ideas in vibe coding and AI-assisted software development.

Chainguard delivers Ruby 4.0 container images: secure, zero-CVE, FIPS-ready, and available free so developers can adopt the latest Ruby safely and fast.