
Chainguard Signs CISA’s Secure Software Development Attestation Form
Chainguard has recently signed CISA’s Secure Software Development Attestation Form, attesting to the security of Chainguard and its products.
2432 articles

Chainguard has recently signed CISA’s Secure Software Development Attestation Form, attesting to the security of Chainguard and its products.

Check out some of the previous Fetch the Flag challenges grounded in the same technical concepts and tactical material we’ve seen in the industry – and get excited for the 2025 Fetch the Flag!

Custom Assembly is Chainguard’s new image customization product that enables companies to consume zero-CVE open source software tailored to unique requirements.

Velotix utilizes Chainguard Images to help reduce CVEs, improve performance, and save time. Learn how Chainguard helps them build a more secure infrastructure.

Docker Bake is a great resource to define build configuration using a declarative file that integrates well with Chainguard Images. See how.

Recently, researchers have found another Software Supply Chain issue in BoltDB, a popular database tool in the Go programming environment. The BoltDB Go Module was found backdoored and contained hidden malicious code.

Chainguard Containers are a great way to consume third party applications like MySQL, NGINX, ArgoCD, and others while reducing size and CVEs.

New guidelines for HIPAA’s Security Rule have been proposed, which include updated requirements for vulnerability management, risk management, and more.

Snyk’s integration with Google Cloud Security Command Center (SCC) enables CISOs and security teams to monitor and manage AppSec vulnerabilities and misconfigurations from Snyk alongside cloud security issues from Google Cloud, all within a single pane of glass.

Chainguard Assemble is an event hosted by Chainguard for engineering and security professionals and leaders on March 25, 2025 at Convene in San Francisco, CA.

In this post, we’ll delve into what SBOMs are, why they’re necessary, and their role in open source security.

Chainguard CVE Visualizations, now generally available, is a capability that allows users to compare CVE numbers in both Chainguard Containers and upstream.