
Project Safe Source: Identifying potential vulnerabilities in Wolfi upstream
Chainguard’s Project Safe Source uses CodeQL to identify & fix vulnerabilities in open source projects packaged in Wolfi with automated pull requests.
2432 articles

Chainguard’s Project Safe Source uses CodeQL to identify & fix vulnerabilities in open source projects packaged in Wolfi with automated pull requests.

Learn about three industry trends that affect how companies approach software supply chain security, along with actionable tips for responding to them.

Chainguard remains committed to securing open source software. Discover how our updated Developer Images offering supports your projects.

Secure by default starts with immutability. Discover how to control change and minimize risks.

New NIST AI standards address generative AI risks with a focus on risk management, security practices, and recognizing synthetic content.

Learn the basics of vulnerability remediation from this teaser of Chainguard’s Get Smart in Five Minutes series on Youtube.

In honor of the upcoming Olympics, let’s look at a few of the “training areas” that help security teams on their journey to AppSec gold.

Read four expert tips for establishing the right tools, process, and culture for a DevSecOps program, as discussed at the InCyber Forum Europe.

In this blog post, we aim to provide an overview of common security vulnerabilities and vulnerable patterns that can occur when writing C/C++ add-ons in NodeJS.

In this post, we’ll cover four simple methods for finding security vulnerabilities in your Java and Kotlin code.

Master CMMC 2.0 compliance! Get expert insights, downloadable resources, and guidance to safeguard your sensitive data.

A recent Gartner report shows that AI transparency is a common issue in many organizations. Snyk Code’s hybrid AI-powered SAST is the secret ingredient for AI security & coding.