Registries and the npm Breach: Securing the Weakest Link in the Software Supply Chain
Chainguard Libraries provides a different and proven defense against supply chain attacks like the recent npm breach. See why preventing malware is important.

3862 articles
3862 ARTICLES
Chainguard Libraries provides a different and proven defense against supply chain attacks like the recent npm breach. See why preventing malware is important.


The future of Prisma ORM is here: The Rust-free version of Prisma ORM and the ESM-first prisma-client generator are both Generally Available in v6.16.0.

Chainguard has created a Slack community to foster a direct connection with the team, engage with your peers, and get the latest updates on Chainguard news.

We believe recognition in the IDC MarketScape for ASPM reflects our commitment to redefining how modern/cloud and AI-native applications are built and secured.

A deeper look at the npm debug/chalk supply-chain incident: deobfuscating the wallet-hijacking browser interceptor, quantifying the ~2-hour exposure with Wiz telemetry (~99% package prevalence, ~10% malware presence), and unpacking what made it spread so fast.

WizOS is in public preview starting today, enabling Wiz customers to adopt and operationalize secured images at scale.

We’re excited to announce that Snyk has been recognized as a Leader in the Forrester Wave™: Static Application Security Testing (SAST) Solutions, Q3 2025.

Our Chainguard Containers catalog now has more than 1,700 minimal, zero-CVE images, rebuilt from source every day – industry-leading in both breadth and depth.

Discover why Prisma ORM outperforms Drizzle ORM in TypeScript type checking. Our benchmarks show Prisma checks queries 72% faster on average, thanks to code generation that keeps editors snappy and CI runs smooth.

On Monday, September 8th, a highly regarded open source developer, ~qix, was compromised via a phishing email.

Exposed cloud credentials become the launchpad for mass phishing, highlighting email services as a prime target in cloud exploitation campaigns.

Discover key insights from DevSecCon speaker Brett Smith on securing AI in your pipelines. Register for DevSecCon 2025 to enhance your AI security knowledge.
Cookies
We use analytics cookies (Google Analytics) to improve this site. Accept to allow them. Privacy Policy