June 23-25, 2026
Welcome to Innovation Week: AI Readiness
Chainguard's first Innovation Week defines what it takes to be AI-ready, and it starts with prevention. Join us to learn how to eliminate known and unknown vulnerabilities, secure the AI SDLC, and govern the supply chain so you can build safely with AI and defend against it.
featured events
Claim your seat for the week's biggest events

The risks of frontier AI models: Live AMA on how to defend your open source
Frontier AI models can now find vulnerabilities in open source code at machine speed, a threat serious enough that the government recently restricted Fable5 and Mythos over critical infrastructure concerns. Join Chainguard CEO Dan Lorenc for a live AMA on what this means for open source, how Chainguard is approaching coordinated defense, and what your organization should do now.
Watch the recording
When AI builds faster than you can secure it: Tech Talks hosted by Chainguard
The traditional supply chain security model is breaking down, and AI coding tools are adding fuel to the fire. Join Chainguard, KKR, and Cursor to learn what engineering and security teams need to do now to stay ahead of security risk and build safely with AI.
Watch the recordingdaily line up
New drops everyday. Check back all week for the latest in supply chain security.
Patch known and unknown vulns
Frontier models are finding vulnerabilities faster than they can be patched, and they pose an imminent threat. Find out what you need to do and how to protect the code our critical infrastructure runs on.
Secure the AI SDLC
Attackers are using AI to target every layer of the SDLC, so defense has to cover every artifact. Find out what's being targeted, and how to secure it so you can build at AI speed without building in risk.
Govern the supply chain
Attackers succeed when small exceptions are made about what's running in production. Learn how security and platform teams can gain control over what enters their software supply chain.
- Tuesday, June 23Patch known and unknown vulns
Frontier models are finding vulnerabilities faster than they can be patched, and they pose an imminent threat. Find out what you need to do and how to protect the code our critical infrastructure runs on.
- Wednesday, June 24Secure the AI SDLC
Attackers are using AI to target every layer of the SDLC, so defense has to cover every artifact. Find out what's being targeted, and how to secure it so you can build at AI speed without building in risk.
- Thursday, June 25Govern the supply chain
Attackers succeed when small exceptions are made about what's running in production. Learn how security and platform teams can gain control over what enters their software supply chain.
Patch Known and Unknown Vulns
Prevention starts here
Blog
The hardest fork
Mythos is changing software security fast. AI-driven zero-days demand new trust infrastructure, coordinated disclosure, and secure open source consumption.
Read the blogReport
Chainguard is named a Leader in the 2026 Gartner®️ Magic Quadrant™️ for Software Supply Chain Security
Chainguard is named a Leader in the 2026 Gartner Magic Quadrant for Software Supply Chain Security, and positioned furthest right for Completeness of Vision among all vendors evaluated.
Download the reportProduct Release
Chainguard Libraries for Java is now GA and includes CVE remediation
Chainguard Libraries for Java is now GA with CVE remediation. Chainguard backports critical and high-severity fixes across the Spring Boot ecosystem and ships them as clean artifacts, so teams stay secure while they plan their next upgrade.
Read the announcement
Secure the AI SDLC
Safe at machine speed
Product Release
Chainguard Actions beta with 500+ actions to secure your CI/CD pipeline
Keep using the GitHub Actions your team relies on, now hardened and continuously verified. The public beta brings self-serve access to 500+ Actions you can adopt in 15 minutes.
Read the announcementProduct Release
Secure agent skills, at scale with 1000+ available in our public registry
Browse and install 1,000+ hardened agent skills into Claude Code, Cursor, Copilot, and more. A new private registry gives your team's own skills the same versioning, access control, and audit trail.
Read the announcementResource
Chainguard Actions migration skill
The Chainguard Actions Migration Skill inventories every GitHub Action running across your workflows, automatically swaps eligible Actions for hardened equivalents, and files requests for anything not yet in the catalog, so you can secure your pipelines with hardened Actions faster.
Get the skillProduct Release
Chainguard artifacts are now available natively in Cursor
When Cursor reaches for a base image or dependency, it now pulls from Chainguard instead of public registries. Install the plugin from the Cursor Marketplace in two minutes, with no workflow changes.
Read the announcementProduct Release
Adopt hardened containers without changing your pipelines, tooling, or environment
The compatibility gaps that kept hardened images out of enterprise pipelines are closing. RHEL 9 and 10 RPM support, drop-in -full tags, a validated Go FIPS image, and Dependabot support all land today.
Read the announcementProduct Release
Securing the AI Coding Ecosystem: Chainguard and the AI Tools Developers Use
AI agents are now developing software. Chainguard is building the trust layer for that future, partnering with tools like Cursor and Kiro so every artifact an agent pulls is hardened and verified by default.
Read the announcement
Govern the supply chain
Built-in control
Technical Blog
The Self-Updating Monorepo: How AI Keeps Our Code On-Standard
A look inside how Chainguard runs a fleet of AI agents that keeps hundreds of monorepo modules on-standard, opening fixes continuously and auto-merging the low-risk ones. The principle that makes it safe: an AI never merges code on its own.
Read the blogProduct Release
Wiz now scans Chainguard Libraries including Python and Java
Wiz now scans across Chainguard Libraries for Python, Java, and JavaScript. Your team gets a cleaner baseline with fewer false positives and less triage, all inside the Wiz interface you currently use.
Read the announcementProduct Release
Chainguard now scans source code for malware and “greyware”
Chainguard's new source code scanner blocks malware and "greyware,"that pass traditional scans but still behave maliciously. It screens 100,000+ packages a day and is included for Chainguard Libraries customers.
Read the announcementResource
The new standard for software supply chain security
This comprehensive guide maps the three AI threat vectors, defines the standard every artifact in your supply chain should meet, and shows how to govern the supply chain rom dependencies through deployment.
Read the guideProduct Release
Everything we announced during Innovation Week: AI Readiness
Chainguard shipped advances across every layer of the software supply chain and announced Athena, a new industry coalition for defending open source against AI attacks. Here's everything we announced.
Read the announcement
